commit 3e5f89c7062ebeaa82013de94e831d78b3c9273a Author: Xi Xu Date: Fri Dec 19 16:17:52 2025 +0800 Initial commit: add installer, README, and license Add install.sh for automated HY proxy and nginx deployment with SSL, a comprehensive README with usage instructions, and the MIT license. This sets up the project foundation for one-command server setup on Debian/Ubuntu. diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..99f5cea --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2025 Xi Xu + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md new file mode 100644 index 0000000..41057e2 --- /dev/null +++ b/README.md @@ -0,0 +1,250 @@ +# HY Nginx Deploy + +One-command automated deployment script for setting up a HY proxy server with nginx and SSL certificates on Debian/Ubuntu systems. + +## Features + +- 🚀 **One-Command Setup**: Fully automated installation and configuration +- 🔒 **Automatic SSL**: Let's Encrypt certificate management via Certbot +- 🌐 **Nginx Integration**: Professional masquerade website on port 443/TCP +- 🛡️ **Security Hardened**: UFW firewall configuration and system tuning +- 🔐 **Auto-Generated Passwords**: Secure random password generation +- 📝 **Ready-to-Use Config**: Outputs client configuration + +## Quick Start + +```bash +sudo bash -c "$(curl -fsSL https://github.com/xixu-me/hy-nginx-deploy/raw/refs/heads/main/install.sh)" -s -d example.com -e admin@example.com +``` + +Replace `example.com` with your domain and `admin@example.com` with your email. + +## Requirements + +- **OS**: Ubuntu 20.04+ or Debian 11+ (x86_64) +- **Domain**: A domain name pointed to your server's IP address +- **Root Access**: Script must be run with sudo/root privileges +- **Ports**: 22 (SSH), 80 (HTTP), 443/TCP (HTTPS), 443/UDP (HY) + +## Installation + +### Method 1: Direct Download + +```bash +curl -fsSL https://raw.githubusercontent.com/xixu-me/hy-nginx-deploy/main/install.sh -o install.sh +sudo bash install.sh -d your-domain.com -e your@email.com +``` + +### Method 2: Clone Repository + +```bash +git clone https://github.com/xixu-me/hy-nginx-deploy.git +cd hy-nginx-deploy +sudo bash install.sh -d your-domain.com -e your@email.com +``` + +## Usage + +``` +sudo bash install.sh -d -e [-p ] [--no-ufw] [--no-sysctl] + +Options: + -d, --domain Domain name (required) + -e, --email Email for Let's Encrypt registration (required) + -p, --password HY password (optional; auto-generated if omitted) + --no-ufw Do not enable/modify UFW firewall + --no-sysctl Do not apply sysctl tuning for UDP buffers + -h, --help Show help message +``` + +### Examples + +**Basic installation with auto-generated password:** + +```bash +sudo bash install.sh -d proxy.example.com -e admin@example.com +``` + +**Custom password:** + +```bash +sudo bash install.sh -d proxy.example.com -e admin@example.com -p MySecurePass123 +``` + +**Skip firewall configuration:** + +```bash +sudo bash install.sh -d proxy.example.com -e admin@example.com --no-ufw +``` + +## What Gets Installed + +The script automatically sets up: + +1. **Nginx Web Server** + - Serves a masquerade website on port 443/TCP + - SSL/TLS termination via Let's Encrypt + - Automatic certificate renewal + +2. **HY Server** + - Listens on port 443/UDP + - Password authentication + - SSL certificates from Let's Encrypt + - Masquerades as HTTPS traffic to nginx + +3. **SSL Certificates** + - Let's Encrypt certificates via Certbot + - Automatic HTTPS redirect + - Shared between nginx and HY + +4. **Firewall (UFW)** + - Port 22 (SSH) + - Port 80 (HTTP) + - Port 443/TCP (HTTPS) + - Port 443/UDP (HY) + +5. **System Tuning** + - UDP buffer optimization for better performance + +## Client Configuration + +After installation, the script outputs a ready-to-use configuration: + +```yaml +proxies: + - name: "hy2-your-domain.com" + type: hysteria2 + server: your-domain.com + port: 443 + password: "your-generated-password" + skip-cert-verify: false + alpn: + - h3 +``` + +Copy this configuration to your client. + +## Management + +### Check Service Status + +```bash +# Nginx +systemctl status nginx + +# HY +systemctl status hysteria-server.service +``` + +### View Logs + +```bash +# Nginx +tail -f /var/log/nginx/access.log +tail -f /var/log/nginx/error.log + +# HY +journalctl -u hysteria-server.service -f +``` + +### Restart Services + +```bash +# Nginx +systemctl restart nginx + +# HY +systemctl restart hysteria-server.service +``` + +### Certificate Renewal + +Certificates are automatically renewed by Certbot. To manually renew: + +```bash +certbot renew +systemctl reload nginx +systemctl restart hysteria-server.service +``` + +## Configuration Files + +- **Nginx**: `/etc/nginx/sites-available/your-domain.com` +- **HY**: `/etc/hysteria/config.yaml` +- **Web Root**: `/var/www/your-domain.com` +- **SSL Certificates**: `/etc/letsencrypt/live/your-domain.com/` + +## Troubleshooting + +### Domain Not Resolving + +Ensure your domain's DNS A record points to your server's IP: + +```bash +dig +short your-domain.com +``` + +### Certbot Fails + +- Verify domain DNS is correctly configured +- Check ports 80 and 443/TCP are accessible +- Ensure no other web server is running + +### HY Connection Issues + +```bash +# Check service status +systemctl status hysteria-server.service + +# View detailed logs +journalctl -u hysteria-server.service -n 50 + +# Test UDP port +nc -vzu your-ip 443 +``` + +### Firewall Blocking Traffic + +```bash +# Check UFW status +ufw status verbose + +# Allow required ports +ufw allow 80/tcp +ufw allow 443/tcp +ufw allow 443/udp +``` + +## Security Considerations + +- The script generates cryptographically secure random passwords +- All traffic is encrypted with TLS 1.3 +- Consider using a strong custom password with `-p` option +- Regularly update the system: `apt update && apt upgrade` +- Monitor logs for suspicious activity + +## Uninstallation + +```bash +# Stop and disable services +systemctl stop hysteria-server.service nginx +systemctl disable hysteria-server.service nginx + +# Remove packages +apt remove --purge nginx certbot python3-certbot-nginx + +# Remove configurations +rm -rf /etc/hysteria /etc/nginx /var/www/your-domain.com +rm -rf /etc/letsencrypt + +# Remove HY binary +rm -f /usr/local/bin/hysteria +``` + +## License + +[MIT License](LICENSE) + +## Disclaimer + +This tool is for educational and legitimate use only. Users are responsible for complying with local laws and regulations. The authors are not responsible for any misuse or damage caused by this software. diff --git a/install.sh b/install.sh new file mode 100644 index 0000000..48e0145 --- /dev/null +++ b/install.sh @@ -0,0 +1,282 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Constants +DOMAIN="" +EMAIL="" +HY_PASS="" +NO_UFW=0 +NO_SYSCTL=0 + +# Colors +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +RED='\033[0;31m' +NC='\033[0m' # No Color + +log() { echo -e "${GREEN}[+] $*${NC}"; } +warn() { echo -e "${YELLOW}[!] $*${NC}" >&2; } +err() { echo -e "${RED}[✗] $*${NC}" >&2; exit 1; } + +need_root() { + [[ "${EUID}" -eq 0 ]] || err "Please run as root: sudo bash $0 ..." +} + +check_os() { + if [[ -f /etc/os-release ]]; then + source /etc/os-release + if [[ "${ID}" != "ubuntu" && "${ID}" != "debian" ]]; then + warn "This script is optimized for Debian/Ubuntu. Your OS (${ID}) might not be supported." + read -r -p "Press ENTER to continue anyway, or Ctrl+C to abort..." + fi + else + err "Cannot detect OS. /etc/os-release not found." + fi +} + +has_cmd() { command -v "$1" >/dev/null 2>&1; } + +usage() { + cat < -e [-p ] [--no-ufw] [--no-sysctl] + +Options: + -d, --domain Domain name (required) + -e, --email Email for Let's Encrypt registration (required) + -p, --password HY password (optional; auto-generated if omitted) + --no-ufw Do not enable/modify UFW (firewall) + --no-sysctl Do not apply sysctl tuning (UDP buffers) + -h, --help Show this help message + +Example: + sudo bash $0 -d example.com -e admin@example.com +EOF +} + +parse_args() { + while [[ $# -gt 0 ]]; do + case "$1" in + -d|--domain) DOMAIN="${2:-}"; shift 2;; + -e|--email) EMAIL="${2:-}"; shift 2;; + -p|--password) HY_PASS="${2:-}"; shift 2;; + --no-ufw) NO_UFW=1; shift 1;; + --no-sysctl) NO_SYSCTL=1; shift 1;; + -h|--help) usage; exit 0;; + *) err "Unknown argument: $1 (use -h for help)";; + esac + done + + # Interactive prompts if missing args + if [[ -z "${DOMAIN}" ]]; then + read -r -p "Enter your domain (e.g., example.com): " DOMAIN + fi + if [[ -z "${EMAIL}" ]]; then + read -r -p "Enter your email for Let's Encrypt: " EMAIL + fi + + # Generate password if missing + if [[ -z "${HY_PASS}" ]]; then + if has_cmd openssl; then + HY_PASS="$(openssl rand -base64 24 | tr -d '\n')" + else + HY_PASS="$(tr -dc 'A-Za-z0-9' "${webroot}/index.html" < + + + + + Welcome to ${DOMAIN} + + + +
+

${DOMAIN}

+

Site is under construction.

+
+ + +EOF + chown -R www-data:www-data "${webroot}" + + local site_avail="/etc/nginx/sites-available/${DOMAIN}" + if [[ -f "${site_avail}" ]]; then + cp -a "${site_avail}" "${site_avail}.$(date +%F_%H%M%S).bak" + warn "Existing nginx config found. Backed up to ${site_avail}.bak" + fi + + cat > "${site_avail}" < /etc/hysteria/config.yaml < /etc/sysctl.d/99-hy.conf <<'EOF' +net.core.rmem_max=16777216 +net.core.wmem_max=16777216 +EOF + sysctl --system >/dev/null +} + +setup_ufw() { + [[ "${NO_UFW}" -eq 1 ]] && { warn "Skipping UFW setup."; return 0; } + + log "Configuring UFW firewall..." + ufw allow 22/tcp # SSH + ufw allow 80/tcp # HTTP + ufw allow 443/tcp # HTTPS + ufw allow 443/udp # HY (QUIC) + + if ufw status | grep -qi "inactive"; then + echo "y" | ufw enable >/dev/null || true + fi +} + +print_proxies() { + echo + echo "========== Client Config Snippet ==========" + cat <