forked from kutovoys/xray-checker
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.node.yml
More file actions
53 lines (45 loc) · 2.14 KB
/
Copy pathdocker-compose.node.yml
File metadata and controls
53 lines (45 loc) · 2.14 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
# docker-compose.node.yml — Deployment template for xray-checker remote node
# Designed for restricted/enterprise networks (corporate proxies, firewalls, NAT).
#
# Usage:
# docker compose -f docker-compose.node.yml up -d
#
# Network Traffic Separation:
# 1. Node Reports (REPORT_URL): Directly to master. NO_PROXY automatically excludes
# the master host/IP, localhost, and RFC1918 private subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
# 2. Direct Probes: Direct TCP/UDP reachability checks to proxy servers always go directly.
# 3. Target Probes: HTTP 204 target tests are routed through the proxy under test via local SOCKS5.
# 4. Subscriptions & Geo bases: If GitHub or subscription panel is blocked in your network,
# set BOOTSTRAP_PROXY below.
services:
xray-node:
image: ghcr.io/vlv-code/xray-checker-tg-bot:latest
container_name: xray-node
restart: unless-stopped
# If building locally behind a corporate proxy:
# build:
# context: .
# args:
# HTTP_PROXY: "http://192.168.27.121:10809"
# HTTPS_PROXY: "http://192.168.27.121:10809"
environment:
# Remote master ingest URL and bearer token (required for node mode)
# NOTE: Node name is assigned exclusively on the master when creating token via /nodeadd <name>.
# Nodes are authenticated strictly by REPORT_TOKEN.
REPORT_URL: "http://<YOUR_MASTER_IP>:2112/api/v1/nodes/report"
REPORT_TOKEN: "CHANGE_ME_TO_YOUR_NODE_BEARER_TOKEN"
# Proxy for downloading subscriptions and geo databases if direct internet
# is restricted on this host (does NOT affect master reports or proxy checks):
# BOOTSTRAP_PROXY: "http://192.168.27.121:10809"
# Custom NO_PROXY if you need additional intranet exclusions
# (defaults to localhost, RFC1918 private networks, and REPORT_URL host):
# NO_PROXY: "localhost,127.0.0.1,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16"
# Logging level: info (default), debug, warn, error
LOG_LEVEL: "info"
volumes:
# Persistent storage for node data and geo databases
- node-data:/app/data
- node-geo:/app/geo
volumes:
node-data:
node-geo: