Compare commits

..
3 Commits
Author SHA1 Message Date
renovate-bot ae686f9b55 chore(deps): update container patch updates
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 3s
ci / lint-prettier (pull_request) Successful in 3s
ci / lint-ruff (pull_request) Successful in 1s
ci / lint-yaml (pull_request) Successful in 3s
ci / lint-dockerfiles (pull_request) Successful in 2s
ci / validate (pull_request) Successful in 2s
ci / build (push) Has been skipped
ci / build (pull_request) Has been skipped
ci / deploy-userbot-panel (push) Has been skipped
renovate-ci / validate-renovate (pull_request) Successful in 11s
ci / deploy-userbot-panel (pull_request) Has been skipped
2026-09-21 10:17:55 +00:00
forust 9c4580a522 fix(prometheus): exclude xui services from TraefikServiceHighLatency
ci / lint-prettier (push) Successful in 3s
renovate-ci / validate-renovate (push) Successful in 9s
ci / build (push) Successful in 1s
ci / deploy-userbot-panel (push) Has been skipped
ci / lint-ruff (push) Successful in 2s
ci / lint-yaml (push) Successful in 3s
ci / lint-dockerfiles (push) Successful in 2s
ci / validate (push) Successful in 3s
Long-lived VPN WebSocket sessions inflate P95 request duration; keep 5xx/down/cert alerts for xui unchanged.
2026-09-19 19:06:42 +02:00
forust 4e3ad00202 feat(xui): add 3x-ui VPN panel behind cloudflared tunnel
VLESS+WS inbound (port 10000) via Traefik IngressRoute, panel on internal domains only with public route commented out. gitignore now covers nested k8s secrets and local-only grafana values.
2026-09-19 19:06:37 +02:00
10 changed files with 178 additions and 4 deletions

No files matched your search

+4
View File
@@ -104,6 +104,10 @@ temp/*
# kubernetes
*/k8s/*secret*
!*/k8s/*secret*.example
**/k8s/*secret*
!**/k8s/*secret*.example
# Local-only tweaks, not for upstream
prometheus-stack/k8s/grafana-values.yaml
traefik/k8s/local-tls.yaml
converters/k8s/config.yaml
convertx/k8s/config.yaml
+1 -1
View File
@@ -1,6 +1,6 @@
services:
n8n:
image: docker.n8n.io/n8nio/n8n:2.40.3
image: docker.n8n.io/n8nio/n8n:2.40.4
container_name: n8n
restart: unless-stopped
environment:
+1 -1
View File
@@ -27,7 +27,7 @@ spec:
spec:
containers:
- name: n8n
image: docker.n8n.io/n8nio/n8n:2.40.3
image: docker.n8n.io/n8nio/n8n:2.40.4
envFrom:
- configMapRef:
name: n8n-config
+1 -1
View File
@@ -42,7 +42,7 @@ spec:
- alert: TraefikServiceHighLatency
expr: |
histogram_quantile(0.95,
sum(rate(traefik_service_request_duration_seconds_bucket[5m])) by (le, service)) > 2
sum(rate(traefik_service_request_duration_seconds_bucket{service!~"xui-xui-service-.*"}[5m])) by (le, service)) > 2
for: 5m
labels:
severity: warning
+1 -1
View File
@@ -16,7 +16,7 @@ spec:
restartPolicy: Never
containers:
- name: renovate
image: renovate/renovate:44.103.7
image: renovate/renovate:44.103.0
env:
- name: RENOVATE_PLATFORM
value: gitea
View File
Whitespace-only changes.
+11
View File
@@ -0,0 +1,11 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: xui-config
namespace: xui
data:
XUI_DB_FOLDER: "/etc/x-ui"
XUI_ENABLE_FAIL2BAN: "false"
XUI_INIT_WEB_BASE_PATH: "/"
XUI_LOG_LEVEL: "warning"
XUI_PORT: "30379"
+81
View File
@@ -0,0 +1,81 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: xui-local
namespace: xui
spec:
entryPoints:
- websecure
routes:
- match: Host(`xui.workstation.internal`) || Host(`xui.gigaforust.internal`)
kind: Rule
services:
- name: xui-service
port: 30379
---
# Public panel access (optional).
# Realistic, but intentionally disabled: the panel has its own login,
# security-chain adds Authentik in front of it.
# To enable: uncomment and add Public Hostname `xui.forust.xyz`
# in the Cloudflare tunnel (same as other *.forust.xyz hosts).
# ---
# apiVersion: traefik.io/v1alpha1
# kind: IngressRoute
# metadata:
# name: xui-prod
# namespace: xui
# spec:
# entryPoints:
# - websecure
# routes:
# - match: Host(`xui.forust.xyz`)
# kind: Rule
# middlewares:
# - name: security-chain@file
# services:
# - name: xui-service
# port: 30379
# tls:
# certResolver: letsencrypt
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: xray-prod
namespace: xui
spec:
entryPoints:
- websecure
routes:
- match: Host(`xray.forust.xyz`) && PathPrefix(`/pzzfpz6oi281f0u8`)
kind: Rule
services:
- name: xui-service
port: 2096
- match: Host(`xray.forust.xyz`)
kind: Rule
services:
- name: xui-service
port: 10000
tls:
certResolver: letsencrypt
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: xray-local
namespace: xui
spec:
entryPoints:
- websecure
routes:
- match: (Host(`xray.workstation.internal`) || Host(`xray.gigaforust.internal`)) && PathPrefix(`/pzzfpz6oi281f0u8`)
kind: Rule
services:
- name: xui-service
port: 2096
- match: Host(`xray.workstation.internal`) || Host(`xray.gigaforust.internal`)
kind: Rule
services:
- name: xui-service
port: 10000
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: xui
+74
View File
@@ -0,0 +1,74 @@
apiVersion: v1
kind: Service
metadata:
name: xui-service
namespace: xui
spec:
selector:
app: xui
ports:
- port: 30379
name: panel
targetPort: 30379
- port: 10000
name: xray
targetPort: 10000
- port: 2096
name: sub
targetPort: 2096
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: xui-deployment
namespace: xui
spec:
replicas: 1
selector:
matchLabels:
app: xui
template:
metadata:
labels:
app: xui
spec:
containers:
- name: xui
image: ghcr.io/mhsanaei/3x-ui:v3.8.5
envFrom:
- configMapRef:
name: xui-config
tty: true
ports:
- containerPort: 30379
name: panel
- containerPort: 10000
name: xray
- containerPort: 2096
name: sub
volumeMounts:
- name: x-ui-db
mountPath: /etc/x-ui
resources:
requests:
memory: "128Mi"
cpu: "100m"
limits:
memory: "1Gi"
cpu: "1000m"
volumes:
- name: x-ui-db
persistentVolumeClaim:
claimName: xui-pvc
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: xui-pvc
namespace: xui
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi