Skip to content

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 18:50
· 45 commits to main since this release

v1.1.0 — маршрутизация MTProxy через Xray-router

English · Русский

Дата: 2026-10-01. Предыдущий выпуск: v1.0.3.

Меняются панель (миграция базы 21), менеджер Xray-router и compose.xray-router.yaml (новый сервис xray-router-ingress). На узлах с Xray-router после обновления панели пересоберите роутер и поднимите мост — команда ниже. Полный список опубликованных файлов и контрольные суммы — на странице выпуска.

Русский

Добавлено

  • MTProxy можно маршрутизировать. Раньше экран «Маршрутизация» показывал для MTProxy «вне области». Теперь MTProxy подключается к Xray-router узла, как NaiveProxy и Mieru, и выходит в интернет так, как скажет политика:

    • через WARP узла;
    • через свой выход (SOCKS, HTTP, VLESS, Trojan, Shadowsocks);
    • через другой узел парка, например: центр в одной стране, а трафик Telegram выходит в другой.

    Правила по CIDR, geoip и порту работают. Правила по домену, geosite и протоколу предпросмотр отклоняет и объясняет почему: Telemt ходит к дата-центрам Telegram по IP, и такое правило никогда бы не сработало.

  • Подключение без перезапуска Telemt. «Подключить к Xray-router» меняет upstream Telemt через его API и включает новую конфигурацию на лету. Открытые сессии доживают на прежнем пути. «Отключить» возвращает тот upstream, что был до подключения. «Откатить» работает и для MTProxy.

  • Мост xray-router-ingress. Telemt работает в сети Docker, а Xray-router — в сети хоста. Между ними теперь маленький мост из того же образа, что и роутер:

    • новых портов на хосте нет;
    • правил firewall не нужно;
    • второго Xray нет, маршрутизирует тот же роутер.

    Учётку для этого входа роутер создаёт сам.

  • Понятные ответы. Если роутер узла ещё не пересобран, экран говорит об этом прямо (router_lacks_mtproxy), а NaiveProxy и Mieru работают как раньше. Если не отвечает мост — ingress_unreachable. Если связанный узел старше v1.1 — node_lacks_mtproxy_egress.

  • Обновление одной командой. Уже установленный сервер обновляется тем же скриптом, что ставит новый:

    curl -fsSLO https://github.com/dubr1k/proxy-control/releases/latest/download/install-release.sh
    curl -fsSLO https://github.com/dubr1k/proxy-control/releases/latest/download/install-release.sh.sha256
    sha256sum --check install-release.sh.sha256
    bash install-release.sh --update

    Скрипт проверяет выпуск так же, как при установке, затем version-agent сервера обновляет панель (с резервной копией и откатом), а изменившиеся менеджеры пересобираются сами. Telemt, сертификаты, .env и secrets/ не трогаются.

Изменено

  • Установщик поднимает, проверяет и удаляет мост вместе с Xray-router. Вопрос мастера про Xray-router и install-release.sh --requirements упоминают MTProxy.

Обновление с v1.0.3

С v1.1.0 обновление делается одной командой — bash install-release.sh --update (выше): она выполнит шаги 1 и 2. Вручную:

  1. «Версии» → карточка «Proxy Control / панель» → 1.1.0 → «Установить».

  2. На узлах с Xray-router (карточка скажет «Изменились менеджеры: xray_router_manager»):

    cd /opt/mtproxy-shared443
    docker compose --env-file .env --env-file .env.mieru --env-file .env.xray-router --env-file .env.naive \
      -f compose.yaml -f compose.mieru.yaml -f compose.xray-router.yaml -f compose.naive.yaml \
      up -d --build --no-deps --wait xray-router xray-router-ingress

    Оставьте только те --env-file и -f, которые есть у вашей установки. Роутер один раз перезапустится.

  3. В парке сначала обновите узлы, потом центр.

Подробности — UPGRADING, устройство — ROUTING и XRAY_ROUTER.

English

Added

  • MTProxy can be routed. The «Routing» screen used to say MTProxy was out of scope. Now MTProxy attaches to the node's Xray-router like NaiveProxy and Mieru and leaves the way the policy says:

    • through the node's WARP;
    • through your own exit (SOCKS, HTTP, VLESS, Trojan, Shadowsocks);
    • through another node of the fleet — for example, a central in one country while Telegram traffic leaves in another.

    Rules by CIDR, geoip and port work. Rules by domain, geosite and protocol are refused in the preview, with the reason: Telemt reaches Telegram's data centres by IP, so such a rule could never match.

  • Attaching without restarting Telemt. «Attach to the Xray-router» changes Telemt's upstream through its API and activates the new configuration on the fly. Open sessions finish on the previous path. «Detach» puts back the upstream Telemt had before. «Rollback» works for MTProxy too.

  • The xray-router-ingress bridge. Telemt runs on the Docker network and the Xray-router on the host network. A small bridge from the router's own image now sits between them:

    • no new host ports;
    • no firewall rules;
    • no second Xray — the same router routes the traffic.

    The router mints the credential for this ingress itself.

  • Clear answers. If the node's router has not been rebuilt yet, the screen says so (router_lacks_mtproxy), while NaiveProxy and Mieru keep working. If the bridge does not answer — ingress_unreachable. If a linked node is older than v1.1 — node_lacks_mtproxy_egress.

  • One-command updates. An installed server updates with the same script that installs a new one:

    curl -fsSLO https://github.com/dubr1k/proxy-control/releases/latest/download/install-release.sh
    curl -fsSLO https://github.com/dubr1k/proxy-control/releases/latest/download/install-release.sh.sha256
    sha256sum --check install-release.sh.sha256
    bash install-release.sh --update

    The script verifies the release exactly as for an install, then the server's version-agent updates the panel (with a backup and a rollback) and the changed managers are rebuilt by themselves. Telemt, certificates, .env and secrets/ are not touched.

Changed

  • The installer starts, verifies and removes the bridge together with the Xray-router. The wizard's Xray-router question and install-release.sh --requirements mention MTProxy.

Upgrading from v1.0.3

From v1.1.0 on, the update is one command — bash install-release.sh --update (above): it does steps 1 and 2. By hand:

  1. «Versions» → the «Proxy Control / panel» card → 1.1.0 → «Install».

  2. On nodes with an Xray-router (the card says «Managers changed: xray_router_manager»):

    cd /opt/mtproxy-shared443
    docker compose --env-file .env --env-file .env.mieru --env-file .env.xray-router --env-file .env.naive \
      -f compose.yaml -f compose.mieru.yaml -f compose.xray-router.yaml -f compose.naive.yaml \
      up -d --build --no-deps --wait xray-router xray-router-ingress

    Keep only the --env-file and -f your installation has. The router restarts once.

  3. In a fleet, update the nodes first, then the central.

Details: UPGRADING; how it works: ROUTING and XRAY_ROUTER.