- Added `expose_upstream_errors` option to the configuration, allowing detailed error messages in JSON responses for 502 errors. - Implemented `writeBadGatewayJSON` function to streamline JSON error responses, including upstream error details when enabled. - Updated documentation to reflect changes in configuration and error handling behavior for improved diagnostics.
76 lines
3.1 KiB
YAML
76 lines
3.1 KiB
YAML
# Telemt API gateway — copy to config.yaml and mount into the container.
|
||
#
|
||
# Semantics: client calls GET /api/{alias}/health
|
||
# forwarded to GET {base_url}/v1/health
|
||
#
|
||
# Web UI (SvelteKit) в образе Docker встроен в тот же процесс: GET / — панель,
|
||
# /api/… — API. CORS для панели на том же origin не нужен.
|
||
|
||
listen: ":8080"
|
||
|
||
# Диагностика: при 502 от прокси в JSON добавляется error.detail с текстом ошибки RoundTrip (TLS, DNS, таймаут).
|
||
# Включайте только во внутренней сети — строка может содержать хосты/порты upstream.
|
||
# expose_upstream_errors: true
|
||
|
||
# If true, IP whitelist is not enforced (development only).
|
||
allow_all: false
|
||
|
||
# CIDR allowlist when allow_all is false. Empty list denies all clients.
|
||
# Можно указывать и одиночный IP (будет трактован как /32 или /128), и CIDR.
|
||
whitelist_cidrs:
|
||
- "127.0.0.1/32"
|
||
- "203.0.113.5"
|
||
- "::1/128"
|
||
# Docker bridge (adjust to your environment):
|
||
# - "172.16.0.0/12"
|
||
|
||
# When the direct TCP peer is in these CIDRs, client IP for whitelist is taken
|
||
# from X-Forwarded-For (first hop) or X-Real-IP (e.g. behind nginx).
|
||
# trusted_proxies:
|
||
# - "10.0.0.0/8"
|
||
trusted_proxies: []
|
||
|
||
# CORS только если фронт на другом origin (например Vite :5173 при разработке).
|
||
# В production за nginx на одном хосте с шлюзом обычно не требуется.
|
||
# cors_allowed_origins:
|
||
# - "http://localhost:5173"
|
||
# # - "*"
|
||
|
||
# Опционально: по умолчанию /api/agg/* опрашивает все servers; можно ограничить список и включить кэш ответов:
|
||
# aggregate:
|
||
# include_aliases:
|
||
# - gt1
|
||
# - gt2
|
||
# cache_ttl_ms: 2000
|
||
|
||
# Геолокация IP в /api/agg/unique-ips. См. docs/GEOIP.md (City + опционально ASN; Country-only не нужен)
|
||
# geoip:
|
||
# enabled: true
|
||
# database_path: /var/lib/telemt-gateway/GeoLite2-City.mmdb
|
||
# download_url: "https://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-City.mmdb"
|
||
# asn_database_path: /var/lib/telemt-gateway/GeoLite2-ASN.mmdb
|
||
# asn_download_url: "https://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-ASN.mmdb"
|
||
|
||
servers:
|
||
- alias: main_srv
|
||
base_url: http://127.0.0.1:9091
|
||
path_prefix: /v1
|
||
# authorization_env: TELEMT_API_AUTH
|
||
# Mihomo: тот же compose-сервис (container_name: mihomo, сеть proxy-net, external-controller :9090).
|
||
# У процесса/контейнера gateway в environment: TELEMT_MIHOMO_AUTH=Bearer ${CLASH_SECRET} (как у mihomo).
|
||
mihomo_base_url: http://172.20.0.2:9090
|
||
mihomo_authorization_env: Bearer Ifwrbqifwrbq1995
|
||
|
||
# ivx: HTTPS + nginx location /api/ → Telemt; base_url должен заканчиваться на /api/
|
||
- alias: gt1
|
||
base_url: https://gt1.ivx.su/api/
|
||
path_prefix: /v1
|
||
|
||
- alias: gt2
|
||
base_url: https://gt2.ivx.su/api/
|
||
path_prefix: /v1
|
||
|
||
- alias: gt3
|
||
base_url: https://gt3.ivx.su/api/
|
||
path_prefix: /v1
|