install_script_standalone.sh 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943
  1. #!/usr/bin/env bash
  2. PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
  3. export PATH
  4. # System Required: CentOS 7+/Ubuntu 18+/Debian 10+
  5. # Version: v1.0.0
  6. # Description: One click Install Trojan Panel standalone server
  7. # Author: jonssonyan <https://jonssonyan.com>
  8. # Github: https://github.com/trojanpanel/install-script
  9. init_var() {
  10. ECHO_TYPE="echo -e"
  11. package_manager=""
  12. release=""
  13. get_arch=""
  14. can_google=0
  15. # Docker
  16. DOCKER_MIRROR='"https://registry.docker-cn.com","https://hub-mirror.c.163.com","https://docker.mirrors.ustc.edu.cn"'
  17. # 项目目录
  18. TP_DATA="/tpdata/"
  19. STATIC_HTML="https://github.com/trojanpanel/install-script/releases/download/v1.0.0/html.tar.gz"
  20. # Caddy
  21. CADDY_DATA="/tpdata/caddy/"
  22. CADDY_Caddyfile="/tpdata/caddy/Caddyfile"
  23. CADDY_SRV="/tpdata/caddy/srv/"
  24. CADDY_ACME="/tpdata/caddy/acme/"
  25. DOMAIN_FILE="/tpdata/caddy/domain.lock"
  26. domain=""
  27. caddy_remote_port=8863
  28. your_email="[email protected]"
  29. crt_path=""
  30. key_path=""
  31. ssl_option=1
  32. # trojanGFW
  33. TROJANGFW_DATA="/tpdata/trojanGFW/"
  34. TROJANGFW_STANDALONE_CONFIG="/tpdata/trojanGFW/standalone_config.json"
  35. trojanGFW_port=443
  36. # trojanGO
  37. TROJANGO_DATA="/tpdata/trojanGO/"
  38. TROJANGO_STANDALONE_CONFIG="/tpdata/trojanGO/standalone_config.json"
  39. trojanGO_port=443
  40. trojanGO_websocket_enable=false
  41. trojanGO_websocket_path="trojan-panel-websocket-path"
  42. trojanGO_shadowsocks_enable=false
  43. trojanGO_shadowsocks_method="AES-128-GCM"
  44. trojanGO_shadowsocks_password=""
  45. trojanGO_mux_enable=true
  46. # trojan
  47. trojan_pas=""
  48. remote_addr="127.0.0.1"
  49. # hysteria
  50. HYSTERIA_DATA="/tpdata/hysteria/"
  51. HYSTERIA_STANDALONE_CONFIG="/tpdata/hysteria/standalone_config.json"
  52. hysteria_port=443
  53. hysteria_password=""
  54. hysteria_protocol="udp"
  55. hysteria_up_mbps=100
  56. hysteria_down_mbps=100
  57. }
  58. echo_content() {
  59. case $1 in
  60. "red")
  61. ${ECHO_TYPE} "\033[31m$2\033[0m"
  62. ;;
  63. "green")
  64. ${ECHO_TYPE} "\033[32m$2\033[0m"
  65. ;;
  66. "yellow")
  67. ${ECHO_TYPE} "\033[33m$2\033[0m"
  68. ;;
  69. "blue")
  70. ${ECHO_TYPE} "\033[34m$2\033[0m"
  71. ;;
  72. "purple")
  73. ${ECHO_TYPE} "\033[35m$2\033[0m"
  74. ;;
  75. "skyBlue")
  76. ${ECHO_TYPE} "\033[36m$2\033[0m"
  77. ;;
  78. "white")
  79. ${ECHO_TYPE} "\033[37m$2\033[0m"
  80. ;;
  81. esac
  82. }
  83. mkdir_tools() {
  84. # 项目目录
  85. mkdir -p ${TP_DATA}
  86. # Caddy
  87. mkdir -p ${CADDY_DATA}
  88. touch ${CADDY_Caddyfile}
  89. mkdir -p ${CADDY_SRV}
  90. mkdir -p ${CADDY_ACME}
  91. # trojanGFW
  92. mkdir -p ${TROJANGFW_DATA}
  93. touch ${TROJANGFW_STANDALONE_CONFIG}
  94. # trojanGO
  95. mkdir -p ${TROJANGO_DATA}
  96. touch ${TROJANGO_STANDALONE_CONFIG}
  97. # hysteria
  98. mkdir -p ${HYSTERIA_DATA}
  99. touch ${HYSTERIA_STANDALONE_CONFIG}
  100. }
  101. can_connect() {
  102. ping -c2 -i0.3 -W1 "$1" &>/dev/null
  103. if [[ "$?" == "0" ]]; then
  104. return 0
  105. else
  106. return 1
  107. fi
  108. }
  109. check_sys() {
  110. if [[ $(command -v yum) ]]; then
  111. package_manager='yum'
  112. elif [[ $(command -v dnf) ]]; then
  113. package_manager='dnf'
  114. elif [[ $(command -v apt) ]]; then
  115. package_manager='apt'
  116. elif [[ $(command -v apt-get) ]]; then
  117. package_manager='apt-get'
  118. fi
  119. if [[ -z "${package_manager}" ]]; then
  120. echo_content red "暂不支持该系统"
  121. exit 0
  122. fi
  123. if [[ -n $(find /etc -name "redhat-release") ]] || grep </proc/version -q -i "centos"; then
  124. release="centos"
  125. elif grep </etc/issue -q -i "debian" && [[ -f "/etc/issue" ]] || grep </etc/issue -q -i "debian" && [[ -f "/proc/version" ]]; then
  126. release="debian"
  127. elif grep </etc/issue -q -i "ubuntu" && [[ -f "/etc/issue" ]] || grep </etc/issue -q -i "ubuntu" && [[ -f "/proc/version" ]]; then
  128. release="ubuntu"
  129. fi
  130. if [[ -z "${release}" ]]; then
  131. echo_content red "仅支持CentOS 7+/Ubuntu 18+/Debian 10+系统"
  132. exit 0
  133. fi
  134. if [[ $(arch) =~ ("x86_64"|"amd64"|"arm64"|"aarch64"|"arm"|"s390x") ]]; then
  135. get_arch=$(arch)
  136. fi
  137. if [[ -z "${get_arch}" ]]; then
  138. echo_content red "仅支持amd64/arm64/arm/s390x处理器架构"
  139. exit 0
  140. fi
  141. }
  142. depend_install() {
  143. if [[ "${package_manager}" != 'yum' && "${package_manager}" != 'dnf' ]]; then
  144. ${package_manager} update -y
  145. fi
  146. ${package_manager} install -y \
  147. curl \
  148. wget \
  149. tar \
  150. lsof \
  151. systemd
  152. }
  153. # 安装BBRPlus 仅支持CentOS系统
  154. install_bbr_plus() {
  155. kernel_version="4.14.129-bbrplus"
  156. if [[ ! -f /etc/redhat-release ]]; then
  157. echo_content yellow "仅支持CentOS系统"
  158. exit 0
  159. fi
  160. if [[ "$(uname -r)" == "${kernel_version}" ]]; then
  161. echo_content yellow "内核已经安装,无需重复执行"
  162. exit 0
  163. fi
  164. # 卸载原加速
  165. echo_content green "卸载加速..."
  166. sed -i '/net.core.default_qdisc/d' /etc/sysctl.conf
  167. sed -i '/net.ipv4.tcp_congestion_control/d' /etc/sysctl.conf
  168. if [[ -e /appex/bin/serverSpeeder.sh ]]; then
  169. wget --no-check-certificate -O appex.sh https://raw.githubusercontent.com/0oVicero0/serverSpeeder_Install/master/appex.sh && chmod +x appex.sh && bash appex.sh uninstall
  170. rm -f appex.sh
  171. fi
  172. echo_content green "下载内核..."
  173. wget https://github.com/cx9208/bbrplus/raw/master/centos7/x86_64/kernel-${kernel_version}.rpm
  174. echo_content green "安装内核..."
  175. yum install -y kernel-${kernel_version}.rpm
  176. # 检查内核是否安装成功
  177. list="$(awk -F\' '$1=="menuentry " {print i++ " : " $2}' /etc/grub2.cfg)"
  178. target="CentOS Linux (${kernel_version})"
  179. result=$(echo "${list}" | grep "${target}")
  180. if [[ -z "${result}" ]]; then
  181. echo_content red "内核安装失败"
  182. exit 1
  183. fi
  184. echo_content green "切换内核..."
  185. grub2-set-default "CentOS Linux (${kernel_version}) 7 (Core)"
  186. echo_content green "启用模块..."
  187. echo "net.core.default_qdisc=fq" >>/etc/sysctl.conf
  188. echo "net.ipv4.tcp_congestion_control=bbrplus" >>/etc/sysctl.conf
  189. rm -f kernel-${kernel_version}.rpm
  190. read -r -p "BBRPlusPlus安装完成,现在重启 ? [Y/n] :" yn
  191. [[ -z "${yn}" ]] && yn="y"
  192. if [[ $yn == [Yy] ]]; then
  193. echo_content green "重启中..."
  194. reboot
  195. fi
  196. }
  197. # 安装Docker
  198. install_docker() {
  199. if [[ ! $(docker -v 2>/dev/null) ]]; then
  200. echo_content green "---> 安装Docker"
  201. # 关闭防火墙
  202. if [[ "$(firewall-cmd --state 2>/dev/null)" == "running" ]]; then
  203. systemctl stop firewalld.service && systemctl disable firewalld.service
  204. fi
  205. # 时区
  206. timedatectl set-timezone Asia/Shanghai
  207. can_connect www.google.com
  208. [[ "$?" == "0" ]] && can_google=1
  209. if [[ ${can_google} == 0 ]]; then
  210. sh <(curl -sL https://get.docker.com) --mirror Aliyun
  211. # 设置Docker国内源
  212. mkdir -p /etc/docker &&
  213. cat >/etc/docker/daemon.json <<EOF
  214. {
  215. "registry-mirrors":[${DOCKER_MIRROR}],
  216. "log-driver":"json-file",
  217. "log-opts":{
  218. "max-size":"50m",
  219. "max-file":"3"
  220. }
  221. }
  222. EOF
  223. else
  224. sh <(curl -sL https://get.docker.com)
  225. fi
  226. systemctl enable docker &&
  227. systemctl restart docker
  228. if [[ $(docker -v 2>/dev/null) ]]; then
  229. echo_content skyBlue "---> Docker安装完成"
  230. else
  231. echo_content red "---> Docker安装失败"
  232. exit 0
  233. fi
  234. else
  235. echo_content skyBlue "---> 你已经安装了Docker"
  236. fi
  237. }
  238. # 安装Caddy TLS
  239. install_caddy_tls() {
  240. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  241. echo_content green "---> 安装Caddy TLS"
  242. wget --no-check-certificate -O ${CADDY_DATA}html.tar.gz ${STATIC_HTML} &&
  243. tar -zxvf ${CADDY_DATA}html.tar.gz -C ${CADDY_SRV}
  244. read -r -p "请输入Caddy的转发端口(用于申请证书,默认:8863): " caddy_remote_port
  245. [[ -z "${caddy_remote_port}" ]] && caddy_remote_port=8863
  246. while read -r -p "请输入你的域名(必填): " domain; do
  247. if [[ -z "${domain}" ]]; then
  248. echo_content red "域名不能为空"
  249. else
  250. break
  251. fi
  252. done
  253. mkdir "${CADDY_ACME}${domain}"
  254. while read -r -p "请选择设置证书的方式?(1/自动申请和续签证书 2/手动设置证书路径 默认:1/自动申请和续签证书): " ssl_option; do
  255. if [[ -z ${ssl_option} || ${ssl_option} == 1 ]]; then
  256. echo_content yellow "正在检测域名,请稍后..."
  257. ping_ip=$(ping "${domain}" -s1 -c1 | grep "ttl=" | head -n1 | cut -d"(" -f2 | cut -d")" -f1)
  258. curl_ip=$(curl ifconfig.me)
  259. if [[ "${ping_ip}" != "${curl_ip}" ]]; then
  260. echo_content yellow "你的域名没有解析到本机IP,请稍后再试"
  261. echo_content red "---> Caddy安装失败"
  262. exit 0
  263. fi
  264. read -r -p "请输入你的邮箱(用于申请证书,默认:[email protected]): " your_email
  265. [[ -z "${your_email}" ]] && your_email="[email protected]"
  266. cat >${CADDY_Caddyfile} <<EOF
  267. http://${domain}:80 {
  268. redir https://${domain}:${caddy_remote_port}{url}
  269. }
  270. https://${domain}:${caddy_remote_port} {
  271. gzip
  272. tls ${your_email}
  273. root ${CADDY_SRV}
  274. }
  275. EOF
  276. break
  277. else
  278. if [[ ${ssl_option} != 2 ]]; then
  279. echo_content red "不可以输入除1和2之外的其他字符"
  280. else
  281. while read -r -p "请输入证书的.crt文件路径(必填): " crt_path; do
  282. if [[ -z "${crt_path}" ]]; then
  283. echo_content red "路径不能为空"
  284. else
  285. if [[ ! -f "${crt_path}" ]]; then
  286. echo_content red "证书的.crt文件路径不存在"
  287. else
  288. cp "${crt_path}" "${CADDY_ACME}${domain}/${domain}.crt"
  289. break
  290. fi
  291. fi
  292. done
  293. while read -r -p "请输入证书的.key文件路径(必填): " key_path; do
  294. if [[ -z "${key_path}" ]]; then
  295. echo_content red "路径不能为空"
  296. else
  297. if [[ ! -f "${key_path}" ]]; then
  298. echo_content red "证书的.key文件路径不存在"
  299. else
  300. cp "${key_path}" "${CADDY_ACME}${domain}/${domain}.key"
  301. break
  302. fi
  303. fi
  304. done
  305. cat >${CADDY_Caddyfile} <<EOF
  306. http://${domain}:80 {
  307. redir https://${domain}:${caddy_remote_port}{url}
  308. }
  309. https://${domain}:${caddy_remote_port} {
  310. gzip
  311. tls /root/.caddy/acme/acme-v02.api.letsencrypt.org/sites/${domain}/${domain}.crt /root/.caddy/acme/acme-v02.api.letsencrypt.org/sites/${domain}/${domain}.key
  312. root ${CADDY_SRV}
  313. }
  314. EOF
  315. break
  316. fi
  317. fi
  318. done
  319. if [[ -n $(lsof -i:80,443 -t) ]]; then
  320. kill -9 "$(lsof -i:80,443 -t)"
  321. fi
  322. docker pull teddysun/caddy:1.0.5 &&
  323. docker run -d --name trojan-panel-caddy --restart always \
  324. --network=host \
  325. -v ${CADDY_Caddyfile}:"/etc/caddy/Caddyfile" \
  326. -v ${CADDY_ACME}:"/root/.caddy/acme/acme-v02.api.letsencrypt.org/sites/" \
  327. -v ${CADDY_SRV}:${CADDY_SRV} \
  328. teddysun/caddy:1.0.5
  329. if [[ -n $(docker ps -q -f "name=^trojan-panel-caddy$" -f "status=running") ]]; then
  330. cat >${DOMAIN_FILE} <<EOF
  331. ${domain}
  332. EOF
  333. echo_content skyBlue "---> Caddy安装完成"
  334. else
  335. echo_content red "---> Caddy安装失败或运行异常,请尝试修复或卸载重装"
  336. exit 0
  337. fi
  338. else
  339. domain=$(cat "${DOMAIN_FILE}")
  340. echo_content skyBlue "---> 你已经安装了Caddy"
  341. fi
  342. }
  343. # 安装TrojanGFW 单机版
  344. install_trojan_gfw_standalone() {
  345. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") ]]; then
  346. echo_content green "---> 安装TrojanGFW"
  347. read -r -p "请输入TrojanGFW的端口(默认:443): " trojanGFW_port
  348. [[ -n ${trojanGFW_port} ]] && trojanGFW_port=443
  349. while read -r -p "请输入TrojanGFW的密码(必填): " trojan_pas; do
  350. if [[ -z "${trojan_pas}" ]]; then
  351. echo_content red "密码不能为空"
  352. else
  353. break
  354. fi
  355. done
  356. cat >${TROJANGFW_STANDALONE_CONFIG} <<EOF
  357. {
  358. "run_type": "server",
  359. "local_addr": "0.0.0.0",
  360. "local_port": ${trojanGFW_port},
  361. "remote_addr": "${remote_addr}",
  362. "remote_port": 80,
  363. "password": [
  364. "${trojan_pas}"
  365. ],
  366. "log_level": 1,
  367. "ssl": {
  368. "cert": "${CADDY_ACME}${domain}/${domain}.crt",
  369. "key": "${CADDY_ACME}${domain}/${domain}.key",
  370. "key_password": "",
  371. "cipher": "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384",
  372. "cipher_tls13": "TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384",
  373. "prefer_server_cipher": true,
  374. "alpn": [
  375. "http/1.1"
  376. ],
  377. "alpn_port_override": {
  378. "h2": 81
  379. },
  380. "reuse_session": true,
  381. "session_ticket": false,
  382. "session_timeout": 600,
  383. "plain_http_response": "",
  384. "curves": "",
  385. "dhparam": ""
  386. },
  387. "tcp": {
  388. "prefer_ipv4": false,
  389. "no_delay": true,
  390. "keep_alive": true,
  391. "reuse_port": false,
  392. "fast_open": false,
  393. "fast_open_qlen": 20
  394. },
  395. "mysql": {
  396. "enabled": false,
  397. "server_addr": "127.0.0.1",
  398. "server_port": 3306,
  399. "database": "",
  400. "username": "",
  401. "password": "",
  402. "key": "",
  403. "cert": "",
  404. "ca": ""
  405. }
  406. }
  407. EOF
  408. docker pull trojangfw/trojan &&
  409. docker run -d --name trojan-panel-trojanGFW-standalone --restart always \
  410. --network=host \
  411. -v ${TROJANGFW_STANDALONE_CONFIG}:"/config/config.json" \
  412. -v ${CADDY_ACME}:${CADDY_ACME} \
  413. trojangfw/trojan
  414. if [[ -n $(docker ps -q -f "name=^trojan-panel-trojanGFW-standalone$" -f "status=running") ]]; then
  415. echo_content skyBlue "---> TrojanGFW 单机版 安装完成"
  416. echo_content red "\n=============================================================="
  417. echo_content skyBlue "TrojanGFW+Caddy+Web+TLS节点 单机版 安装成功"
  418. echo_content yellow "域名: ${domain}"
  419. echo_content yellow "TrojanGFW的端口: ${trojanGFW_port}"
  420. echo_content yellow "TrojanGFW的密码: ${trojan_pas}"
  421. echo_content red "\n=============================================================="
  422. else
  423. echo_content red "---> TrojanGFW 单机版 安装失败或运行异常,请尝试修复或卸载重装"
  424. exit 0
  425. fi
  426. else
  427. echo_content skyBlue "---> 你已经安装了TrojanGFW 单机版"
  428. fi
  429. }
  430. # 安装TrojanGO 单机版
  431. install_trojanGO_standalone() {
  432. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") ]]; then
  433. echo_content green "---> 安装TrojanGO 单机版"
  434. read -r -p "请输入TrojanGO的端口(默认:443): " trojanGO_port
  435. [[ -z "${trojanGO_port}" ]] && trojanGO_port=443
  436. while read -r -p "请输入TrojanGO的密码(必填): " trojan_pas; do
  437. if [[ -z "${trojan_pas}" ]]; then
  438. echo_content red "密码不能为空"
  439. else
  440. break
  441. fi
  442. done
  443. while read -r -p "是否开启多路复用?(false/关闭 true/开启 默认:true/开启): " trojanGO_mux_enable; do
  444. if [[ -z "${trojanGO_mux_enable}" || ${trojanGO_mux_enable} == true ]]; then
  445. trojanGO_mux_enable=true
  446. break
  447. else
  448. if [[ ${trojanGO_mux_enable} != false ]]; then
  449. echo_content red "不可以输入除false和true之外的其他字符"
  450. else
  451. break
  452. fi
  453. fi
  454. done
  455. while read -r -p "是否开启Websocket?(false/关闭 true/开启 默认:false/关闭): " trojanGO_websocket_enable; do
  456. if [[ -z "${trojanGO_websocket_enable}" || ${trojanGO_websocket_enable} == false ]]; then
  457. trojanGO_websocket_enable=false
  458. break
  459. else
  460. if [[ ${trojanGO_websocket_enable} != true ]]; then
  461. echo_content red "不可以输入除false和true之外的其他字符"
  462. else
  463. read -r -p "请输入Websocket路径(默认:trojan-panel-websocket-path): " trojanGO_websocket_path
  464. [[ -z "${trojanGO_websocket_path}" ]] && trojanGO_websocket_path="trojan-panel-websocket-path"
  465. break
  466. fi
  467. fi
  468. done
  469. while read -r -p "是否启用Shadowsocks AEAD加密?(false/关闭 true/开启 默认:false/关闭): " trojanGO_shadowsocks_enable; do
  470. if [[ -z "${trojanGO_shadowsocks_enable}" || ${trojanGO_shadowsocks_enable} == false ]]; then
  471. trojanGO_shadowsocks_enable=false
  472. break
  473. else
  474. if [[ ${trojanGO_shadowsocks_enable} != true ]]; then
  475. echo_content yellow "不可以输入除false和true之外的其他字符"
  476. else
  477. echo_content skyBlue "Shadowsocks AEAD加密方式如下:"
  478. echo_content yellow "1. AES-128-GCM(默认)"
  479. echo_content yellow "2. CHACHA20-IETF-POLY1305"
  480. echo_content yellow "3. AES-256-GCM"
  481. read -r -p "请输入Shadowsocks AEAD加密方式(默认:1): " select_method_type
  482. [[ -z "${select_method_type}" ]] && select_method_type=1
  483. case ${select_method_type} in
  484. 1)
  485. trojanGO_shadowsocks_method="AES-128-GCM"
  486. ;;
  487. 2)
  488. trojanGO_shadowsocks_method="CHACHA20-IETF-POLY1305"
  489. ;;
  490. 3)
  491. trojanGO_shadowsocks_method="AES-256-GCM"
  492. ;;
  493. *)
  494. trojanGO_shadowsocks_method="AES-128-GCM"
  495. ;;
  496. esac
  497. while read -r -p "请输入Shadowsocks AEAD加密密码(必填): " trojanGO_shadowsocks_password; do
  498. if [[ -z "${trojanGO_shadowsocks_password}" ]]; then
  499. echo_content red "密码不能为空"
  500. else
  501. break
  502. fi
  503. done
  504. break
  505. fi
  506. fi
  507. done
  508. cat >${TROJANGO_STANDALONE_CONFIG} <<EOF
  509. {
  510. "run_type": "server",
  511. "local_addr": "0.0.0.0",
  512. "local_port": ${trojanGO_port},
  513. "remote_addr": "${remote_addr}",
  514. "remote_port": 80,
  515. "log_level": 1,
  516. "log_file": "",
  517. "password": [
  518. "${trojan_pas}"
  519. ],
  520. "disable_http_check": false,
  521. "udp_timeout": 60,
  522. "ssl": {
  523. "verify": true,
  524. "verify_hostname": true,
  525. "cert": "${CADDY_ACME}${domain}/${domain}.crt",
  526. "key": "${CADDY_ACME}${domain}/${domain}.key",
  527. "key_password": "",
  528. "cipher": "",
  529. "curves": "",
  530. "prefer_server_cipher": false,
  531. "sni": "",
  532. "alpn": [
  533. "http/1.1"
  534. ],
  535. "session_ticket": true,
  536. "reuse_session": true,
  537. "plain_http_response": "",
  538. "fallback_addr": "",
  539. "fallback_port": 80,
  540. "fingerprint": ""
  541. },
  542. "tcp": {
  543. "no_delay": true,
  544. "keep_alive": true,
  545. "prefer_ipv4": false
  546. },
  547. "mux": {
  548. "enabled": ${trojanGO_mux_enable},
  549. "concurrency": 8,
  550. "idle_timeout": 60
  551. },
  552. "websocket": {
  553. "enabled": ${trojanGO_websocket_enable},
  554. "path": "/${trojanGO_websocket_path}",
  555. "host": "${domain}"
  556. },
  557. "shadowsocks": {
  558. "enabled": ${trojanGO_shadowsocks_enable},
  559. "method": "${trojanGO_shadowsocks_method}",
  560. "password": "${trojanGO_shadowsocks_password}"
  561. },
  562. "mysql": {
  563. "enabled": false,
  564. "server_addr": "localhost",
  565. "server_port": 3306,
  566. "database": "",
  567. "username": "",
  568. "password": "",
  569. "check_rate": 60
  570. }
  571. }
  572. EOF
  573. docker pull p4gefau1t/trojan-go &&
  574. docker run -d --name trojan-panel-trojanGO-standalone --restart=always \
  575. --network=host \
  576. -v ${TROJANGO_STANDALONE_CONFIG}:"/etc/trojan-go/config.json" \
  577. -v ${CADDY_ACME}:${CADDY_ACME} \
  578. p4gefau1t/trojan-go
  579. if [[ -n $(docker ps -q -f "name=^trojan-panel-trojanGO-standalone$" -f "status=running") ]]; then
  580. echo_content skyBlue "---> TrojanGO 单机版 安装完成"
  581. echo_content red "\n=============================================================="
  582. echo_content skyBlue "TrojanGO+Caddy+Web+TLS+Websocket节点 单机版 安装成功"
  583. echo_content yellow "域名: ${domain}"
  584. echo_content yellow "TrojanGO的端口: ${trojanGO_port}"
  585. echo_content yellow "TrojanGO的密码: ${trojan_pas}"
  586. echo_content yellow "TrojanGO私钥和证书目录: ${CADDY_ACME}${domain}/"
  587. if [[ ${trojanGO_websocket_enable} == true ]]; then
  588. echo_content yellow "Websocket路径: ${trojanGO_websocket_path}"
  589. fi
  590. if [[ ${trojanGO_shadowsocks_enable} == true ]]; then
  591. echo_content yellow "Shadowsocks AEAD加密方式: ${trojanGO_shadowsocks_method}"
  592. echo_content yellow "Shadowsocks AEAD加密密码: ${trojanGO_shadowsocks_password}"
  593. fi
  594. echo_content red "\n=============================================================="
  595. else
  596. echo_content red "---> TrojanGO 单机版 安装失败或运行异常,请尝试修复或卸载重装"
  597. exit 0
  598. fi
  599. else
  600. echo_content skyBlue "---> 你已经了安装了TrojanGO 单机版"
  601. fi
  602. }
  603. # 安装Hysteria 单机版
  604. install_hysteria_standalone() {
  605. if [[ -z $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") ]]; then
  606. echo_content green "---> 安装Hysteria 单机版"
  607. echo_content skyBlue "Hysteria的模式如下:"
  608. echo_content yellow "1. udp(默认)"
  609. echo_content yellow "2. faketcp"
  610. read -r -p "请输入Hysteria的模式(默认:1): " selectProtocolType
  611. [[ -z "${selectProtocolType}" ]] && selectProtocolType=1
  612. case ${selectProtocolType} in
  613. 1)
  614. hysteria_protocol="udp"
  615. ;;
  616. 2)
  617. hysteria_protocol="faketcp"
  618. ;;
  619. *)
  620. hysteria_protocol="udp"
  621. ;;
  622. esac
  623. read -r -p "请输入Hysteria的端口(默认:443): " hysteria_port
  624. [[ -z ${hysteria_port} ]] && hysteria_port=443
  625. read -r -p "请输入单客户端最大上传速度/Mbps(默认:100): " hysteria_up_mbps
  626. [[ -z "${hysteria_up_mbps}" ]] && hysteria_up_mbps=100
  627. read -r -p "请输入单客户端最大下载速度/Mbps(默认:100): " hysteria_down_mbps
  628. [[ -z "${hysteria_down_mbps}" ]] && hysteria_down_mbps=100
  629. while read -r -p "请输入Hysteria的密码(必填): " hysteria_password; do
  630. if [[ -z ${hysteria_password} ]]; then
  631. echo_content red "密码不能为空"
  632. else
  633. break
  634. fi
  635. done
  636. cat >${HYSTERIA_STANDALONE_CONFIG} <<EOF
  637. {
  638. "listen": ":${hysteria_port}",
  639. "protocol": "${hysteria_protocol}",
  640. "cert": "${CADDY_ACME}${domain}/${domain}.crt",
  641. "key": "${CADDY_ACME}${domain}/${domain}.key",
  642. "up_mbps": ${hysteria_up_mbps},
  643. "down_mbps": ${hysteria_down_mbps},
  644. "obfs": "${hysteria_password}"
  645. }
  646. EOF
  647. docker pull tobyxdd/hysteria &&
  648. docker run -d --name trojan-panel-hysteria-standalone --restart=always \
  649. --network=host \
  650. -v ${HYSTERIA_STANDALONE_CONFIG}:/etc/hysteria.json \
  651. -v ${CADDY_ACME}:${CADDY_ACME} \
  652. tobyxdd/hysteria -c /etc/hysteria.json server
  653. if [[ -n $(docker ps -q -f "name=^trojan-panel-hysteria-standalone$" -f "status=running") ]]; then
  654. echo_content skyBlue "---> Hysteria 单机版 安装完成"
  655. echo_content red "\n=============================================================="
  656. echo_content skyBlue "Hysteria节点 单机版 安装成功"
  657. echo_content yellow "域名: ${domain}"
  658. echo_content yellow "Hysteria的端口: ${hysteria_port}"
  659. echo_content yellow "Hysteria的密码: ${hysteria_password}"
  660. echo_content yellow "Hysteria私钥和证书目录: ${CADDY_ACME}${domain}/"
  661. echo_content red "\n=============================================================="
  662. else
  663. echo_content red "---> Hysteria 单机版 安装失败或运行异常,请尝试修复或卸载重装"
  664. exit 0
  665. fi
  666. else
  667. echo_content skyBlue "---> 你已经安装了Hysteria 单机版"
  668. fi
  669. }
  670. # 卸载Caddy TLS
  671. uninstall_caddy_tls() {
  672. # 判断Caddy TLS是否安装
  673. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  674. echo_content green "---> 卸载Caddy TLS"
  675. docker rm -f trojan-panel-caddy &&
  676. rm -rf ${CADDY_DATA}
  677. echo_content skyBlue "---> Caddy TLS卸载完成"
  678. else
  679. echo_content red "---> 请先安装Caddy TLS"
  680. fi
  681. }
  682. # 卸载TrojanGFW 单机版
  683. uninstall_trojan_gfw_standalone() {
  684. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") ]]; then
  685. echo_content green "---> 卸载TrojanGFW 单机版"
  686. docker rm -f trojan-panel-trojanGFW-standalone &&
  687. docker rmi -f trojangfw/trojan &&
  688. rm -f ${TROJANGFW_STANDALONE_CONFIG}
  689. echo_content skyBlue "---> TrojanGFW 单机版卸载完成"
  690. else
  691. echo_content red "---> 请先安装TrojanGFW 单机版"
  692. fi
  693. }
  694. # 卸载TrojanGO 单机版
  695. uninstall_trojanGO_standalone() {
  696. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") ]]; then
  697. echo_content green "---> 卸载TrojanGO 单机版"
  698. docker rm -f trojan-panel-trojanGO-standalone &&
  699. docker rmi -f p4gefau1t/trojan-go &&
  700. rm -f ${TROJANGO_STANDALONE_CONFIG}
  701. echo_content skyBlue "---> TrojanGO 单机版卸载完成"
  702. else
  703. echo_content red "---> 请先安装TrojanGO 单机版"
  704. fi
  705. }
  706. # 卸载Hysteria节点 单机版
  707. uninstall_hysteria_standalone() {
  708. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") ]]; then
  709. echo_content green "---> 卸载Hysteria节点 单机版"
  710. docker rm -f trojan-panel-hysteria-standalone &&
  711. docker rmi -f tobyxdd/hysteria &&
  712. rm -f ${HYSTERIA_STANDALONE_CONFIG}
  713. echo_content skyBlue "---> Hysteria节点 单机版卸载完成"
  714. else
  715. echo_content red "---> 请先安装Hysteria节点 单机版"
  716. fi
  717. }
  718. # 卸载全部Trojan Panel相关的容器
  719. uninstall_all() {
  720. echo_content green "---> 卸载全部Trojan Panel相关的容器"
  721. docker rm -f $(docker ps -a -q -f "name=^trojan-panel") &&
  722. docker rmi -f $(docker images | grep "^trojan-panel" | awk '{print $3}') &&
  723. rm -rf ${TP_DATA}
  724. echo_content skyBlue "---> 卸载全部Trojan Panel相关的容器完成"
  725. }
  726. # 故障检测
  727. failure_testing() {
  728. echo_content green "---> 故障检测开始"
  729. if [[ ! $(docker -v 2>/dev/null) ]]; then
  730. echo_content red "---> Docker运行异常"
  731. else
  732. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-caddy$") ]]; then
  733. if [[ -z $(docker ps -q -f "name=^trojan-panel-caddy$" -f "status=running") ]]; then
  734. echo_content red "---> Caddy TLS运行异常"
  735. else
  736. domain=$(cat "${DOMAIN_FILE}")
  737. if [[ -z $(cat "${DOMAIN_FILE}") || ! -d "${CADDY_ACME}${domain}" || ! -f "${CADDY_ACME}${domain}/${domain}.crt" ]]; then
  738. echo_content red "---> 证书申请异常,请尝试重启服务器将重新申请证书或者重新搭建选择自定义证书选项"
  739. fi
  740. fi
  741. fi
  742. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGFW-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-trojanGFW-standalone$" -f "status=running") ]]; then
  743. echo_content red "---> TrojanGFW运行异常"
  744. fi
  745. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-trojanGO-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-trojanGO-standalone$" -f "status=running") ]]; then
  746. echo_content red "---> TrojanGO运行异常"
  747. fi
  748. if [[ -n $(docker ps -a -q -f "name=^trojan-panel-hysteria-standalone$") && -z $(docker ps -q -f "name=^trojan-panel-hysteria-standalone$" -f "status=running") ]]; then
  749. echo_content red "---> Hysteria运行异常"
  750. fi
  751. fi
  752. echo_content green "---> 故障检测结束"
  753. }
  754. # 卸载阿里云内置相关监控
  755. uninstall_aliyun() {
  756. # 卸载云监控(Cloudmonitor) Java 版
  757. /usr/local/cloudmonitor/wrapper/bin/cloudmonitor.sh stop &&
  758. /usr/local/cloudmonitor/wrapper/bin/cloudmonitor.sh remove &&
  759. rm -rf /usr/local/cloudmonitor
  760. # 卸载云盾(安骑士)
  761. wget --no-check-certificate -O uninstall.sh http://update.aegis.aliyun.com/download/uninstall.sh && chmod +x uninstall.sh && ./uninstall.sh
  762. wget --no-check-certificate -O quartz_uninstall.sh http://update.aegis.aliyun.com/download/quartz_uninstall.sh && chmod +x quartz_uninstall.sh && ./quartz_uninstall.sh
  763. pkill aliyun-service
  764. rm -fr /etc/init.d/agentwatch /usr/sbin/aliyun-service
  765. rm -rf /usr/local/aegis*
  766. iptables -I INPUT -s 140.205.201.0/28 -j DROP
  767. iptables -I INPUT -s 140.205.201.16/29 -j DROP
  768. iptables -I INPUT -s 140.205.201.32/28 -j DROP
  769. iptables -I INPUT -s 140.205.225.192/29 -j DROP
  770. iptables -I INPUT -s 140.205.225.200/30 -j DROP
  771. iptables -I INPUT -s 140.205.225.184/29 -j DROP
  772. iptables -I INPUT -s 140.205.225.183/32 -j DROP
  773. iptables -I INPUT -s 140.205.225.206/32 -j DROP
  774. iptables -I INPUT -s 140.205.225.205/32 -j DROP
  775. iptables -I INPUT -s 140.205.225.195/32 -j DROP
  776. iptables -I INPUT -s 140.205.225.204/32 -j DROP
  777. }
  778. main() {
  779. cd "$HOME" || exit 0
  780. init_var
  781. mkdir_tools
  782. check_sys
  783. depend_install
  784. clear
  785. echo_content red "\n=============================================================="
  786. echo_content skyBlue "System Required: CentOS 7+/Ubuntu 18+/Debian 10+"
  787. echo_content skyBlue "Version: v1.0.0"
  788. echo_content skyBlue "Description: One click Install Trojan Panel standalone server"
  789. echo_content skyBlue "Author: jonssonyan <https://jonssonyan.com>"
  790. echo_content skyBlue "Github: https://github.com/trojanpanel/install-script"
  791. echo_content red "\n=============================================================="
  792. echo_content yellow "1. 卸载阿里云盾(仅支持阿里云服务器)"
  793. echo_content yellow "2. 安装BBRPlus(仅支持CentOS系统)"
  794. echo_content green "\n=============================================================="
  795. echo_content yellow "3. 安装TrojanGFW+Caddy+Web+TLS+Websocket节点 单机版"
  796. echo_content yellow "4. 卸载TrojanGFW 单机版"
  797. echo_content green "\n=============================================================="
  798. echo_content yellow "5. 安装TrojanGO+Caddy+Web+TLS+Websocket节点 单机版"
  799. echo_content yellow "6. 卸载TrojanGO 单机版"
  800. echo_content green "\n=============================================================="
  801. echo_content yellow "7. 安装Hysteria节点 单机版"
  802. echo_content yellow "8. 卸载Hysteria节点 单机版"
  803. echo_content green "\n=============================================================="
  804. echo_content yellow "9. 卸载Caddy TLS"
  805. echo_content yellow "10. 卸载全部Trojan Panel相关的容器"
  806. echo_content green "\n=============================================================="
  807. echo_content yellow "11. 故障检测"
  808. read -r -p "请选择:" selectInstall_type
  809. case ${selectInstall_type} in
  810. 1)
  811. uninstall_aliyun
  812. ;;
  813. 2)
  814. install_bbr_plus
  815. ;;
  816. 3)
  817. install_docker
  818. install_caddy_tls
  819. install_trojan_gfw_standalone
  820. ;;
  821. 4)
  822. uninstall_trojan_gfw_standalone
  823. ;;
  824. 5)
  825. install_docker
  826. install_caddy_tls
  827. install_trojanGO_standalone
  828. ;;
  829. 6)
  830. uninstall_trojanGO_standalone
  831. ;;
  832. 7)
  833. install_docker
  834. install_caddy_tls
  835. install_hysteria_standalone
  836. ;;
  837. 8)
  838. uninstall_hysteria_standalone
  839. ;;
  840. 9)
  841. uninstall_caddy_tls
  842. ;;
  843. 10)
  844. uninstall_all
  845. ;;
  846. 11)
  847. failure_testing
  848. ;;
  849. *)
  850. echo_content red "没有这个选项"
  851. ;;
  852. esac
  853. }
  854. main