feat: add per-edge sing-box GitOps projects

This commit is contained in:
Codex
2026-07-19 08:11:52 -07:00
commit bab0625575
7 changed files with 183 additions and 0 deletions
+5
View File
@@ -0,0 +1,5 @@
DOMAIN=dc9.example.com
ACME_EMAIL=admin@example.com
USER1_PASSWORD=change-me
CLOUDFLARE_API_TOKEN=change-me
+40
View File
@@ -0,0 +1,40 @@
services:
config-render:
image: alpine:3.20
environment:
DOMAIN: ${DOMAIN}
ACME_EMAIL: ${ACME_EMAIL}
USER1_PASSWORD: ${USER1_PASSWORD}
CLOUDFLARE_API_TOKEN: ${CLOUDFLARE_API_TOKEN}
volumes:
- ./etc/sing-box/config.json.template:/template/config.json.template:ro
- sing-box-config:/output
command:
- /bin/sh
- -ec
- |
apk add --no-cache gettext
envsubst < /template/config.json.template > /output/config.json
chmod 600 /output/config.json
restart: "no"
sing-box:
image: ghcr.io/sagernet/sing-box:v1.12.13
restart: unless-stopped
depends_on:
config-render:
condition: service_completed_successfully
volumes:
- sing-box-config:/etc/sing-box:ro
- sing-box-data:/var/lib/sing-box
command: -D /var/lib/sing-box -C /etc/sing-box/ run
network_mode: host
logging:
driver: json-file
options:
max-size: 200k
volumes:
sing-box-config:
sing-box-data:
@@ -0,0 +1,44 @@
{
"inbounds": [
{
"type": "trojan",
"tag": "trojan-in",
"listen": "::",
"listen_port": 7364,
"sniff": true,
"sniff_override_destination": true,
"users": [
{
"name": "user1",
"password": "${USER1_PASSWORD}"
}
],
"tls": {
"enabled": true,
"server_name": "${DOMAIN}",
"acme": {
"domain": "${DOMAIN}",
"email": "${ACME_EMAIL}",
"dns01_challenge": {
"provider": "cloudflare",
"api_token": "${CLOUDFLARE_API_TOKEN}"
}
}
},
"multiplex": {
"enabled": true
}
}
],
"outbounds": [
{
"type": "direct"
}
],
"log": {
"disabled": false,
"level": "info",
"timestamp": true
}
}