Add VPN admin tab with subscription proxy via cp-vpn for selected sources.

Persist settings in CA, expose /admin/vpn and /internal/vpn, and route Telegram (and optional web/nlp) traffic through mihomo SOCKS when enabled.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-08-16 23:41:33 +03:00
co-authored by Cursor
parent 8ab606747f
commit 5811ecb134
25 changed files with 1146 additions and 18 deletions
+25 -4
View File
@@ -49,6 +49,17 @@ services:
- ca-api
restart: unless-stopped
cp-vpn:
build: ./centers/parsing/vpn
environment:
CA_API_URL: http://ca-api:8000
INTERNAL_TOKEN: ${INTERNAL_TOKEN:-dev-internal-token}
VPN_POLL_SECONDS: "15"
VPN_SOCKS_PORT: "1080"
depends_on:
- ca-api
restart: unless-stopped
cp-workers:
build:
context: .
@@ -62,14 +73,17 @@ services:
TELEGRAM_SESSION_PATH: /data/telegram.session
TELEGRAM_LISTENER_ENABLED: "true"
TELEGRAM_LISTENER_REFRESH_SECONDS: "60"
# Host xray is 127.0.0.1:10808; socat on host forwards 0.0.0.0:11080 → that SOCKS
# Env fallback when VPN tab is off (host Happ/xray; socat 11080→10808).
# Overrides .env 127.0.0.1 which is wrong inside the container.
TELEGRAM_PROXY_HOST: host.docker.internal
TELEGRAM_PROXY_PORT: "11080"
CP_VPN_HOST: cp-vpn
CP_VPN_PORT: "1080"
ENABLED_ADAPTERS: telegram
WORKER_FAMILIES: telegram
CA_API_URL: http://ca-api:8000
REDIS_URL: redis://redis:6379/0
INTERNAL_TOKEN: dev-internal-token
INTERNAL_TOKEN: ${INTERNAL_TOKEN:-dev-internal-token}
extra_hosts:
- "host.docker.internal:host-gateway"
volumes:
@@ -77,6 +91,7 @@ services:
depends_on:
- redis
- ca-api
- cp-vpn
restart: unless-stopped
cp-workers-web:
@@ -92,12 +107,15 @@ services:
TELEGRAM_LISTENER_ENABLED: "false"
ENABLED_ADAPTERS: crawl4ai
WORKER_FAMILIES: web
CP_VPN_HOST: cp-vpn
CP_VPN_PORT: "1080"
CA_API_URL: http://ca-api:8000
REDIS_URL: redis://redis:6379/0
INTERNAL_TOKEN: dev-internal-token
INTERNAL_TOKEN: ${INTERNAL_TOKEN:-dev-internal-token}
depends_on:
- redis
- ca-api
- cp-vpn
restart: unless-stopped
cp-workers-nlp:
@@ -111,12 +129,15 @@ services:
TELEGRAM_LISTENER_ENABLED: "false"
ENABLED_ADAPTERS: viina
WORKER_FAMILIES: nlp
CP_VPN_HOST: cp-vpn
CP_VPN_PORT: "1080"
CA_API_URL: http://ca-api:8000
REDIS_URL: redis://redis:6379/0
INTERNAL_TOKEN: dev-internal-token
INTERNAL_TOKEN: ${INTERNAL_TOKEN:-dev-internal-token}
depends_on:
- redis
- ca-api
- cp-vpn
restart: unless-stopped
volumes: