-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathcompose.yml
More file actions
48 lines (44 loc) · 1.79 KB
/
Copy pathcompose.yml
File metadata and controls
48 lines (44 loc) · 1.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
# Proxy Workbench as a small self-hosted service:
# check finds working proxies and re-checks them every 30 minutes
# api serves them over HTTP (http://127.0.0.1:8765/random, /proxies, /pac, /clash)
# gateway rotating proxy on 127.0.0.1:8899 (HTTP and SOCKS5)
#
# PROXY_WORKBENCH_API_TOKEN=change-me \
# PROXY_WORKBENCH_GATEWAY_TOKEN=another-secret docker compose up -d
#
# Two identities, two variables. `PROXY_WORKBENCH_API_TOKEN` is the Bearer token of
# the read-only API; `PROXY_WORKBENCH_GATEWAY_TOKEN` is the password a proxy client
# gives the gateway. They are deliberately never the same value: whoever knows the
# gateway password (a phone on the LAN, a QR code) must not be able to read the
# published snapshot, and a leaked API token must not be a working proxy.
# Leave the gateway variable unset and the gateway
# makes its own password and prints it in its log.
#
# Edit the check command to test your own service: --url https://example.org/health
x-workbench: &workbench
image: ghcr.io/davidvoitenko/proxy-workbench:latest
restart: unless-stopped
volumes:
- workbench-data:/app/data
services:
check:
<<: *workbench
command: ["run", "--want", "100", "--watch", "30"]
api:
<<: *workbench
command: ["serve", "--host", "0.0.0.0"]
environment:
PROXY_WORKBENCH_API_TOKEN: ${PROXY_WORKBENCH_API_TOKEN:?set PROXY_WORKBENCH_API_TOKEN}
ports:
- "127.0.0.1:8765:8765"
gateway:
<<: *workbench
command: ["gateway", "--host", "0.0.0.0", "--lan"]
environment:
# Not the API token: the gateway password is a separate identity. Unset is
# fine -- the gateway then generates one and prints it.
PROXY_WORKBENCH_GATEWAY_TOKEN: ${PROXY_WORKBENCH_GATEWAY_TOKEN:-}
ports:
- "127.0.0.1:8899:8899"
volumes:
workbench-data: