install_script_standalone.sh 35 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070
  1. #!/usr/bin/env bash
  2. PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
  3. export PATH
  4. # System Required: CentOS 7+/Ubuntu 18+/Debian 10+
  5. # Version: v1.3.3
  6. # Description: One click Install Trojan Panel standalone server
  7. # Author: jonssonyan <https://jonssonyan.com>
  8. # Github: https://github.com/trojanpanel/install-script
  9. init_var() {
  10. ECHO_TYPE="echo -e"
  11. package_manager=""
  12. release=""
  13. get_arch=""
  14. can_google=0
  15. # Docker
  16. DOCKER_MIRROR='"https://registry.docker-cn.com","https://hub-mirror.c.163.com","https://docker.mirrors.ustc.edu.cn"'
  17. # 项目目录
  18. TP_DATA="/tpdata/"
  19. STATIC_HTML="https://github.com/trojanpanel/install-script/releases/download/v1.0.0/html.tar.gz"
  20. # Caddy
  21. CADDY_DATA="/tpdata/caddy/"
  22. CADDY_Caddyfile="/tpdata/caddy/Caddyfile"
  23. CADDY_SRV="/tpdata/caddy/srv/"
  24. CADDY_ACME="/tpdata/caddy/acme/"
  25. DOMAIN_FILE="/tpdata/caddy/domain.lock"
  26. domain=""
  27. caddy_remote_port=8863
  28. your_email="[email protected]"
  29. crt_path=""
  30. key_path=""
  31. ssl_option=1
  32. # trojanGFW
  33. TROJANGFW_DATA="/tpdata/trojanGFW/"
  34. TROJANGFW_STANDALONE_CONFIG="/tpdata/trojanGFW/standalone_config.json"
  35. trojanGFW_port=443
  36. # trojanGO
  37. TROJANGO_DATA="/tpdata/trojanGO/"
  38. TROJANGO_STANDALONE_CONFIG="/tpdata/trojanGO/standalone_config.json"
  39. trojanGO_port=443
  40. trojanGO_websocket_enable=false
  41. trojanGO_websocket_path="trojan-panel-websocket-path"
  42. trojanGO_shadowsocks_enable=false
  43. trojanGO_shadowsocks_method="AES-128-GCM"
  44. trojanGO_shadowsocks_password=""
  45. trojanGO_mux_enable=true
  46. # trojan
  47. trojan_pas=""
  48. remote_addr="127.0.0.1"
  49. # hysteria
  50. HYSTERIA_DATA="/tpdata/hysteria/"
  51. HYSTERIA_STANDALONE_CONFIG="/tpdata/hysteria/standalone_config.json"
  52. hysteria_port=443
  53. hysteria_password=""
  54. hysteria_protocol="udp"
  55. hysteria_up_mbps=100
  56. hysteria_down_mbps=100
  57. # naiveproxy
  58. NAIVEPROXY_DATA="/tpdata/naiveproxy/"
  59. NAIVEPROXY_STANDALONE_CONFIG="/tpdata/naiveproxy/standalone_config.json"
  60. naiveproxy_port=443
  61. naiveproxy_username=""
  62. naiveproxy_pass=""
  63. }
  64. echo_content() {
  65. case $1 in
  66. "red")
  67. ${ECHO_TYPE} "\033[31m$2\033[0m"
  68. ;;
  69. "green")
  70. ${ECHO_TYPE} "\033[32m$2\033[0m"
  71. ;;
  72. "yellow")
  73. ${ECHO_TYPE} "\033[33m$2\033[0m"
  74. ;;
  75. "blue")
  76. ${ECHO_TYPE} "\033[34m$2\033[0m"
  77. ;;
  78. "purple")
  79. ${ECHO_TYPE} "\033[35m$2\033[0m"
  80. ;;
  81. "skyBlue")
  82. ${ECHO_TYPE} "\033[36m$2\033[0m"
  83. ;;
  84. "white")
  85. ${ECHO_TYPE} "\033[37m$2\033[0m"
  86. ;;
  87. esac
  88. }
  89. mkdir_tools() {
  90. # 项目目录
  91. mkdir -p ${TP_DATA}
  92. # Caddy
  93. mkdir -p ${CADDY_DATA}
  94. touch ${CADDY_Caddyfile}
  95. mkdir -p ${CADDY_SRV}
  96. mkdir -p ${CADDY_ACME}
  97. # trojanGFW
  98. mkdir -p ${TROJANGFW_DATA}
  99. touch ${TROJANGFW_STANDALONE_CONFIG}
  100. # trojanGO
  101. mkdir -p ${TROJANGO_DATA}
  102. touch ${TROJANGO_STANDALONE_CONFIG}
  103. # hysteria
  104. mkdir -p ${HYSTERIA_DATA}
  105. touch ${HYSTERIA_STANDALONE_CONFIG}
  106. # naiveproxy
  107. mkdir -p ${NAIVEPROXY_DATA}
  108. touch ${NAIVEPROXY_STANDALONE_CONFIG}
  109. }
  110. can_connect() {
  111. ping -c2 -i0.3 -W1 "$1" &>/dev/null
  112. if [[ "$?" == "0" ]]; then
  113. return 0
  114. else
  115. return 1
  116. fi
  117. }
  118. check_sys() {
  119. if [[ $(command -v yum) ]]; then
  120. package_manager='yum'
  121. elif [[ $(command -v dnf) ]]; then
  122. package_manager='dnf'
  123. elif [[ $(command -v apt) ]]; then
  124. package_manager='apt'
  125. elif [[ $(command -v apt-get) ]]; then
  126. package_manager='apt-get'
  127. fi
  128. if [[ -z "${package_manager}" ]]; then
  129. echo_content red "暂不支持该系统"
  130. exit 0
  131. fi
  132. if [[ -n $(find /etc -name "redhat-release") ]] || grep </proc/version -q -i "centos"; then
  133. release="centos"
  134. elif grep </etc/issue -q -i "debian" && [[ -f "/etc/issue" ]] || grep </etc/issue -q -i "debian" && [[ -f "/proc/version" ]]; then
  135. release="debian"
  136. elif grep </etc/issue -q -i "ubuntu" && [[ -f "/etc/issue" ]] || grep </etc/issue -q -i "ubuntu" && [[ -f "/proc/version" ]]; then
  137. release="ubuntu"
  138. fi
  139. if [[ -z "${release}" ]]; then
  140. echo_content red "仅支持CentOS 7+/Ubuntu 18+/Debian 10+系统"
  141. exit 0
  142. fi
  143. if [[ $(arch) =~ ("x86_64"|"amd64"|"arm64"|"aarch64"|"arm"|"s390x") ]]; then
  144. get_arch=$(arch)
  145. fi
  146. if [[ -z "${get_arch}" ]]; then
  147. echo_content red "仅支持amd64/arm64/arm/s390x处理器架构"
  148. exit 0
  149. fi
  150. }
  151. depend_install() {
  152. if [[ "${package_manager}" != 'yum' && "${package_manager}" != 'dnf' ]]; then
  153. ${package_manager} update -y
  154. fi
  155. ${package_manager} install -y \
  156. curl \
  157. wget \
  158. tar \
  159. lsof \
  160. systemd
  161. }
  162. # 安装Docker
  163. install_docker() {
  164. if [[ ! $(docker -v 2>/dev/null) ]]; then
  165. echo_content green "---> 安装Docker"
  166. # 关闭防火墙
  167. if [[ "$(firewall-cmd --state 2>/dev/null)" == "running" ]]; then
  168. systemctl stop firewalld.service && systemctl disable firewalld.service
  169. fi
  170. # 时区
  171. timedatectl set-timezone Asia/Shanghai
  172. can_connect www.google.com
  173. [[ "$?" == "0" ]] && can_google=1
  174. if [[ ${can_google} == 0 ]]; then
  175. sh <(curl -sL https://get.docker.com) --mirror Aliyun
  176. # 设置Docker国内源
  177. mkdir -p /etc/docker &&
  178. cat >/etc/docker/daemon.json <<EOF
  179. {
  180. "registry-mirrors":[${DOCKER_MIRROR}],
  181. "log-driver":"json-file",
  182. "log-opts":{
  183. "max-size":"50m",
  184. "max-file":"3"
  185. }
  186. }
  187. EOF
  188. else
  189. sh <(curl -sL https://get.docker.com)
  190. fi
  191. systemctl enable docker &&
  192. systemctl restart docker
  193. if [[ $(docker -v 2>/dev/null) ]]; then
  194. echo_content skyBlue "---> Docker安装完成"
  195. else
  196. echo_content red "---> Docker安装失败"
  197. exit 0
  198. fi
  199. else
  200. echo_content skyBlue "---> 你已经安装了Docker"
  201. fi
  202. }
  203. # 安装Caddy TLS
  204. install_caddy_tls() {
  205. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  206. echo_content green "---> 安装Caddy TLS"
  207. wget --no-check-certificate -O ${CADDY_DATA}html.tar.gz ${STATIC_HTML} &&
  208. tar -zxvf ${CADDY_DATA}html.tar.gz -C ${CADDY_SRV}
  209. read -r -p "请输入Caddy的转发端口(用于申请证书,默认:8863): " caddy_remote_port
  210. [[ -z "${caddy_remote_port}" ]] && caddy_remote_port=8863
  211. while read -r -p "请输入你的域名(必填): " domain; do
  212. if [[ -z "${domain}" ]]; then
  213. echo_content red "域名不能为空"
  214. else
  215. break
  216. fi
  217. done
  218. mkdir "${CADDY_ACME}${domain}"
  219. while read -r -p "请选择设置证书的方式?(1/自动申请和续签证书 2/手动设置证书路径 默认:1/自动申请和续签证书): " ssl_option; do
  220. if [[ -z ${ssl_option} || ${ssl_option} == 1 ]]; then
  221. echo_content yellow "正在检测域名,请稍后..."
  222. ping_ip=$(ping "${domain}" -s1 -c1 | grep "ttl=" | head -n1 | cut -d"(" -f2 | cut -d")" -f1)
  223. curl_ip=$(curl ifconfig.me)
  224. if [[ "${ping_ip}" != "${curl_ip}" ]]; then
  225. echo_content yellow "你的域名没有解析到本机IP,请稍后再试"
  226. echo_content red "---> Caddy安装失败"
  227. exit 0
  228. fi
  229. read -r -p "请输入你的邮箱(用于申请证书,默认:[email protected]): " your_email
  230. [[ -z "${your_email}" ]] && your_email="[email protected]"
  231. cat >${CADDY_Caddyfile} <<EOF
  232. http://${domain}:80 {
  233. redir https://${domain}:${caddy_remote_port}{url}
  234. }
  235. https://${domain}:${caddy_remote_port} {
  236. gzip
  237. tls ${your_email}
  238. root ${CADDY_SRV}
  239. }
  240. EOF
  241. break
  242. else
  243. if [[ ${ssl_option} != 2 ]]; then
  244. echo_content red "不可以输入除1和2之外的其他字符"
  245. else
  246. while read -r -p "请输入证书的.crt文件路径(必填): " crt_path; do
  247. if [[ -z "${crt_path}" ]]; then
  248. echo_content red "路径不能为空"
  249. else
  250. if [[ ! -f "${crt_path}" ]]; then
  251. echo_content red "证书的.crt文件路径不存在"
  252. else
  253. cp "${crt_path}" "${CADDY_ACME}${domain}/${domain}.crt"
  254. break
  255. fi
  256. fi
  257. done
  258. while read -r -p "请输入证书的.key文件路径(必填): " key_path; do
  259. if [[ -z "${key_path}" ]]; then
  260. echo_content red "路径不能为空"
  261. else
  262. if [[ ! -f "${key_path}" ]]; then
  263. echo_content red "证书的.key文件路径不存在"
  264. else
  265. cp "${key_path}" "${CADDY_ACME}${domain}/${domain}.key"
  266. break
  267. fi
  268. fi
  269. done
  270. cat >${CADDY_Caddyfile} <<EOF
  271. http://${domain}:80 {
  272. redir https://${domain}:${caddy_remote_port}{url}
  273. }
  274. https://${domain}:${caddy_remote_port} {
  275. gzip
  276. tls /root/.caddy/acme/acme-v02.api.letsencrypt.org/sites/${domain}/${domain}.crt /root/.caddy/acme/acme-v02.api.letsencrypt.org/sites/${domain}/${domain}.key
  277. root ${CADDY_SRV}
  278. }
  279. EOF
  280. break
  281. fi
  282. fi
  283. done
  284. if [[ -n $(lsof -i:80,443 -t) ]]; then
  285. kill -9 "$(lsof -i:80,443 -t)"
  286. fi
  287. docker pull teddysun/caddy:1.0.5 &&
  288. docker run -d --name trojan-panel-caddy --restart always \
  289. --network=host \
  290. -v ${CADDY_Caddyfile}:"/etc/caddy/Caddyfile" \
  291. -v ${CADDY_ACME}:"/root/.caddy/acme/acme-v02.api.letsencrypt.org/sites/" \
  292. -v ${CADDY_SRV}:${CADDY_SRV} \
  293. teddysun/caddy:1.0.5
  294. if [[ -n $(docker ps -q -f "name=^trojan-panel-caddy$" -f "status=running") ]]; then
  295. cat >${DOMAIN_FILE} <<EOF
  296. ${domain}
  297. EOF
  298. echo_content skyBlue "---> Caddy安装完成"
  299. else
  300. echo_content red "---> Caddy安装失败或运行异常,请尝试修复或卸载重装"
  301. exit 0
  302. fi
  303. else
  304. domain=$(cat "${DOMAIN_FILE}")
  305. echo_content skyBlue "---> 你已经安装了Caddy"
  306. fi
  307. }
  308. # TrojanGFW+Caddy+Web+TLS+Websocket
  309. install_trojan_gfw_standalone() {
  310. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") ]]; then
  311. echo_content green "---> 安装TrojanGFW+Caddy+Web+TLS+Websocket"
  312. read -r -p "请输入TrojanGFW的端口(默认:443): " trojanGFW_port
  313. [[ -n ${trojanGFW_port} ]] && trojanGFW_port=443
  314. while read -r -p "请输入TrojanGFW的密码(必填): " trojan_pas; do
  315. if [[ -z "${trojan_pas}" ]]; then
  316. echo_content red "密码不能为空"
  317. else
  318. break
  319. fi
  320. done
  321. cat >${TROJANGFW_STANDALONE_CONFIG} <<EOF
  322. {
  323. "run_type": "server",
  324. "local_addr": "0.0.0.0",
  325. "local_port": ${trojanGFW_port},
  326. "remote_addr": "${remote_addr}",
  327. "remote_port": 80,
  328. "password": [
  329. "${trojan_pas}"
  330. ],
  331. "log_level": 1,
  332. "ssl": {
  333. "cert": "${CADDY_ACME}${domain}/${domain}.crt",
  334. "key": "${CADDY_ACME}${domain}/${domain}.key",
  335. "key_password": "",
  336. "cipher": "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384",
  337. "cipher_tls13": "TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384",
  338. "prefer_server_cipher": true,
  339. "alpn": [
  340. "http/1.1"
  341. ],
  342. "alpn_port_override": {
  343. "h2": 81
  344. },
  345. "reuse_session": true,
  346. "session_ticket": false,
  347. "session_timeout": 600,
  348. "plain_http_response": "",
  349. "curves": "",
  350. "dhparam": ""
  351. },
  352. "tcp": {
  353. "prefer_ipv4": false,
  354. "no_delay": true,
  355. "keep_alive": true,
  356. "reuse_port": false,
  357. "fast_open": false,
  358. "fast_open_qlen": 20
  359. },
  360. "mysql": {
  361. "enabled": false,
  362. "server_addr": "127.0.0.1",
  363. "server_port": 3306,
  364. "database": "",
  365. "username": "",
  366. "password": "",
  367. "key": "",
  368. "cert": "",
  369. "ca": ""
  370. }
  371. }
  372. EOF
  373. docker pull trojangfw/trojan &&
  374. docker run -d --name trojan-panel-trojanGFW-standalone --restart always \
  375. --network=host \
  376. -v ${TROJANGFW_STANDALONE_CONFIG}:"/config/config.json" \
  377. -v ${CADDY_ACME}:${CADDY_ACME} \
  378. trojangfw/trojan
  379. if [[ -n $(docker ps -q -f "name=^trojan-panel-trojanGFW-standalone$" -f "status=running") ]]; then
  380. echo_content skyBlue "---> TrojanGFW+Caddy+Web+TLS 安装完成"
  381. echo_content red "\n=============================================================="
  382. echo_content skyBlue "TrojanGFW+Caddy+Web+TLS 安装成功"
  383. echo_content yellow "域名: ${domain}"
  384. echo_content yellow "TrojanGFW的端口: ${trojanGFW_port}"
  385. echo_content yellow "TrojanGFW的密码: ${trojan_pas}"
  386. echo_content red "\n=============================================================="
  387. else
  388. echo_content red "---> TrojanGFW+Caddy+Web+TLS 安装失败或运行异常,请尝试修复或卸载重装"
  389. exit 0
  390. fi
  391. else
  392. echo_content skyBlue "---> 你已经安装了TrojanGFW+Caddy+Web+TLS"
  393. fi
  394. }
  395. # TrojanGO+Caddy+Web+TLS+Websocket
  396. install_trojanGO_standalone() {
  397. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") ]]; then
  398. echo_content green "---> 安装TrojanGO+Caddy+Web+TLS+Websocket"
  399. read -r -p "请输入TrojanGO的端口(默认:443): " trojanGO_port
  400. [[ -z "${trojanGO_port}" ]] && trojanGO_port=443
  401. while read -r -p "请输入TrojanGO的密码(必填): " trojan_pas; do
  402. if [[ -z "${trojan_pas}" ]]; then
  403. echo_content red "密码不能为空"
  404. else
  405. break
  406. fi
  407. done
  408. while read -r -p "是否开启多路复用?(false/关闭 true/开启 默认:true/开启): " trojanGO_mux_enable; do
  409. if [[ -z "${trojanGO_mux_enable}" || ${trojanGO_mux_enable} == true ]]; then
  410. trojanGO_mux_enable=true
  411. break
  412. else
  413. if [[ ${trojanGO_mux_enable} != false ]]; then
  414. echo_content red "不可以输入除false和true之外的其他字符"
  415. else
  416. break
  417. fi
  418. fi
  419. done
  420. while read -r -p "是否开启Websocket?(false/关闭 true/开启 默认:false/关闭): " trojanGO_websocket_enable; do
  421. if [[ -z "${trojanGO_websocket_enable}" || ${trojanGO_websocket_enable} == false ]]; then
  422. trojanGO_websocket_enable=false
  423. break
  424. else
  425. if [[ ${trojanGO_websocket_enable} != true ]]; then
  426. echo_content red "不可以输入除false和true之外的其他字符"
  427. else
  428. read -r -p "请输入Websocket路径(默认:trojan-panel-websocket-path): " trojanGO_websocket_path
  429. [[ -z "${trojanGO_websocket_path}" ]] && trojanGO_websocket_path="trojan-panel-websocket-path"
  430. break
  431. fi
  432. fi
  433. done
  434. while read -r -p "是否启用Shadowsocks AEAD加密?(false/关闭 true/开启 默认:false/关闭): " trojanGO_shadowsocks_enable; do
  435. if [[ -z "${trojanGO_shadowsocks_enable}" || ${trojanGO_shadowsocks_enable} == false ]]; then
  436. trojanGO_shadowsocks_enable=false
  437. break
  438. else
  439. if [[ ${trojanGO_shadowsocks_enable} != true ]]; then
  440. echo_content yellow "不可以输入除false和true之外的其他字符"
  441. else
  442. echo_content skyBlue "Shadowsocks AEAD加密方式如下:"
  443. echo_content yellow "1. AES-128-GCM(默认)"
  444. echo_content yellow "2. CHACHA20-IETF-POLY1305"
  445. echo_content yellow "3. AES-256-GCM"
  446. read -r -p "请输入Shadowsocks AEAD加密方式(默认:1): " select_method_type
  447. [[ -z "${select_method_type}" ]] && select_method_type=1
  448. case ${select_method_type} in
  449. 1)
  450. trojanGO_shadowsocks_method="AES-128-GCM"
  451. ;;
  452. 2)
  453. trojanGO_shadowsocks_method="CHACHA20-IETF-POLY1305"
  454. ;;
  455. 3)
  456. trojanGO_shadowsocks_method="AES-256-GCM"
  457. ;;
  458. *)
  459. trojanGO_shadowsocks_method="AES-128-GCM"
  460. ;;
  461. esac
  462. while read -r -p "请输入Shadowsocks AEAD加密密码(必填): " trojanGO_shadowsocks_password; do
  463. if [[ -z "${trojanGO_shadowsocks_password}" ]]; then
  464. echo_content red "密码不能为空"
  465. else
  466. break
  467. fi
  468. done
  469. break
  470. fi
  471. fi
  472. done
  473. cat >${TROJANGO_STANDALONE_CONFIG} <<EOF
  474. {
  475. "run_type": "server",
  476. "local_addr": "0.0.0.0",
  477. "local_port": ${trojanGO_port},
  478. "remote_addr": "${remote_addr}",
  479. "remote_port": 80,
  480. "log_level": 1,
  481. "log_file": "",
  482. "password": [
  483. "${trojan_pas}"
  484. ],
  485. "disable_http_check": false,
  486. "udp_timeout": 60,
  487. "ssl": {
  488. "verify": true,
  489. "verify_hostname": true,
  490. "cert": "${CADDY_ACME}${domain}/${domain}.crt",
  491. "key": "${CADDY_ACME}${domain}/${domain}.key",
  492. "key_password": "",
  493. "cipher": "",
  494. "curves": "",
  495. "prefer_server_cipher": false,
  496. "sni": "",
  497. "alpn": [
  498. "http/1.1"
  499. ],
  500. "session_ticket": true,
  501. "reuse_session": true,
  502. "plain_http_response": "",
  503. "fallback_addr": "",
  504. "fallback_port": 80,
  505. "fingerprint": ""
  506. },
  507. "tcp": {
  508. "no_delay": true,
  509. "keep_alive": true,
  510. "prefer_ipv4": false
  511. },
  512. "mux": {
  513. "enabled": ${trojanGO_mux_enable},
  514. "concurrency": 8,
  515. "idle_timeout": 60
  516. },
  517. "websocket": {
  518. "enabled": ${trojanGO_websocket_enable},
  519. "path": "/${trojanGO_websocket_path}",
  520. "host": "${domain}"
  521. },
  522. "shadowsocks": {
  523. "enabled": ${trojanGO_shadowsocks_enable},
  524. "method": "${trojanGO_shadowsocks_method}",
  525. "password": "${trojanGO_shadowsocks_password}"
  526. },
  527. "mysql": {
  528. "enabled": false,
  529. "server_addr": "localhost",
  530. "server_port": 3306,
  531. "database": "",
  532. "username": "",
  533. "password": "",
  534. "check_rate": 60
  535. }
  536. }
  537. EOF
  538. docker pull p4gefau1t/trojan-go &&
  539. docker run -d --name trojan-panel-trojanGO-standalone --restart=always \
  540. --network=host \
  541. -v ${TROJANGO_STANDALONE_CONFIG}:"/etc/trojan-go/config.json" \
  542. -v ${CADDY_ACME}:${CADDY_ACME} \
  543. p4gefau1t/trojan-go
  544. if [[ -n $(docker ps -q -f "name=^trojan-panel-trojanGO-standalone$" -f "status=running") ]]; then
  545. echo_content skyBlue "---> TrojanGO+Caddy+Web+TLS+Websocket 安装完成"
  546. echo_content red "\n=============================================================="
  547. echo_content skyBlue "TrojanGO+Caddy+Web+TLS+Websocket 安装成功"
  548. echo_content yellow "域名: ${domain}"
  549. echo_content yellow "TrojanGO的端口: ${trojanGO_port}"
  550. echo_content yellow "TrojanGO的密码: ${trojan_pas}"
  551. echo_content yellow "TrojanGO私钥和证书目录: ${CADDY_ACME}${domain}/"
  552. if [[ ${trojanGO_websocket_enable} == true ]]; then
  553. echo_content yellow "Websocket路径: ${trojanGO_websocket_path}"
  554. fi
  555. if [[ ${trojanGO_shadowsocks_enable} == true ]]; then
  556. echo_content yellow "Shadowsocks AEAD加密方式: ${trojanGO_shadowsocks_method}"
  557. echo_content yellow "Shadowsocks AEAD加密密码: ${trojanGO_shadowsocks_password}"
  558. fi
  559. echo_content red "\n=============================================================="
  560. else
  561. echo_content red "---> TrojanGO+Caddy+Web+TLS+Websocket 安装失败或运行异常,请尝试修复或卸载重装"
  562. exit 0
  563. fi
  564. else
  565. echo_content skyBlue "---> 你已经了安装了TrojanGO+Caddy+Web+TLS+Websocket"
  566. fi
  567. }
  568. # 安装Hysteria
  569. install_hysteria_standalone() {
  570. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") ]]; then
  571. echo_content green "---> 安装Hysteria"
  572. echo_content skyBlue "Hysteria的模式如下:"
  573. echo_content yellow "1. udp(默认)"
  574. echo_content yellow "2. faketcp"
  575. read -r -p "请输入Hysteria的模式(默认:1): " selectProtocolType
  576. [[ -z "${selectProtocolType}" ]] && selectProtocolType=1
  577. case ${selectProtocolType} in
  578. 1)
  579. hysteria_protocol="udp"
  580. ;;
  581. 2)
  582. hysteria_protocol="faketcp"
  583. ;;
  584. *)
  585. hysteria_protocol="udp"
  586. ;;
  587. esac
  588. read -r -p "请输入Hysteria的端口(默认:443): " hysteria_port
  589. [[ -z ${hysteria_port} ]] && hysteria_port=443
  590. read -r -p "请输入单客户端最大上传速度/Mbps(默认:100): " hysteria_up_mbps
  591. [[ -z "${hysteria_up_mbps}" ]] && hysteria_up_mbps=100
  592. read -r -p "请输入单客户端最大下载速度/Mbps(默认:100): " hysteria_down_mbps
  593. [[ -z "${hysteria_down_mbps}" ]] && hysteria_down_mbps=100
  594. while read -r -p "请输入Hysteria的密码(必填): " hysteria_password; do
  595. if [[ -z ${hysteria_password} ]]; then
  596. echo_content red "密码不能为空"
  597. else
  598. break
  599. fi
  600. done
  601. cat >${HYSTERIA_STANDALONE_CONFIG} <<EOF
  602. {
  603. "listen": ":${hysteria_port}",
  604. "protocol": "${hysteria_protocol}",
  605. "cert": "${CADDY_ACME}${domain}/${domain}.crt",
  606. "key": "${CADDY_ACME}${domain}/${domain}.key",
  607. "up_mbps": ${hysteria_up_mbps},
  608. "down_mbps": ${hysteria_down_mbps},
  609. "obfs": "${hysteria_password}"
  610. }
  611. EOF
  612. docker pull tobyxdd/hysteria &&
  613. docker run -d --name trojan-panel-hysteria-standalone --restart=always \
  614. --network=host \
  615. -v ${HYSTERIA_STANDALONE_CONFIG}:/etc/hysteria.json \
  616. -v ${CADDY_ACME}:${CADDY_ACME} \
  617. tobyxdd/hysteria -c /etc/hysteria.json server
  618. if [[ -n $(docker ps -q -f "name=^trojan-panel-hysteria-standalone$" -f "status=running") ]]; then
  619. echo_content skyBlue "---> Hysteria 安装完成"
  620. echo_content red "\n=============================================================="
  621. echo_content skyBlue "Hysteria 安装成功"
  622. echo_content yellow "域名: ${domain}"
  623. echo_content yellow "Hysteria的端口: ${hysteria_port}"
  624. echo_content yellow "Hysteria的密码: ${hysteria_password}"
  625. echo_content yellow "Hysteria私钥和证书目录: ${CADDY_ACME}${domain}/"
  626. echo_content red "\n=============================================================="
  627. else
  628. echo_content red "---> Hysteria 安装失败或运行异常,请尝试修复或卸载重装"
  629. exit 0
  630. fi
  631. else
  632. echo_content skyBlue "---> 你已经安装了Hysteria"
  633. fi
  634. }
  635. # 安装NaiveProxy(Caddy+ForwardProxy)
  636. install_navieproxy_standalone() {
  637. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-navieproxy-standalone$") ]]; then
  638. echo_content green "---> 安装NaiveProxy(Caddy+ForwardProxy)"
  639. read -r -p "请输入NaiveProxy的端口(默认:443): " naiveproxy_port
  640. [[ -z "${naiveproxy_port}" ]] && naiveproxy_port=443
  641. while read -r -p "请输入NaiveProxy的用户名(必填): " naiveproxy_username; do
  642. if [[ -z "${naiveproxy_username}" ]]; then
  643. echo_content red "用户名不能为空"
  644. else
  645. break
  646. fi
  647. done
  648. while read -r -p "请输入NaiveProxy的密码(必填): " naiveproxy_pass; do
  649. if [[ -z "${naiveproxy_pass}" ]]; then
  650. echo_content red "密码不能为空"
  651. else
  652. break
  653. fi
  654. done
  655. domain=$(cat "${DOMAIN_FILE}")
  656. cat >${NAIVEPROXY_STANDALONE_CONFIG} <<EOF
  657. {
  658. "admin": {
  659. "disabled": true
  660. },
  661. "logging": {
  662. "sink": {
  663. "writer": {
  664. "output": "discard"
  665. }
  666. },
  667. "logs": {
  668. "default": {
  669. "writer": {
  670. "output": "discard"
  671. }
  672. }
  673. }
  674. },
  675. "apps": {
  676. "http": {
  677. "servers": {
  678. "srv0": {
  679. "listen": [
  680. ":${naiveproxy_port}"
  681. ],
  682. "routes": [
  683. {
  684. "handle": [
  685. {
  686. "handler": "subroute",
  687. "routes": [
  688. {
  689. "handle": [
  690. {
  691. "auth_pass_deprecated": "${naiveproxy_pass}",
  692. "auth_user_deprecated": "${naiveproxy_username}",
  693. "handler": "forward_proxy",
  694. "hide_ip": true,
  695. "hide_via": true,
  696. "probe_resistance": {}
  697. }
  698. ]
  699. },
  700. {
  701. "match": [
  702. {
  703. "host": [
  704. "${domain}"
  705. ]
  706. }
  707. ],
  708. "handle": [
  709. {
  710. "handler": "file_server",
  711. "root": "/caddy-forwardproxy/dist/",
  712. "index_names": [
  713. "index.html",
  714. "index.htm"
  715. ]
  716. }
  717. ],
  718. "terminal": true
  719. }
  720. ]
  721. }
  722. ]
  723. }
  724. ],
  725. "tls_connection_policies": [
  726. {
  727. "match": {
  728. "sni": [
  729. "${domain}"
  730. ]
  731. }
  732. }
  733. ],
  734. "automatic_https": {
  735. "disable": true
  736. }
  737. }
  738. }
  739. },
  740. "tls": {
  741. "certificates": {
  742. "load_files": [
  743. {
  744. "certificate": "${CADDY_ACME}${domain}/${domain}.crt",
  745. "key": "${CADDY_ACME}${domain}/${domain}.key"
  746. }
  747. ]
  748. }
  749. }
  750. }
  751. }
  752. EOF
  753. docker pull jonssonyan/caddy-forwardproxy &&
  754. docker run -d --name trojan-panel-navieproxy-standalone --restart=always \
  755. --network=host \
  756. -v ${NAIVEPROXY_STANDALONE_CONFIG}:"/caddy-forwardproxy/config/config.json" \
  757. -v ${CADDY_ACME}:${CADDY_ACME} \
  758. jonssonyan/caddy-forwardproxy
  759. if [[ -n $(docker ps -q -f "name=^trojan-panel-navieproxy-standalone$" -f "status=running") ]]; then
  760. echo_content skyBlue "---> NaiveProxy(Caddy+ForwardProxy) 安装完成"
  761. echo_content red "\n=============================================================="
  762. echo_content skyBlue "NaiveProxy(Caddy+ForwardProxy) 安装成功"
  763. echo_content yellow "域名: ${domain}"
  764. echo_content yellow "NaiveProxy的端口: ${naiveproxy_port}"
  765. echo_content yellow "NaiveProxy的用户名: ${naiveproxy_username}"
  766. echo_content yellow "NaiveProxy的密码: ${naiveproxy_pass}"
  767. echo_content yellow "NaiveProxy私钥和证书目录: ${CADDY_ACME}${domain}/"
  768. echo_content red "\n=============================================================="
  769. else
  770. echo_content red "---> NaiveProxy(Caddy+ForwardProxy) 安装失败或运行异常,请尝试修复或卸载重装"
  771. exit 0
  772. fi
  773. else
  774. echo_content skyBlue "---> 你已经了安装了NaiveProxy(Caddy+ForwardProxy)"
  775. fi
  776. }
  777. # 卸载Caddy TLS
  778. uninstall_caddy_tls() {
  779. # 判断Caddy TLS是否安装
  780. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  781. echo_content green "---> 卸载Caddy TLS"
  782. docker rm -f trojan-panel-caddy &&
  783. rm -rf ${CADDY_DATA}
  784. echo_content skyBlue "---> Caddy TLS卸载完成"
  785. else
  786. echo_content red "---> 请先安装Caddy TLS"
  787. fi
  788. }
  789. # TrojanGFW+Caddy+Web+TLS
  790. uninstall_trojan_gfw_standalone() {
  791. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") ]]; then
  792. echo_content green "---> 卸载TrojanGFW+Caddy+Web+TLS"
  793. docker rm -f trojan-panel-trojanGFW-standalone &&
  794. docker rmi -f trojangfw/trojan &&
  795. rm -f ${TROJANGFW_STANDALONE_CONFIG}
  796. echo_content skyBlue "---> TrojanGFW+Caddy+Web+TLS 卸载完成"
  797. else
  798. echo_content red "---> 请先安装TrojanGFW+Caddy+Web+TLS"
  799. fi
  800. }
  801. # 卸载TrojanGO 单机版
  802. uninstall_trojanGO_standalone() {
  803. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") ]]; then
  804. echo_content green "---> 卸载TrojanGO+Caddy+Web+TLS+Websocket"
  805. docker rm -f trojan-panel-trojanGO-standalone &&
  806. docker rmi -f p4gefau1t/trojan-go &&
  807. rm -f ${TROJANGO_STANDALONE_CONFIG}
  808. echo_content skyBlue "---> TrojanGO+Caddy+Web+TLS+Websocket 卸载完成"
  809. else
  810. echo_content red "---> 请先安装TrojanGO+Caddy+Web+TLS+Websocket"
  811. fi
  812. }
  813. # 卸载Hysteria
  814. uninstall_hysteria_standalone() {
  815. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") ]]; then
  816. echo_content green "---> 卸载Hysteria"
  817. docker rm -f trojan-panel-hysteria-standalone &&
  818. docker rmi -f tobyxdd/hysteria &&
  819. rm -f ${HYSTERIA_STANDALONE_CONFIG}
  820. echo_content skyBlue "---> Hysteria 卸载完成"
  821. else
  822. echo_content red "---> 请先安装Hysteria"
  823. fi
  824. }
  825. # 卸载NaiveProxy(Caddy+ForwardProxy)
  826. uninstall_navieproxy_standalone() {
  827. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-navieproxy-standalone$") ]]; then
  828. echo_content green "---> 卸载NaiveProxy(Caddy+ForwardProxy)"
  829. docker rm -f trojan-panel-navieproxy-standalone &&
  830. docker rmi -f jonssonyan/caddy-forwardproxy &&
  831. rm -f ${NAIVEPROXY_STANDALONE_CONFIG}
  832. echo_content skyBlue "---> NaiveProxy(Caddy+ForwardProxy) 卸载完成"
  833. else
  834. echo_content red "---> 请先安装NaiveProxy(Caddy+ForwardProxy)"
  835. fi
  836. }
  837. # 卸载全部Trojan Panel相关的容器
  838. uninstall_all() {
  839. echo_content green "---> 卸载全部Trojan Panel相关的容器"
  840. docker rm -f $(docker ps -a -q -f "name=^trojan-panel") &&
  841. rm -rf ${TP_DATA}
  842. echo_content skyBlue "---> 卸载全部Trojan Panel相关的容器完成"
  843. }
  844. # 故障检测
  845. failure_testing() {
  846. echo_content green "---> 故障检测开始"
  847. if [[ ! $(docker -v 2>/dev/null) ]]; then
  848. echo_content red "---> Docker运行异常"
  849. else
  850. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  851. if [[ -z $(docker ps -q -f "name=^trojan-panel-caddy$" -f "status=running") ]]; then
  852. echo_content red "---> Caddy TLS运行异常"
  853. fi
  854. domain=$(cat "${DOMAIN_FILE}")
  855. if [[ -z $(cat "${DOMAIN_FILE}") || ! -d "${CADDY_ACME}${domain}" || ! -f "${CADDY_ACME}${domain}/${domain}.crt" ]]; then
  856. echo_content red "---> 证书申请异常,请尝试重启服务器将重新申请证书或者重新搭建选择自定义证书选项"
  857. fi
  858. fi
  859. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-trojanGFW-standalone$" -f "status=running") ]]; then
  860. echo_content red "---> TrojanGFW运行异常"
  861. fi
  862. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-trojanGO-standalone$" -f "status=running") ]]; then
  863. echo_content red "---> TrojanGO运行异常"
  864. fi
  865. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-hysteria-standalone$" -f "status=running") ]]; then
  866. echo_content red "---> Hysteria运行异常"
  867. fi
  868. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-navieproxy-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-navieproxy-standalone$" -f "status=running") ]]; then
  869. echo_content red "---> NaiveProxy(Caddy+ForwardProxy)运行异常"
  870. fi
  871. fi
  872. echo_content green "---> 故障检测结束"
  873. }
  874. # 卸载阿里云内置相关监控
  875. uninstall_aliyun() {
  876. # 卸载云监控(Cloudmonitor) Java 版
  877. /usr/local/cloudmonitor/wrapper/bin/cloudmonitor.sh stop &&
  878. /usr/local/cloudmonitor/wrapper/bin/cloudmonitor.sh remove &&
  879. rm -rf /usr/local/cloudmonitor
  880. # 卸载云盾(安骑士)
  881. wget --no-check-certificate -O uninstall.sh http://update.aegis.aliyun.com/download/uninstall.sh && chmod +x uninstall.sh && ./uninstall.sh
  882. wget --no-check-certificate -O quartz_uninstall.sh http://update.aegis.aliyun.com/download/quartz_uninstall.sh && chmod +x quartz_uninstall.sh && ./quartz_uninstall.sh
  883. pkill aliyun-service
  884. rm -fr /etc/init.d/agentwatch /usr/sbin/aliyun-service
  885. rm -rf /usr/local/aegis*
  886. iptables -I INPUT -s 140.205.201.0/28 -j DROP
  887. iptables -I INPUT -s 140.205.201.16/29 -j DROP
  888. iptables -I INPUT -s 140.205.201.32/28 -j DROP
  889. iptables -I INPUT -s 140.205.225.192/29 -j DROP
  890. iptables -I INPUT -s 140.205.225.200/30 -j DROP
  891. iptables -I INPUT -s 140.205.225.184/29 -j DROP
  892. iptables -I INPUT -s 140.205.225.183/32 -j DROP
  893. iptables -I INPUT -s 140.205.225.206/32 -j DROP
  894. iptables -I INPUT -s 140.205.225.205/32 -j DROP
  895. iptables -I INPUT -s 140.205.225.195/32 -j DROP
  896. iptables -I INPUT -s 140.205.225.204/32 -j DROP
  897. }
  898. main() {
  899. cd "$HOME" || exit 0
  900. init_var
  901. mkdir_tools
  902. check_sys
  903. depend_install
  904. clear
  905. echo_content red "\n=============================================================="
  906. echo_content skyBlue "System Required: CentOS 7+/Ubuntu 18+/Debian 10+"
  907. echo_content skyBlue "Version: v1.3.3"
  908. echo_content skyBlue "Description: One click Install Trojan Panel standalone server"
  909. echo_content skyBlue "Author: jonssonyan <https://jonssonyan.com>"
  910. echo_content skyBlue "Github: https://github.com/trojanpanel"
  911. echo_content skyBlue "Docs: https://trojanpanel.github.io"
  912. echo_content red "\n=============================================================="
  913. echo_content yellow "1. 安装TrojanGFW+Caddy+Web+TLS"
  914. echo_content yellow "2. 安装TrojanGO+Caddy+Web+TLS+Websocket"
  915. echo_content yellow "3. 安装Hysteria"
  916. echo_content yellow "4. 安装NaiveProxy(Caddy+ForwardProxy)"
  917. echo_content yellow "5. 安装Caddy TLS"
  918. echo_content green "\n=============================================================="
  919. echo_content yellow "6. 卸载TrojanGFW+Caddy+Web+TLS"
  920. echo_content yellow "7. 卸载TrojanGO+Caddy+Web+TLS+Websocket"
  921. echo_content yellow "8. 卸载Hysteria"
  922. echo_content yellow "9. 卸载NaiveProxy(Caddy+ForwardProxy)"
  923. echo_content yellow "10. 卸载Caddy TLS"
  924. echo_content yellow "11. 卸载全部Trojan Panel相关的应用"
  925. echo_content green "\n=============================================================="
  926. echo_content yellow "12. 故障检测"
  927. read -r -p "请选择:" selectInstall_type
  928. case ${selectInstall_type} in
  929. 1)
  930. install_docker
  931. install_caddy_tls
  932. install_trojan_gfw_standalone
  933. ;;
  934. 2)
  935. install_docker
  936. install_caddy_tls
  937. install_trojanGO_standalone
  938. ;;
  939. 3)
  940. install_docker
  941. install_caddy_tls
  942. install_hysteria_standalone
  943. ;;
  944. 4)
  945. install_docker
  946. install_caddy_tls
  947. install_navieproxy_standalone
  948. ;;
  949. 5)
  950. install_docker
  951. install_caddy_tls
  952. ;;
  953. 6)
  954. uninstall_trojan_gfw_standalone
  955. ;;
  956. 7)
  957. uninstall_trojanGO_standalone
  958. ;;
  959. 8)
  960. uninstall_hysteria_standalone
  961. ;;
  962. 9)
  963. uninstall_navieproxy_standalone
  964. ;;
  965. 10)
  966. uninstall_caddy_tls
  967. ;;
  968. 11)
  969. uninstall_all
  970. ;;
  971. 12)
  972. failure_testing
  973. ;;
  974. *)
  975. echo_content red "没有这个选项"
  976. ;;
  977. esac
  978. }
  979. main