feat: add web admin panel for node management
Add Flask panel with login, add/delete nodes, and share link copy. Generate sing-box config from SQLite; add uninstall script and clean install flow. Panel served at https://DOMAIN:8444 via nginx. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
+81
-59
@@ -1,6 +1,5 @@
|
||||
#!/usr/bin/env bash
|
||||
# VPS 一键部署:sing-box (Reality + Hysteria2) + Nginx fallback
|
||||
# 适用:Ubuntu 22.04/24.04、Debian 12
|
||||
# VPS 一键部署:sing-box + Web 管理面板
|
||||
# 用法:sudo bash scripts/install.sh
|
||||
set -euo pipefail
|
||||
|
||||
@@ -15,6 +14,20 @@ NC='\033[0m'
|
||||
log() { echo -e "${GREEN}[+]${NC} $*"; }
|
||||
err() { echo -e "${RED}[!]${NC} $*" >&2; exit 1; }
|
||||
|
||||
wait_for_apt() {
|
||||
local i=0
|
||||
while fuser /var/lib/dpkg/lock-frontend >/dev/null 2>&1; do
|
||||
if (( i == 0 )); then
|
||||
log "等待 apt 锁释放(系统自动更新中)..."
|
||||
fi
|
||||
(( i++ )) || true
|
||||
if (( i > 120 )); then
|
||||
err "apt 锁等待超时,请稍后重试: bash scripts/install.sh"
|
||||
fi
|
||||
sleep 5
|
||||
done
|
||||
}
|
||||
|
||||
[[ $EUID -eq 0 ]] || err "请使用 root 运行: sudo bash scripts/install.sh"
|
||||
[[ -f "$ENV_FILE" ]] || err "缺少 .env 文件,请先: cp .env.example .env 并填写"
|
||||
|
||||
@@ -25,17 +38,30 @@ source "$ENV_FILE"
|
||||
: "${DOMAIN:?请在 .env 中设置 DOMAIN}"
|
||||
: "${ACME_EMAIL:?请在 .env 中设置 ACME_EMAIL}"
|
||||
: "${REALITY_SERVER_NAME:=www.microsoft.com}"
|
||||
: "${PANEL_USERNAME:=admin}"
|
||||
|
||||
if [[ -z "${UUID:-}" || -z "${REALITY_PRIVATE_KEY:-}" ]]; then
|
||||
log "未检测到密钥,运行 generate-keys.sh ..."
|
||||
if [[ -z "${REALITY_PRIVATE_KEY:-}" ]]; then
|
||||
log "未检测到 Reality 密钥,运行 generate-keys.sh ..."
|
||||
bash "$SCRIPT_DIR/generate-keys.sh"
|
||||
source "$ENV_FILE"
|
||||
fi
|
||||
|
||||
: "${UUID:?}"
|
||||
if [[ -z "${PANEL_PASSWORD:-}" ]]; then
|
||||
PANEL_PASSWORD="$(sing-box generate rand --base64 32 | tr -d '/+=' | head -c 20)"
|
||||
if grep -q "^PANEL_PASSWORD=" "$ENV_FILE" 2>/dev/null; then
|
||||
sed -i "s|^PANEL_PASSWORD=.*|PANEL_PASSWORD=${PANEL_PASSWORD}|" "$ENV_FILE"
|
||||
else
|
||||
echo "PANEL_PASSWORD=${PANEL_PASSWORD}" >> "$ENV_FILE"
|
||||
fi
|
||||
source "$ENV_FILE"
|
||||
fi
|
||||
|
||||
: "${REALITY_PRIVATE_KEY:?}"
|
||||
: "${REALITY_PUBLIC_KEY:?}"
|
||||
: "${REALITY_SHORT_ID:?}"
|
||||
: "${HY2_PASSWORD:?}"
|
||||
: "${PANEL_PASSWORD:?}"
|
||||
|
||||
export JIEDIAN_ROOT="$ROOT_DIR"
|
||||
|
||||
ARCH="$(uname -m)"
|
||||
case "$ARCH" in
|
||||
@@ -47,10 +73,11 @@ esac
|
||||
SB_VERSION="1.11.0"
|
||||
SB_URL="https://github.com/SagerNet/sing-box/releases/download/v${SB_VERSION}/sing-box-${SB_VERSION}-linux-${SB_ARCH}.tar.gz"
|
||||
|
||||
wait_for_apt
|
||||
log "更新系统包 ..."
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
apt-get update -qq
|
||||
apt-get install -y -qq curl wget nginx ufw ca-certificates
|
||||
apt-get install -y -qq curl wget nginx ufw ca-certificates python3 python3-venv python3-pip
|
||||
|
||||
log "安装 sing-box ${SB_VERSION} ..."
|
||||
TMP="$(mktemp -d)"
|
||||
@@ -66,6 +93,7 @@ ufw allow 22/tcp comment 'SSH'
|
||||
ufw allow 80/tcp comment 'HTTP-ACME'
|
||||
ufw allow 443/tcp comment 'Reality'
|
||||
ufw allow 8443/udp comment 'Hysteria2'
|
||||
ufw allow 8444/tcp comment 'Panel-HTTPS'
|
||||
ufw --force enable
|
||||
|
||||
log "部署 Nginx fallback 站点 ..."
|
||||
@@ -80,7 +108,6 @@ mkdir -p /var/www/acme
|
||||
sed "s|__DOMAIN__|${DOMAIN}|g" "$ROOT_DIR/server/nginx/acme.conf.template" \
|
||||
> /etc/nginx/sites-available/acme
|
||||
ln -sf /etc/nginx/sites-available/acme /etc/nginx/sites-enabled/acme
|
||||
nginx -t && systemctl enable nginx && systemctl restart nginx
|
||||
|
||||
log "申请 TLS 证书 (Let's Encrypt) ..."
|
||||
mkdir -p /etc/sing-box/certs
|
||||
@@ -90,7 +117,6 @@ fi
|
||||
# shellcheck disable=SC1091
|
||||
source /root/.acme.sh/acme.sh.env || true
|
||||
|
||||
# 确保域名已解析到本机
|
||||
CURRENT_IP="$(curl -4 -fsSL ifconfig.me 2>/dev/null || curl -4 -fsSL ip.sb)"
|
||||
if [[ "$CURRENT_IP" != "$VPS_IP" ]]; then
|
||||
err "域名 $DOMAIN 需先解析到 VPS IP ($VPS_IP),当前 VPS 出口 IP 为 $CURRENT_IP"
|
||||
@@ -106,19 +132,23 @@ log "安装 TLS 证书到 sing-box ..."
|
||||
--key-file /etc/sing-box/certs/privkey.pem \
|
||||
--fullchain-file /etc/sing-box/certs/fullchain.pem
|
||||
|
||||
log "部署管理面板 Nginx (8444) ..."
|
||||
sed "s|__DOMAIN__|${DOMAIN}|g" "$ROOT_DIR/server/nginx/panel.conf.template" \
|
||||
> /etc/nginx/sites-available/panel
|
||||
ln -sf /etc/nginx/sites-available/panel /etc/nginx/sites-enabled/panel
|
||||
nginx -t && systemctl enable nginx && systemctl restart nginx
|
||||
|
||||
log "安装 Python 面板依赖 ..."
|
||||
python3 -m venv "$ROOT_DIR/panel/venv"
|
||||
"$ROOT_DIR/panel/venv/bin/pip" install -q -r "$ROOT_DIR/panel/requirements.txt"
|
||||
|
||||
log "初始化节点数据库 ..."
|
||||
python3 "$ROOT_DIR/panel/init_db.py"
|
||||
|
||||
log "生成 sing-box 服务端配置 ..."
|
||||
mkdir -p /etc/sing-box/certs
|
||||
sed -e "s|\${UUID}|${UUID}|g" \
|
||||
-e "s|\${REALITY_SERVER_NAME}|${REALITY_SERVER_NAME}|g" \
|
||||
-e "s|\${REALITY_PRIVATE_KEY}|${REALITY_PRIVATE_KEY}|g" \
|
||||
-e "s|\${REALITY_SHORT_ID}|${REALITY_SHORT_ID}|g" \
|
||||
-e "s|\${HY2_PASSWORD}|${HY2_PASSWORD}|g" \
|
||||
-e "s|\${DOMAIN}|${DOMAIN}|g" \
|
||||
"$ROOT_DIR/server/sing-box.json.template" > /etc/sing-box/config.json
|
||||
python3 "$ROOT_DIR/scripts/render-server.py"
|
||||
|
||||
sing-box check -c /etc/sing-box/config.json
|
||||
|
||||
log "创建 systemd 服务 ..."
|
||||
log "创建 sing-box systemd 服务 ..."
|
||||
cat > /etc/systemd/system/sing-box.service <<'UNIT'
|
||||
[Unit]
|
||||
Description=sing-box service
|
||||
@@ -136,54 +166,46 @@ LimitNOFILE=1048576
|
||||
WantedBy=multi-user.target
|
||||
UNIT
|
||||
|
||||
log "创建管理面板 systemd 服务 ..."
|
||||
cat > /etc/systemd/system/jiedian-panel.service <<UNIT
|
||||
[Unit]
|
||||
Description=jiedian admin panel
|
||||
After=network.target sing-box.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
WorkingDirectory=${ROOT_DIR}/panel
|
||||
Environment=JIEDIAN_ROOT=${ROOT_DIR}
|
||||
ExecStart=${ROOT_DIR}/panel/venv/bin/python app.py
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
UNIT
|
||||
|
||||
systemctl daemon-reload
|
||||
systemctl enable sing-box
|
||||
systemctl enable sing-box jiedian-panel
|
||||
|
||||
log "注册证书续期 reload 命令 ..."
|
||||
/root/.acme.sh/acme.sh --install-cert -d "$DOMAIN" \
|
||||
--key-file /etc/sing-box/certs/privkey.pem \
|
||||
--fullchain-file /etc/sing-box/certs/fullchain.pem \
|
||||
--reloadcmd "systemctl restart sing-box" \
|
||||
|| log "acme reloadcmd 注册失败,可忽略(服务已配置)"
|
||||
|| log "acme reloadcmd 注册失败,可忽略"
|
||||
|
||||
systemctl restart sing-box
|
||||
|
||||
log "生成客户端配置 ..."
|
||||
CLIENT_DIR="${ROOT_DIR}/client/generated"
|
||||
mkdir -p "$CLIENT_DIR"
|
||||
: "${REALITY_PUBLIC_KEY:?请在 .env 中设置 REALITY_PUBLIC_KEY(运行 generate-keys.sh 可自动生成)}"
|
||||
|
||||
sed -e "s|\${VPS_IP}|${VPS_IP}|g" \
|
||||
-e "s|\${DOMAIN}|${DOMAIN}|g" \
|
||||
-e "s|\${UUID}|${UUID}|g" \
|
||||
-e "s|\${REALITY_SERVER_NAME}|${REALITY_SERVER_NAME}|g" \
|
||||
-e "s|\${REALITY_PUBLIC_KEY}|${REALITY_PUBLIC_KEY}|g" \
|
||||
-e "s|\${REALITY_SHORT_ID}|${REALITY_SHORT_ID}|g" \
|
||||
-e "s|\${HY2_PASSWORD}|${HY2_PASSWORD}|g" \
|
||||
"$ROOT_DIR/client/sing-box-client.json.template" > "$CLIENT_DIR/sing-box-client.json"
|
||||
|
||||
# 生成分享链接
|
||||
cat > "$CLIENT_DIR/share-links.txt" <<EOF
|
||||
========== VLESS + Reality (主力) ==========
|
||||
vless://${UUID}@${VPS_IP}:443?encryption=none&flow=xtls-rprx-vision&security=reality&sni=${REALITY_SERVER_NAME}&fp=chrome&pbk=${REALITY_PUBLIC_KEY}&sid=${REALITY_SHORT_ID}&type=tcp#Reality-Main
|
||||
|
||||
========== Hysteria2 (备用) ==========
|
||||
hy2://${HY2_PASSWORD}@${DOMAIN}:8443?sni=${DOMAIN}#Hysteria2-Backup
|
||||
|
||||
========== 参数明细 ==========
|
||||
VPS IP: ${VPS_IP}
|
||||
UUID: ${UUID}
|
||||
Reality SNI: ${REALITY_SERVER_NAME}
|
||||
Reality PublicKey: ${REALITY_PUBLIC_KEY}
|
||||
Reality ShortId: ${REALITY_SHORT_ID}
|
||||
Hysteria2 域名: ${DOMAIN}
|
||||
Hysteria2 密码: ${HY2_PASSWORD}
|
||||
EOF
|
||||
systemctl restart sing-box jiedian-panel
|
||||
|
||||
log "部署完成!"
|
||||
echo ""
|
||||
cat "$CLIENT_DIR/share-links.txt"
|
||||
echo "=========================================="
|
||||
echo " 管理面板: https://${DOMAIN}:8444"
|
||||
echo " 用户名: ${PANEL_USERNAME}"
|
||||
echo " 密码: ${PANEL_PASSWORD}"
|
||||
echo "=========================================="
|
||||
echo ""
|
||||
log "客户端配置文件: ${CLIENT_DIR}/sing-box-client.json"
|
||||
log "sing-box 状态: systemctl status sing-box"
|
||||
log "查看日志: journalctl -u sing-box -f"
|
||||
echo "节点链接请在面板中添加/复制。"
|
||||
echo ""
|
||||
log "sing-box: systemctl status sing-box"
|
||||
log "面板: systemctl status jiedian-panel"
|
||||
log "卸载重装: bash scripts/uninstall.sh && bash scripts/install.sh"
|
||||
|
||||
Reference in New Issue
Block a user