Skip to content

Add baseline support for config subscriptions - #3

Merged
andre487 merged 1 commit into
mainfrom
feat/config-subscriptions
Oct 10, 2026
Merged

andre487 merged 1 commit into
mainfrom
feat/config-subscriptions

Conversation

@andre487

Copy link
Copy Markdown
Owner

Inventory currently supports local config exports only. Add an optional HTTPS service on separate inventory hosts so clients can subscribe to personalized MegaProxy v8 configurations generated on every authenticated request. All API instances are peers and advertise the other configured endpoints as subscription fallbacks.

Changes

  • Deploy a loopback Python API behind nginx with trusted domain or public-IP certificates, certificate renewal, firewall rules and service hardening.
  • Verify UTF-8 Basic Auth using salted scrypt hashes. Store user configuration and linked SSH secrets encrypted with AES-GCM under a password-derived key; generate credentials from each authenticated request.
  • Add explicit HTTPS-to-SSH account bindings and return only authorized direct and jump profiles. Support documented v8 settings, additional existing transport profiles, client-specific responses, stable profile IDs and authenticated ETags against pinned upstream schemas.
  • Return 403 for invalid paths, methods and credentials, with the deliberate exception of public GET /robots.txt returning 200 and Disallow: /. Add noindex headers and disable access logging and response caching.
  • Add inventory examples, setup documentation, CLI/wizard support and deployment verification. Derive omitted administrative public keys from their private keys and scope bootstrap inventory to the current host.

Existing local exports retain their v7 format. This change does not deploy new SOCKS5 or MASQUE servers. Production deployment has not been verified on target hosts.

Validation

  • pytest -q: 84 passed.
  • Ruff and git diff --check: passed.
  • Ansible syntax checks for site, bootstrap and verify playbooks: passed.
  • Real nginx HTTPS integration: trusted certificate verification, v8 response, authenticated ETag, exact paths, robots.txt, 403 responses and noindex headers passed.

Private inventory, user credentials and generated bundles are excluded from this PR.

@andre487
andre487 merged commit 8cb1ada into main Oct 10, 2026
9 of 10 checks passed
@andre487
andre487 deleted the feat/config-subscriptions branch October 10, 2026 21:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant