install_script_standalone.sh 38 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163
  1. #!/usr/bin/env bash
  2. PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
  3. export PATH
  4. # System Required: CentOS 7+/Ubuntu 18+/Debian 10+
  5. # Version: v1.3.4
  6. # Description: One click Install Trojan Panel standalone server
  7. # Author: jonssonyan <https://jonssonyan.com>
  8. # Github: https://github.com/trojanpanel/install-script
  9. init_var() {
  10. ECHO_TYPE="echo -e"
  11. package_manager=""
  12. release=""
  13. get_arch=""
  14. can_google=0
  15. # Docker
  16. DOCKER_MIRROR='"https://registry.docker-cn.com","https://hub-mirror.c.163.com","https://docker.mirrors.ustc.edu.cn"'
  17. # 项目目录
  18. TP_DATA="/tpdata/"
  19. STATIC_HTML="https://github.com/trojanpanel/install-script/releases/download/v1.0.0/html.tar.gz"
  20. # Caddy
  21. CADDY_DATA="/tpdata/caddy/"
  22. CADDY_Config="/tpdata/caddy/config.json"
  23. CADDY_SRV="/tpdata/caddy/srv/"
  24. CADDY_CERT="/tpdata/caddy/cert/"
  25. DOMAIN_FILE="/tpdata/caddy/domain.lock"
  26. CADDY_CRT_DIR="/tpdata/caddy/cert/certificates/acme-v02.api.letsencrypt.org-directory/"
  27. CADDY_KEY_DIR="/tpdata/caddy/cert/certificates/acme-v02.api.letsencrypt.org-directory/"
  28. domain=""
  29. caddy_remote_port=8863
  30. your_email=""
  31. ssl_option=1
  32. ssl_module_type=1
  33. ssl_module="acme"
  34. crt_path=""
  35. key_path=""
  36. caddy_crt_path="/tpdata/caddy/cert/server.crt"
  37. caddy_key_path="/tpdata/caddy/cert/server.key"
  38. # trojanGFW
  39. TROJANGFW_DATA="/tpdata/trojanGFW/"
  40. TROJANGFW_STANDALONE_CONFIG="/tpdata/trojanGFW/standalone_config.json"
  41. trojanGFW_port=443
  42. # trojanGO
  43. TROJANGO_DATA="/tpdata/trojanGO/"
  44. TROJANGO_STANDALONE_CONFIG="/tpdata/trojanGO/standalone_config.json"
  45. trojanGO_port=443
  46. trojanGO_websocket_enable=false
  47. trojanGO_websocket_path="trojan-panel-websocket-path"
  48. trojanGO_shadowsocks_enable=false
  49. trojanGO_shadowsocks_method="AES-128-GCM"
  50. trojanGO_shadowsocks_password=""
  51. trojanGO_mux_enable=true
  52. # trojan
  53. trojan_pas=""
  54. remote_addr="127.0.0.1"
  55. # hysteria
  56. HYSTERIA_DATA="/tpdata/hysteria/"
  57. HYSTERIA_STANDALONE_CONFIG="/tpdata/hysteria/standalone_config.json"
  58. hysteria_port=443
  59. hysteria_password=""
  60. hysteria_protocol="udp"
  61. hysteria_up_mbps=100
  62. hysteria_down_mbps=100
  63. # naiveproxy
  64. NAIVEPROXY_DATA="/tpdata/naiveproxy/"
  65. NAIVEPROXY_STANDALONE_CONFIG="/tpdata/naiveproxy/standalone_config.json"
  66. naiveproxy_port=443
  67. naiveproxy_username=""
  68. naiveproxy_pass=""
  69. }
  70. echo_content() {
  71. case $1 in
  72. "red")
  73. ${ECHO_TYPE} "\033[31m$2\033[0m"
  74. ;;
  75. "green")
  76. ${ECHO_TYPE} "\033[32m$2\033[0m"
  77. ;;
  78. "yellow")
  79. ${ECHO_TYPE} "\033[33m$2\033[0m"
  80. ;;
  81. "blue")
  82. ${ECHO_TYPE} "\033[34m$2\033[0m"
  83. ;;
  84. "purple")
  85. ${ECHO_TYPE} "\033[35m$2\033[0m"
  86. ;;
  87. "skyBlue")
  88. ${ECHO_TYPE} "\033[36m$2\033[0m"
  89. ;;
  90. "white")
  91. ${ECHO_TYPE} "\033[37m$2\033[0m"
  92. ;;
  93. esac
  94. }
  95. mkdir_tools() {
  96. # 项目目录
  97. mkdir -p ${TP_DATA}
  98. # Caddy
  99. mkdir -p ${CADDY_DATA}
  100. touch ${CADDY_Config}
  101. mkdir -p ${CADDY_SRV}
  102. mkdir -p ${CADDY_CERT}
  103. # trojanGFW
  104. mkdir -p ${TROJANGFW_DATA}
  105. touch ${TROJANGFW_STANDALONE_CONFIG}
  106. # trojanGO
  107. mkdir -p ${TROJANGO_DATA}
  108. touch ${TROJANGO_STANDALONE_CONFIG}
  109. # hysteria
  110. mkdir -p ${HYSTERIA_DATA}
  111. touch ${HYSTERIA_STANDALONE_CONFIG}
  112. # naiveproxy
  113. mkdir -p ${NAIVEPROXY_DATA}
  114. touch ${NAIVEPROXY_STANDALONE_CONFIG}
  115. }
  116. can_connect() {
  117. ping -c2 -i0.3 -W1 "$1" &>/dev/null
  118. if [[ "$?" == "0" ]]; then
  119. return 0
  120. else
  121. return 1
  122. fi
  123. }
  124. check_sys() {
  125. if [[ $(command -v yum) ]]; then
  126. package_manager='yum'
  127. elif [[ $(command -v dnf) ]]; then
  128. package_manager='dnf'
  129. elif [[ $(command -v apt) ]]; then
  130. package_manager='apt'
  131. elif [[ $(command -v apt-get) ]]; then
  132. package_manager='apt-get'
  133. fi
  134. if [[ -z "${package_manager}" ]]; then
  135. echo_content red "暂不支持该系统"
  136. exit 0
  137. fi
  138. if [[ -n $(find /etc -name "redhat-release") ]] || grep </proc/version -q -i "centos"; then
  139. release="centos"
  140. elif grep </etc/issue -q -i "debian" && [[ -f "/etc/issue" ]] || grep </etc/issue -q -i "debian" && [[ -f "/proc/version" ]]; then
  141. release="debian"
  142. elif grep </etc/issue -q -i "ubuntu" && [[ -f "/etc/issue" ]] || grep </etc/issue -q -i "ubuntu" && [[ -f "/proc/version" ]]; then
  143. release="ubuntu"
  144. fi
  145. if [[ -z "${release}" ]]; then
  146. echo_content red "仅支持CentOS 7+/Ubuntu 18+/Debian 10+系统"
  147. exit 0
  148. fi
  149. if [[ $(arch) =~ ("x86_64"|"amd64"|"arm64"|"aarch64"|"arm"|"s390x") ]]; then
  150. get_arch=$(arch)
  151. fi
  152. if [[ -z "${get_arch}" ]]; then
  153. echo_content red "仅支持amd64/arm64/arm/s390x处理器架构"
  154. exit 0
  155. fi
  156. }
  157. depend_install() {
  158. if [[ "${package_manager}" != 'yum' && "${package_manager}" != 'dnf' ]]; then
  159. ${package_manager} update -y
  160. fi
  161. ${package_manager} install -y \
  162. curl \
  163. wget \
  164. tar \
  165. lsof \
  166. systemd
  167. }
  168. # 安装Docker
  169. install_docker() {
  170. if [[ ! $(docker -v 2>/dev/null) ]]; then
  171. echo_content green "---> 安装Docker"
  172. # 关闭防火墙
  173. if [[ "$(firewall-cmd --state 2>/dev/null)" == "running" ]]; then
  174. systemctl stop firewalld.service && systemctl disable firewalld.service
  175. fi
  176. # 时区
  177. timedatectl set-timezone Asia/Shanghai
  178. can_connect www.google.com
  179. [[ "$?" == "0" ]] && can_google=1
  180. if [[ ${can_google} == 0 ]]; then
  181. sh <(curl -sL https://get.docker.com) --mirror Aliyun
  182. # 设置Docker国内源
  183. mkdir -p /etc/docker &&
  184. cat >/etc/docker/daemon.json <<EOF
  185. {
  186. "registry-mirrors":[${DOCKER_MIRROR}],
  187. "log-driver":"json-file",
  188. "log-opts":{
  189. "max-size":"50m",
  190. "max-file":"3"
  191. }
  192. }
  193. EOF
  194. else
  195. sh <(curl -sL https://get.docker.com)
  196. fi
  197. systemctl enable docker &&
  198. systemctl restart docker
  199. if [[ $(docker -v 2>/dev/null) ]]; then
  200. echo_content skyBlue "---> Docker安装完成"
  201. else
  202. echo_content red "---> Docker安装失败"
  203. exit 0
  204. fi
  205. else
  206. echo_content skyBlue "---> 你已经安装了Docker"
  207. fi
  208. }
  209. # 安装Caddy TLS
  210. install_caddy_tls() {
  211. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  212. echo_content green "---> 安装Caddy TLS"
  213. wget --no-check-certificate -O ${CADDY_DATA}html.tar.gz ${STATIC_HTML} &&
  214. tar -zxvf ${CADDY_DATA}html.tar.gz -C ${CADDY_SRV}
  215. read -r -p "请输入Caddy的转发端口(默认:8863): " caddy_remote_port
  216. [[ -z "${caddy_remote_port}" ]] && caddy_remote_port=8863
  217. echo_content yellow "提示:请确认域名已经解析到本机 否则可能安装失败"
  218. while read -r -p "请输入你的域名(必填): " domain; do
  219. if [[ -z "${domain}" ]]; then
  220. echo_content red "域名不能为空"
  221. else
  222. break
  223. fi
  224. done
  225. read -r -p "请输入你的邮箱(可选): " your_email
  226. while read -r -p "请选择设置证书的方式?(1/自动申请和续签证书 2/手动设置证书路径 默认:1/自动申请和续签证书): " ssl_option; do
  227. if [[ -z ${ssl_option} || ${ssl_option} == 1 ]]; then
  228. while read -r -p "请选择申请证书的方式(1/acme 2/zerossl 默认:1/acme): " ssl_module_type; do
  229. if [[ -z "${ssl_module_type}" || ${ssl_module_type} == 1 ]]; then
  230. ssl_module="acme"
  231. CADDY_CRT_DIR="/tpdata/caddy/cert/certificates/acme-v02.api.letsencrypt.org-directory/"
  232. CADDY_KEY_DIR="/tpdata/caddy/cert/certificates/acme-v02.api.letsencrypt.org-directory/"
  233. break
  234. elif [[ ${ssl_module_type} == 2 ]]; then
  235. ssl_module="zerossl"
  236. CADDY_CRT_DIR="/tpdata/caddy/cert/certificates/acme.zerossl.com-v2-dv90/"
  237. CADDY_KEY_DIR="/tpdata/caddy/cert/certificates/acme.zerossl.com-v2-dv90/"
  238. break
  239. else
  240. echo_content red "不可以输入除1和2之外的其他字符"
  241. fi
  242. done
  243. break
  244. elif [[ ${ssl_option} == 2 ]]; then
  245. while read -r -p "请输入证书的.crt文件路径(必填): " crt_path; do
  246. if [[ -z "${crt_path}" ]]; then
  247. echo_content red "路径不能为空"
  248. else
  249. if [[ ! -f "${crt_path}" ]]; then
  250. echo_content red "证书的.crt文件路径不存在"
  251. else
  252. cp "${crt_path}" "${caddy_crt_path}"
  253. break
  254. fi
  255. fi
  256. done
  257. while read -r -p "请输入证书的.key文件路径(必填): " key_path; do
  258. if [[ -z "${key_path}" ]]; then
  259. echo_content red "路径不能为空"
  260. else
  261. if [[ ! -f "${key_path}" ]]; then
  262. echo_content red "证书的.key文件路径不存在"
  263. else
  264. cp "${key_path}" "${caddy_key_path}"
  265. break
  266. fi
  267. fi
  268. done
  269. break
  270. else
  271. echo_content red "不可以输入除1和2之外的其他字符"
  272. fi
  273. done
  274. cat >${CADDY_Config} <<EOF
  275. {
  276. "admin": {
  277. "disabled": true
  278. },
  279. "logging": {
  280. "sink": {
  281. "writer": {
  282. "output": "discard"
  283. }
  284. },
  285. "logs": {
  286. "default": {
  287. "writer": {
  288. "output": "discard"
  289. }
  290. }
  291. }
  292. },
  293. "storage": {
  294. "module": "file_system",
  295. "root": "${CADDY_CERT}"
  296. },
  297. "apps": {
  298. "http": {
  299. "servers": {
  300. "srv0": {
  301. "listen": [
  302. ":80"
  303. ],
  304. "routes": [
  305. {
  306. "match": [
  307. {
  308. "host": [
  309. "${domain}"
  310. ]
  311. }
  312. ],
  313. "handle": [
  314. {
  315. "handler": "static_response",
  316. "headers": {
  317. "Location": [
  318. "https://{http.request.host}:${caddy_remote_port}{http.request.uri}"
  319. ]
  320. },
  321. "status_code": 301
  322. }
  323. ]
  324. }
  325. ]
  326. },
  327. "srv1": {
  328. "listen": [
  329. ":${caddy_remote_port}"
  330. ],
  331. "routes": [
  332. {
  333. "handle": [
  334. {
  335. "handler": "subroute",
  336. "routes": [
  337. {
  338. "match": [
  339. {
  340. "host": [
  341. "${domain}"
  342. ]
  343. }
  344. ],
  345. "handle": [
  346. {
  347. "handler": "file_server",
  348. "root": "${CADDY_SRV}",
  349. "index_names": [
  350. "index.html",
  351. "index.htm"
  352. ]
  353. }
  354. ],
  355. "terminal": true
  356. }
  357. ]
  358. }
  359. ]
  360. }
  361. ],
  362. "tls_connection_policies": [
  363. {
  364. "match": {
  365. "sni": [
  366. "${domain}"
  367. ]
  368. }
  369. }
  370. ],
  371. "automatic_https": {
  372. "disable": true
  373. }
  374. }
  375. }
  376. },
  377. "tls": {
  378. "certificates": {
  379. "automate": [
  380. "${domain}"
  381. ],
  382. "load_files": [
  383. {
  384. "certificate": "${CADDY_CRT_DIR}${domain}/${domain}.crt",
  385. "key": "${CADDY_KEY_DIR}${domain}/${domain}.key"
  386. }
  387. ]
  388. },
  389. "automation": {
  390. "policies": [
  391. {
  392. "issuers": [
  393. {
  394. "module": "${ssl_module}",
  395. "email": "${your_email}"
  396. }
  397. ]
  398. }
  399. ]
  400. }
  401. }
  402. }
  403. }
  404. EOF
  405. if [[ -n $(lsof -i:80,443 -t) ]]; then
  406. kill -9 "$(lsof -i:80,443 -t)"
  407. fi
  408. docker pull caddy:2.6.2 &&
  409. docker run -d --name trojan-panel-caddy --restart always \
  410. --network=host \
  411. -v "${CADDY_Config}":"${CADDY_Config}" \
  412. -v ${caddy_crt_path}:"${CADDY_CRT_DIR}${domain}/${domain}.crt" \
  413. -v ${caddy_key_path}:"${CADDY_KEY_DIR}${domain}/${domain}.key" \
  414. -v ${CADDY_SRV}:${CADDY_SRV} \
  415. caddy:2.6.2 caddy run --config ${CADDY_Config}
  416. if [[ -n $(docker ps -q -f "name=^trojan-panel-caddy$" -f "status=running") ]]; then
  417. cat >${DOMAIN_FILE} <<EOF
  418. ${domain}
  419. EOF
  420. echo_content skyBlue "---> Caddy安装完成"
  421. else
  422. echo_content red "---> Caddy安装失败或运行异常,请尝试修复或卸载重装"
  423. exit 0
  424. fi
  425. else
  426. domain=$(cat "${DOMAIN_FILE}")
  427. echo_content skyBlue "---> 你已经安装了Caddy"
  428. fi
  429. }
  430. # TrojanGFW+Caddy+Web+TLS+Websocket
  431. install_trojan_gfw_standalone() {
  432. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") ]]; then
  433. echo_content green "---> 安装TrojanGFW+Caddy+Web+TLS+Websocket"
  434. read -r -p "请输入TrojanGFW的端口(默认:443): " trojanGFW_port
  435. [[ -n ${trojanGFW_port} ]] && trojanGFW_port=443
  436. while read -r -p "请输入TrojanGFW的密码(必填): " trojan_pas; do
  437. if [[ -z "${trojan_pas}" ]]; then
  438. echo_content red "密码不能为空"
  439. else
  440. break
  441. fi
  442. done
  443. cat >${TROJANGFW_STANDALONE_CONFIG} <<EOF
  444. {
  445. "run_type": "server",
  446. "local_addr": "0.0.0.0",
  447. "local_port": ${trojanGFW_port},
  448. "remote_addr": "${remote_addr}",
  449. "remote_port": 80,
  450. "password": [
  451. "${trojan_pas}"
  452. ],
  453. "log_level": 1,
  454. "ssl": {
  455. "cert": "${caddy_crt_path}",
  456. "key": "${caddy_key_path}",
  457. "key_password": "",
  458. "cipher": "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384",
  459. "cipher_tls13": "TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384",
  460. "prefer_server_cipher": true,
  461. "alpn": [
  462. "http/1.1"
  463. ],
  464. "alpn_port_override": {
  465. "h2": 81
  466. },
  467. "reuse_session": true,
  468. "session_ticket": false,
  469. "session_timeout": 600,
  470. "plain_http_response": "",
  471. "curves": "",
  472. "dhparam": ""
  473. },
  474. "tcp": {
  475. "prefer_ipv4": false,
  476. "no_delay": true,
  477. "keep_alive": true,
  478. "reuse_port": false,
  479. "fast_open": false,
  480. "fast_open_qlen": 20
  481. },
  482. "mysql": {
  483. "enabled": false,
  484. "server_addr": "127.0.0.1",
  485. "server_port": 3306,
  486. "database": "",
  487. "username": "",
  488. "password": "",
  489. "key": "",
  490. "cert": "",
  491. "ca": ""
  492. }
  493. }
  494. EOF
  495. docker pull trojangfw/trojan &&
  496. docker run -d --name trojan-panel-trojanGFW-standalone --restart always \
  497. --network=host \
  498. -v ${TROJANGFW_STANDALONE_CONFIG}:"/config/config.json" \
  499. -v ${CADDY_CERT}:${CADDY_CERT} \
  500. trojangfw/trojan
  501. if [[ -n $(docker ps -q -f "name=^trojan-panel-trojanGFW-standalone$" -f "status=running") ]]; then
  502. echo_content skyBlue "---> TrojanGFW+Caddy+Web+TLS 安装完成"
  503. echo_content red "\n=============================================================="
  504. echo_content skyBlue "TrojanGFW+Caddy+Web+TLS 安装成功"
  505. echo_content yellow "域名: ${domain}"
  506. echo_content yellow "TrojanGFW的端口: ${trojanGFW_port}"
  507. echo_content yellow "TrojanGFW的密码: ${trojan_pas}"
  508. echo_content red "\n=============================================================="
  509. else
  510. echo_content red "---> TrojanGFW+Caddy+Web+TLS 安装失败或运行异常,请尝试修复或卸载重装"
  511. exit 0
  512. fi
  513. else
  514. echo_content skyBlue "---> 你已经安装了TrojanGFW+Caddy+Web+TLS"
  515. fi
  516. }
  517. # TrojanGO+Caddy+Web+TLS+Websocket
  518. install_trojanGO_standalone() {
  519. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") ]]; then
  520. echo_content green "---> 安装TrojanGO+Caddy+Web+TLS+Websocket"
  521. read -r -p "请输入TrojanGO的端口(默认:443): " trojanGO_port
  522. [[ -z "${trojanGO_port}" ]] && trojanGO_port=443
  523. while read -r -p "请输入TrojanGO的密码(必填): " trojan_pas; do
  524. if [[ -z "${trojan_pas}" ]]; then
  525. echo_content red "密码不能为空"
  526. else
  527. break
  528. fi
  529. done
  530. while read -r -p "是否开启多路复用?(false/关闭 true/开启 默认:true/开启): " trojanGO_mux_enable; do
  531. if [[ -z "${trojanGO_mux_enable}" || ${trojanGO_mux_enable} == true ]]; then
  532. trojanGO_mux_enable=true
  533. break
  534. else
  535. if [[ ${trojanGO_mux_enable} != false ]]; then
  536. echo_content red "不可以输入除false和true之外的其他字符"
  537. else
  538. break
  539. fi
  540. fi
  541. done
  542. while read -r -p "是否开启Websocket?(false/关闭 true/开启 默认:false/关闭): " trojanGO_websocket_enable; do
  543. if [[ -z "${trojanGO_websocket_enable}" || ${trojanGO_websocket_enable} == false ]]; then
  544. trojanGO_websocket_enable=false
  545. break
  546. else
  547. if [[ ${trojanGO_websocket_enable} != true ]]; then
  548. echo_content red "不可以输入除false和true之外的其他字符"
  549. else
  550. read -r -p "请输入Websocket路径(默认:trojan-panel-websocket-path): " trojanGO_websocket_path
  551. [[ -z "${trojanGO_websocket_path}" ]] && trojanGO_websocket_path="trojan-panel-websocket-path"
  552. break
  553. fi
  554. fi
  555. done
  556. while read -r -p "是否启用Shadowsocks AEAD加密?(false/关闭 true/开启 默认:false/关闭): " trojanGO_shadowsocks_enable; do
  557. if [[ -z "${trojanGO_shadowsocks_enable}" || ${trojanGO_shadowsocks_enable} == false ]]; then
  558. trojanGO_shadowsocks_enable=false
  559. break
  560. else
  561. if [[ ${trojanGO_shadowsocks_enable} != true ]]; then
  562. echo_content yellow "不可以输入除false和true之外的其他字符"
  563. else
  564. echo_content skyBlue "Shadowsocks AEAD加密方式如下:"
  565. echo_content yellow "1. AES-128-GCM(默认)"
  566. echo_content yellow "2. CHACHA20-IETF-POLY1305"
  567. echo_content yellow "3. AES-256-GCM"
  568. read -r -p "请输入Shadowsocks AEAD加密方式(默认:1): " select_method_type
  569. [[ -z "${select_method_type}" ]] && select_method_type=1
  570. case ${select_method_type} in
  571. 1)
  572. trojanGO_shadowsocks_method="AES-128-GCM"
  573. ;;
  574. 2)
  575. trojanGO_shadowsocks_method="CHACHA20-IETF-POLY1305"
  576. ;;
  577. 3)
  578. trojanGO_shadowsocks_method="AES-256-GCM"
  579. ;;
  580. *)
  581. trojanGO_shadowsocks_method="AES-128-GCM"
  582. ;;
  583. esac
  584. while read -r -p "请输入Shadowsocks AEAD加密密码(必填): " trojanGO_shadowsocks_password; do
  585. if [[ -z "${trojanGO_shadowsocks_password}" ]]; then
  586. echo_content red "密码不能为空"
  587. else
  588. break
  589. fi
  590. done
  591. break
  592. fi
  593. fi
  594. done
  595. cat >${TROJANGO_STANDALONE_CONFIG} <<EOF
  596. {
  597. "run_type": "server",
  598. "local_addr": "0.0.0.0",
  599. "local_port": ${trojanGO_port},
  600. "remote_addr": "${remote_addr}",
  601. "remote_port": 80,
  602. "log_level": 1,
  603. "log_file": "",
  604. "password": [
  605. "${trojan_pas}"
  606. ],
  607. "disable_http_check": false,
  608. "udp_timeout": 60,
  609. "ssl": {
  610. "verify": true,
  611. "verify_hostname": true,
  612. "cert": "${caddy_crt_path}",
  613. "key": "${caddy_key_path}",
  614. "key_password": "",
  615. "cipher": "",
  616. "curves": "",
  617. "prefer_server_cipher": false,
  618. "sni": "",
  619. "alpn": [
  620. "http/1.1"
  621. ],
  622. "session_ticket": true,
  623. "reuse_session": true,
  624. "plain_http_response": "",
  625. "fallback_addr": "",
  626. "fallback_port": 80,
  627. "fingerprint": ""
  628. },
  629. "tcp": {
  630. "no_delay": true,
  631. "keep_alive": true,
  632. "prefer_ipv4": false
  633. },
  634. "mux": {
  635. "enabled": ${trojanGO_mux_enable},
  636. "concurrency": 8,
  637. "idle_timeout": 60
  638. },
  639. "websocket": {
  640. "enabled": ${trojanGO_websocket_enable},
  641. "path": "/${trojanGO_websocket_path}",
  642. "host": "${domain}"
  643. },
  644. "shadowsocks": {
  645. "enabled": ${trojanGO_shadowsocks_enable},
  646. "method": "${trojanGO_shadowsocks_method}",
  647. "password": "${trojanGO_shadowsocks_password}"
  648. },
  649. "mysql": {
  650. "enabled": false,
  651. "server_addr": "localhost",
  652. "server_port": 3306,
  653. "database": "",
  654. "username": "",
  655. "password": "",
  656. "check_rate": 60
  657. }
  658. }
  659. EOF
  660. docker pull p4gefau1t/trojan-go &&
  661. docker run -d --name trojan-panel-trojanGO-standalone --restart=always \
  662. --network=host \
  663. -v ${TROJANGO_STANDALONE_CONFIG}:"/etc/trojan-go/config.json" \
  664. -v ${CADDY_CERT}:${CADDY_CERT} \
  665. p4gefau1t/trojan-go
  666. if [[ -n $(docker ps -q -f "name=^trojan-panel-trojanGO-standalone$" -f "status=running") ]]; then
  667. echo_content skyBlue "---> TrojanGO+Caddy+Web+TLS+Websocket 安装完成"
  668. echo_content red "\n=============================================================="
  669. echo_content skyBlue "TrojanGO+Caddy+Web+TLS+Websocket 安装成功"
  670. echo_content yellow "域名: ${domain}"
  671. echo_content yellow "TrojanGO的端口: ${trojanGO_port}"
  672. echo_content yellow "TrojanGO的密码: ${trojan_pas}"
  673. echo_content yellow "TrojanGO私钥和证书目录: ${CADDY_CERT}"
  674. if [[ ${trojanGO_websocket_enable} == true ]]; then
  675. echo_content yellow "Websocket路径: ${trojanGO_websocket_path}"
  676. fi
  677. if [[ ${trojanGO_shadowsocks_enable} == true ]]; then
  678. echo_content yellow "Shadowsocks AEAD加密方式: ${trojanGO_shadowsocks_method}"
  679. echo_content yellow "Shadowsocks AEAD加密密码: ${trojanGO_shadowsocks_password}"
  680. fi
  681. echo_content red "\n=============================================================="
  682. else
  683. echo_content red "---> TrojanGO+Caddy+Web+TLS+Websocket 安装失败或运行异常,请尝试修复或卸载重装"
  684. exit 0
  685. fi
  686. else
  687. echo_content skyBlue "---> 你已经了安装了TrojanGO+Caddy+Web+TLS+Websocket"
  688. fi
  689. }
  690. # 安装Hysteria
  691. install_hysteria_standalone() {
  692. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") ]]; then
  693. echo_content green "---> 安装Hysteria"
  694. echo_content skyBlue "Hysteria的模式如下:"
  695. echo_content yellow "1. udp(默认)"
  696. echo_content yellow "2. faketcp"
  697. read -r -p "请输入Hysteria的模式(默认:1): " selectProtocolType
  698. [[ -z "${selectProtocolType}" ]] && selectProtocolType=1
  699. case ${selectProtocolType} in
  700. 1)
  701. hysteria_protocol="udp"
  702. ;;
  703. 2)
  704. hysteria_protocol="faketcp"
  705. ;;
  706. *)
  707. hysteria_protocol="udp"
  708. ;;
  709. esac
  710. read -r -p "请输入Hysteria的端口(默认:443): " hysteria_port
  711. [[ -z ${hysteria_port} ]] && hysteria_port=443
  712. read -r -p "请输入单客户端最大上传速度/Mbps(默认:100): " hysteria_up_mbps
  713. [[ -z "${hysteria_up_mbps}" ]] && hysteria_up_mbps=100
  714. read -r -p "请输入单客户端最大下载速度/Mbps(默认:100): " hysteria_down_mbps
  715. [[ -z "${hysteria_down_mbps}" ]] && hysteria_down_mbps=100
  716. while read -r -p "请输入Hysteria的密码(必填): " hysteria_password; do
  717. if [[ -z ${hysteria_password} ]]; then
  718. echo_content red "密码不能为空"
  719. else
  720. break
  721. fi
  722. done
  723. cat >${HYSTERIA_STANDALONE_CONFIG} <<EOF
  724. {
  725. "listen": ":${hysteria_port}",
  726. "protocol": "${hysteria_protocol}",
  727. "cert": "${caddy_crt_path}",
  728. "key": "${caddy_key_path}",
  729. "up_mbps": ${hysteria_up_mbps},
  730. "down_mbps": ${hysteria_down_mbps},
  731. "auth_str": "${hysteria_password}"
  732. }
  733. EOF
  734. docker pull tobyxdd/hysteria &&
  735. docker run -d --name trojan-panel-hysteria-standalone --restart=always \
  736. --network=host \
  737. -v ${HYSTERIA_STANDALONE_CONFIG}:/etc/hysteria.json \
  738. -v ${CADDY_CERT}:${CADDY_CERT} \
  739. tobyxdd/hysteria -c /etc/hysteria.json server
  740. if [[ -n $(docker ps -q -f "name=^trojan-panel-hysteria-standalone$" -f "status=running") ]]; then
  741. echo_content skyBlue "---> Hysteria 安装完成"
  742. echo_content red "\n=============================================================="
  743. echo_content skyBlue "Hysteria 安装成功"
  744. echo_content yellow "域名: ${domain}"
  745. echo_content yellow "Hysteria的端口: ${hysteria_port}"
  746. echo_content yellow "Hysteria的密码: ${hysteria_password}"
  747. echo_content yellow "Hysteria私钥和证书目录: ${CADDY_CERT}"
  748. echo_content red "\n=============================================================="
  749. else
  750. echo_content red "---> Hysteria 安装失败或运行异常,请尝试修复或卸载重装"
  751. exit 0
  752. fi
  753. else
  754. echo_content skyBlue "---> 你已经安装了Hysteria"
  755. fi
  756. }
  757. # 安装NaiveProxy(Caddy+ForwardProxy)
  758. install_navieproxy_standalone() {
  759. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-navieproxy-standalone$") ]]; then
  760. echo_content green "---> 安装NaiveProxy(Caddy+ForwardProxy)"
  761. read -r -p "请输入NaiveProxy的端口(默认:443): " naiveproxy_port
  762. [[ -z "${naiveproxy_port}" ]] && naiveproxy_port=443
  763. while read -r -p "请输入NaiveProxy的用户名(必填): " naiveproxy_username; do
  764. if [[ -z "${naiveproxy_username}" ]]; then
  765. echo_content red "用户名不能为空"
  766. else
  767. break
  768. fi
  769. done
  770. while read -r -p "请输入NaiveProxy的密码(必填): " naiveproxy_pass; do
  771. if [[ -z "${naiveproxy_pass}" ]]; then
  772. echo_content red "密码不能为空"
  773. else
  774. break
  775. fi
  776. done
  777. domain=$(cat "${DOMAIN_FILE}")
  778. cat >${NAIVEPROXY_STANDALONE_CONFIG} <<EOF
  779. {
  780. "admin": {
  781. "disabled": true
  782. },
  783. "logging": {
  784. "sink": {
  785. "writer": {
  786. "output": "discard"
  787. }
  788. },
  789. "logs": {
  790. "default": {
  791. "writer": {
  792. "output": "discard"
  793. }
  794. }
  795. }
  796. },
  797. "apps": {
  798. "http": {
  799. "servers": {
  800. "srv0": {
  801. "listen": [
  802. ":${naiveproxy_port}"
  803. ],
  804. "routes": [
  805. {
  806. "handle": [
  807. {
  808. "handler": "subroute",
  809. "routes": [
  810. {
  811. "handle": [
  812. {
  813. "auth_pass_deprecated": "${naiveproxy_pass}",
  814. "auth_user_deprecated": "${naiveproxy_username}",
  815. "handler": "forward_proxy",
  816. "hide_ip": true,
  817. "hide_via": true,
  818. "probe_resistance": {}
  819. }
  820. ]
  821. },
  822. {
  823. "match": [
  824. {
  825. "host": [
  826. "${domain}"
  827. ]
  828. }
  829. ],
  830. "handle": [
  831. {
  832. "handler": "file_server",
  833. "root": "/caddy-forwardproxy/dist/",
  834. "index_names": [
  835. "index.html",
  836. "index.htm"
  837. ]
  838. }
  839. ],
  840. "terminal": true
  841. }
  842. ]
  843. }
  844. ]
  845. }
  846. ],
  847. "tls_connection_policies": [
  848. {
  849. "match": {
  850. "sni": [
  851. "${domain}"
  852. ]
  853. }
  854. }
  855. ],
  856. "automatic_https": {
  857. "disable": true
  858. }
  859. }
  860. }
  861. },
  862. "tls": {
  863. "certificates": {
  864. "load_files": [
  865. {
  866. "certificate": "${caddy_crt_path}",
  867. "key": "${caddy_key_path}"
  868. }
  869. ]
  870. }
  871. }
  872. }
  873. }
  874. EOF
  875. docker pull jonssonyan/caddy-forwardproxy &&
  876. docker run -d --name trojan-panel-navieproxy-standalone --restart=always \
  877. --network=host \
  878. -v ${NAIVEPROXY_STANDALONE_CONFIG}:"/caddy-forwardproxy/config/config.json" \
  879. -v ${CADDY_CERT}:${CADDY_CERT} \
  880. jonssonyan/caddy-forwardproxy
  881. if [[ -n $(docker ps -q -f "name=^trojan-panel-navieproxy-standalone$" -f "status=running") ]]; then
  882. echo_content skyBlue "---> NaiveProxy(Caddy+ForwardProxy) 安装完成"
  883. echo_content red "\n=============================================================="
  884. echo_content skyBlue "NaiveProxy(Caddy+ForwardProxy) 安装成功"
  885. echo_content yellow "域名: ${domain}"
  886. echo_content yellow "NaiveProxy的端口: ${naiveproxy_port}"
  887. echo_content yellow "NaiveProxy的用户名: ${naiveproxy_username}"
  888. echo_content yellow "NaiveProxy的密码: ${naiveproxy_pass}"
  889. echo_content yellow "NaiveProxy私钥和证书目录: ${CADDY_CERT}"
  890. echo_content red "\n=============================================================="
  891. else
  892. echo_content red "---> NaiveProxy(Caddy+ForwardProxy) 安装失败或运行异常,请尝试修复或卸载重装"
  893. exit 0
  894. fi
  895. else
  896. echo_content skyBlue "---> 你已经了安装了NaiveProxy(Caddy+ForwardProxy)"
  897. fi
  898. }
  899. # 卸载Caddy TLS
  900. uninstall_caddy_tls() {
  901. # 判断Caddy TLS是否安装
  902. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  903. echo_content green "---> 卸载Caddy TLS"
  904. docker rm -f trojan-panel-caddy &&
  905. rm -rf ${CADDY_DATA}
  906. echo_content skyBlue "---> Caddy TLS卸载完成"
  907. else
  908. echo_content red "---> 请先安装Caddy TLS"
  909. fi
  910. }
  911. # TrojanGFW+Caddy+Web+TLS
  912. uninstall_trojan_gfw_standalone() {
  913. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") ]]; then
  914. echo_content green "---> 卸载TrojanGFW+Caddy+Web+TLS"
  915. docker rm -f trojan-panel-trojanGFW-standalone &&
  916. docker rmi -f trojangfw/trojan &&
  917. rm -f ${TROJANGFW_STANDALONE_CONFIG}
  918. echo_content skyBlue "---> TrojanGFW+Caddy+Web+TLS 卸载完成"
  919. else
  920. echo_content red "---> 请先安装TrojanGFW+Caddy+Web+TLS"
  921. fi
  922. }
  923. # 卸载TrojanGO 单机版
  924. uninstall_trojanGO_standalone() {
  925. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") ]]; then
  926. echo_content green "---> 卸载TrojanGO+Caddy+Web+TLS+Websocket"
  927. docker rm -f trojan-panel-trojanGO-standalone &&
  928. docker rmi -f p4gefau1t/trojan-go &&
  929. rm -f ${TROJANGO_STANDALONE_CONFIG}
  930. echo_content skyBlue "---> TrojanGO+Caddy+Web+TLS+Websocket 卸载完成"
  931. else
  932. echo_content red "---> 请先安装TrojanGO+Caddy+Web+TLS+Websocket"
  933. fi
  934. }
  935. # 卸载Hysteria
  936. uninstall_hysteria_standalone() {
  937. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") ]]; then
  938. echo_content green "---> 卸载Hysteria"
  939. docker rm -f trojan-panel-hysteria-standalone &&
  940. docker rmi -f tobyxdd/hysteria &&
  941. rm -f ${HYSTERIA_STANDALONE_CONFIG}
  942. echo_content skyBlue "---> Hysteria 卸载完成"
  943. else
  944. echo_content red "---> 请先安装Hysteria"
  945. fi
  946. }
  947. # 卸载NaiveProxy(Caddy+ForwardProxy)
  948. uninstall_navieproxy_standalone() {
  949. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-navieproxy-standalone$") ]]; then
  950. echo_content green "---> 卸载NaiveProxy(Caddy+ForwardProxy)"
  951. docker rm -f trojan-panel-navieproxy-standalone &&
  952. docker rmi -f jonssonyan/caddy-forwardproxy &&
  953. rm -f ${NAIVEPROXY_STANDALONE_CONFIG}
  954. echo_content skyBlue "---> NaiveProxy(Caddy+ForwardProxy) 卸载完成"
  955. else
  956. echo_content red "---> 请先安装NaiveProxy(Caddy+ForwardProxy)"
  957. fi
  958. }
  959. # 卸载全部Trojan Panel相关的容器
  960. uninstall_all() {
  961. echo_content green "---> 卸载全部Trojan Panel相关的容器"
  962. docker rm -f $(docker ps -a -q -f "name=^trojan-panel") &&
  963. rm -rf ${TP_DATA}
  964. echo_content skyBlue "---> 卸载全部Trojan Panel相关的容器完成"
  965. }
  966. # 故障检测
  967. failure_testing() {
  968. echo_content green "---> 故障检测开始"
  969. if [[ ! $(docker -v 2>/dev/null) ]]; then
  970. echo_content red "---> Docker运行异常"
  971. else
  972. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  973. if [[ -z $(docker ps -q -f "name=^trojan-panel-caddy$" -f "status=running") ]]; then
  974. echo_content red "---> Caddy TLS运行异常"
  975. fi
  976. domain=$(cat "${DOMAIN_FILE}")
  977. if [[ -z $(cat "${DOMAIN_FILE}") || ! -d "${CADDY_CERT}" || ! -f "${caddy_crt_path}" ]]; then
  978. echo_content red "---> 证书申请异常,请尝试重启服务器将重新申请证书或者重新搭建选择自定义证书选项"
  979. fi
  980. fi
  981. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-trojanGFW-standalone$" -f "status=running") ]]; then
  982. echo_content red "---> TrojanGFW运行异常"
  983. fi
  984. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-trojanGO-standalone$" -f "status=running") ]]; then
  985. echo_content red "---> TrojanGO运行异常"
  986. fi
  987. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-hysteria-standalone$" -f "status=running") ]]; then
  988. echo_content red "---> Hysteria运行异常"
  989. fi
  990. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-navieproxy-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-navieproxy-standalone$" -f "status=running") ]]; then
  991. echo_content red "---> NaiveProxy(Caddy+ForwardProxy)运行异常"
  992. fi
  993. fi
  994. echo_content green "---> 故障检测结束"
  995. }
  996. main() {
  997. cd "$HOME" || exit 0
  998. init_var
  999. mkdir_tools
  1000. check_sys
  1001. depend_install
  1002. clear
  1003. echo_content red "\n=============================================================="
  1004. echo_content skyBlue "System Required: CentOS 7+/Ubuntu 18+/Debian 10+"
  1005. echo_content skyBlue "Version: v1.3.4"
  1006. echo_content skyBlue "Description: One click Install Trojan Panel standalone server"
  1007. echo_content skyBlue "Author: jonssonyan <https://jonssonyan.com>"
  1008. echo_content skyBlue "Github: https://github.com/trojanpanel"
  1009. echo_content skyBlue "Docs: https://trojanpanel.github.io"
  1010. echo_content red "\n=============================================================="
  1011. echo_content yellow "1. 安装TrojanGFW+Caddy+Web+TLS"
  1012. echo_content yellow "2. 安装TrojanGO+Caddy+Web+TLS+Websocket"
  1013. echo_content yellow "3. 安装Hysteria"
  1014. echo_content yellow "4. 安装NaiveProxy(Caddy+ForwardProxy)"
  1015. echo_content yellow "5. 安装Caddy TLS"
  1016. echo_content green "\n=============================================================="
  1017. echo_content yellow "6. 卸载TrojanGFW+Caddy+Web+TLS"
  1018. echo_content yellow "7. 卸载TrojanGO+Caddy+Web+TLS+Websocket"
  1019. echo_content yellow "8. 卸载Hysteria"
  1020. echo_content yellow "9. 卸载NaiveProxy(Caddy+ForwardProxy)"
  1021. echo_content yellow "10. 卸载Caddy TLS"
  1022. echo_content yellow "11. 卸载全部Trojan Panel相关的应用"
  1023. echo_content green "\n=============================================================="
  1024. echo_content yellow "12. 故障检测"
  1025. read -r -p "请选择:" selectInstall_type
  1026. case ${selectInstall_type} in
  1027. 1)
  1028. install_docker
  1029. install_caddy_tls
  1030. install_trojan_gfw_standalone
  1031. ;;
  1032. 2)
  1033. install_docker
  1034. install_caddy_tls
  1035. install_trojanGO_standalone
  1036. ;;
  1037. 3)
  1038. install_docker
  1039. install_caddy_tls
  1040. install_hysteria_standalone
  1041. ;;
  1042. 4)
  1043. install_docker
  1044. install_caddy_tls
  1045. install_navieproxy_standalone
  1046. ;;
  1047. 5)
  1048. install_docker
  1049. install_caddy_tls
  1050. ;;
  1051. 6)
  1052. uninstall_trojan_gfw_standalone
  1053. ;;
  1054. 7)
  1055. uninstall_trojanGO_standalone
  1056. ;;
  1057. 8)
  1058. uninstall_hysteria_standalone
  1059. ;;
  1060. 9)
  1061. uninstall_navieproxy_standalone
  1062. ;;
  1063. 10)
  1064. uninstall_caddy_tls
  1065. ;;
  1066. 11)
  1067. uninstall_all
  1068. ;;
  1069. 12)
  1070. failure_testing
  1071. ;;
  1072. *)
  1073. echo_content red "没有这个选项"
  1074. ;;
  1075. esac
  1076. }
  1077. main