Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,10 @@ For an existing inventory, pass `--inventory PATH` before the command. Generate
./mega-proxy summary
```

Optional personalized configuration feeds can run on separate HTTPS hosts using the same
inventory and user credentials. See [config API setup](docs/ru/config-api.md) and the
[inventory example](inventory.config-api.example.yml).

Inventory and generated exports contain secrets. Keep them private and do not commit them.

## Connect with Android MegaProxy
Expand Down
13 changes: 13 additions & 0 deletions docs/en/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,13 @@ Use dedicated SSH proxy logins, separate from the administrator. SSH key exports
`generated_private_key` on the control machine and embed its contents; a public key alone is not
enough to generate a client configuration. Android MegaProxy requires an unencrypted private key.

To link SSH accounts explicitly, set `ssh_users: [tun-alice]` on an HTTPS user or run
`./mega-proxy link-users` to choose existing accounts. The wizard offers this selection when
creating users of both types. An empty or omitted `ssh_users` means no links; names are never
matched automatically. Unknown accounts and duplicates fail inventory validation. An SSH account
may be linked to multiple HTTPS users; removing an SSH account also removes its links. These links
provide metadata for personalized delivery; the current `export` and `configs` commands still export all users.

For country flags, start host identifiers with a two-letter country code followed by `_`, such as
`de_entry` and `us_exit`. Explicit HTTPS chain pairs supply the exit country in `country_code`.
The code is a display hint; use the client connection test to check the observed exit country.
Expand Down Expand Up @@ -187,6 +194,12 @@ servers. Exports contain plaintext passwords and private keys; handle them as se

## Android MegaProxy

Optional `services.config_api` deploys personalized HTTPS configuration feeds to separate,
equal peers. See the [inventory example](../../inventory.config-api.example.yml) and
[configuration API guide (Russian)](../ru/config-api.md). Feeds use canonical v8, scrypt access
verification, password-encrypted SSH secrets, client projections, bootstrap subscriptions and
authenticated ETags. `/robots.txt` is public; other paths and invalid credentials return 403.

Compatibility was reviewed on 2026-09-08 against AndroidMegaProxy
[revision c8190e9](https://github.com/andre487/AndroidMegaProxy/tree/c8190e97b705a2c4578d278c40a690e97c5d5f27).
The client [importer](https://github.com/andre487/AndroidMegaProxy/blob/c8190e97b705a2c4578d278c40a690e97c5d5f27/app/src/main/java/net/megaproxy487/data/ConfigTransfer.kt)
Expand Down
12 changes: 12 additions & 0 deletions docs/ru/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -140,6 +140,14 @@ Inventory, ключи и экспорты остаются на сервере;
для генерации клиентского конфига недостаточно. Android MegaProxy требует приватный ключ без
парольной защиты.

Для явной привязки SSH-аккаунтов укажите у HTTPS-пользователя `ssh_users: [tun-alice]`
или выполните `./mega-proxy link-users` и выберите аккаунты из списка. Настройщик предлагает
этот выбор при создании пользователей обоих типов. Пустой или отсутствующий `ssh_users`
означает отсутствие привязки; имена автоматически не сопоставляются. Несуществующие аккаунты
и повторы отклоняются при проверке inventory. Один SSH-аккаунт можно привязать к нескольким
HTTPS-пользователям; удаление SSH-аккаунта также удаляет его привязки. Эти связи задают данные
для персональной выдачи; текущие команды `export` и `configs` по-прежнему экспортируют всех пользователей.

Для флагов стран начинайте идентификаторы хостов с двухбуквенного кода страны и `_`, например
`de_entry` и `us_exit`. В явных HTTPS-парах код страны выхода задаётся через `country_code`.
Это подпись для отображения; фактическую страну выхода проверяйте тестом соединения в приложении.
Expand Down Expand Up @@ -194,6 +202,10 @@ SAN, расширяет сертификат и перезапускает GOST,

## Android MegaProxy

Персональную выдачу конфигов по HTTPS на отдельных равноправных машинах можно включить
через `services.config_api`. См. [настройку API](config-api.md) и
[пример inventory](../../inventory.config-api.example.yml).

Совместимость проверена 2026-09-08 по AndroidMegaProxy
[ревизии c8190e9](https://github.com/andre487/AndroidMegaProxy/tree/c8190e97b705a2c4578d278c40a690e97c5d5f27).
Клиентский [импортёр](https://github.com/andre487/AndroidMegaProxy/blob/c8190e97b705a2c4578d278c40a690e97c5d5f27/app/src/main/java/net/megaproxy487/data/ConfigTransfer.kt)
Expand Down
Loading
Loading