-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathproxy-proxy.example.yaml
More file actions
94 lines (86 loc) · 3.57 KB
/
Copy pathproxy-proxy.example.yaml
File metadata and controls
94 lines (86 loc) · 3.57 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# proxy-proxy example config.
# Copy to proxy-proxy.yaml and fill in your real subscriptions and keys:
# cp proxy-proxy.example.yaml proxy-proxy.yaml
# --- optional server settings ---------------------------------------------
# listen: :8080 # HTTP listen address (change requires restart)
# user_agent: clash.meta/1.19.0 # UA sent to upstream providers
# timeout: 30s # upstream fetch timeout
# --- upstream subscriptions -----------------------------------------------
# Set exactly one source on each entry: `url` for HTTP(S), or `file` for a
# local filesystem path.
subs:
- url: https://provider-a.example.com/sub/xxxxxxxx
type: auto # auto | base64 | raw | clash (default: auto)
# refresh period: units s/sec, m/min, h/hr, d/day (e.g. 3h, 30min, 2hr, 1d, 1h30m; default 1h, min 1m)
interval: 3h
name: Provider A # optional; referenced by allowed_subs (defaults to the URL host)
- url: https://provider-b.example.com/clash.yaml
type: clash
interval: 1d
name: Provider B
# Local subscriptions use a filesystem path. The path is inside the process
# (for Docker, mount the file into the container first).
- file: /etc/proxy-proxy/local-subscription.txt
type: auto
interval: 1h
name: Local file
# --- downstream access keys -----------------------------------------------
# Users subscribe to: http://your-host:8080/sub?key=<key>
keys:
- key: pp-change-me-1
# no allowed_subs = this key sees ALL subs
- key: pp-change-me-2
allowed_subs: # names must match subs above
- Provider A
# --- relay (optional) -----------------------------------------------------
# Re-serve upstream proxies of any type mihomo supports (wireguard, vless,
# hysteria2, ...) as plain http/socks5 proxies. The caller's username picks
# the relay, so relays can share one port:
# socks5://pool:change-me@your-host:1080 -> relay pool
# socks5://wg:change-me@your-host:1080 -> relay wg
# Invalid relays, and every relay in a port/username conflict, are skipped
# with an error in the log; the rest keep working. YAML mistakes (a misspelled
# field, a wrong value type) still reject the whole file.
relay:
- name: pool
# how to pick among several upstreams (default url-test):
# url-test | fallback | round-robin | consistent-hashing | sticky-sessions
strategy: url-test
upstream:
# every node of a sub above, by name...
- sub: Provider B
# ...or by URL (http:// or https://), fetched for relays only
- sub: https://provider-c.example.com/sub/xxxxxxxx
interval: 3h # URL only (default 1h, min 1m); a sub by name keeps its own
# an inline Clash proxy, handed to mihomo as-is
- name: my-trojan
type: trojan
server: trojan.example.com
port: 443
password: <trojan password>
sni: trojan.example.com
downstream:
- type: mixed # http | socks5 | mixed (default: http and socks5 on one port)
port: 1080
username: pool # username without password works with type http only
password: change-me
- name: wg
upstream:
- name: wg
type: wireguard
server: wg.example.com
port: 51820
ip: 10.0.0.2
private-key: <client private key>
public-key: <server public key>
udp: true
downstream:
# same port as pool, told apart by username
- type: mixed
port: 1080
username: wg
password: change-me
# a port without username belongs to this relay alone, and relays UDP too
- type: socks5
listen: 127.0.0.1
port: 1081