Skip to content

Latest commit

 

History

102 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

XVEI — Xray (+ Hysteria2) easy install & live editor

Run everything as root.

XVEI installs and configures Xray-core (and optionally Hysteria2) and then lets you reshape the configuration without reinstalling — add/remove inbounds, add/remove WARP/TOR, edit routing rules, switch the country template, swap the camouflage site. Every change is validated and applied automatically.

All configuration lives in one state file (/usr/local/etc/xray/xvei-state.json); a small Python engine (standard library only, no pip packages) regenerates config.json, validates it with xray -test, and only then swaps it in and restarts the services.

What it can do

Inbounds

type notes
vless-tls VLESS + TCP + TLS + xtls-rprx-vision, on :443, nginx fallback
vless-ws VLESS + WebSocket, rides the :443 fallback (needs vless-tls)
vless-xhttp-reality VLESS + XHTTP + REALITY — site masquerade, no domain/cert required
vless-xhttp-tls VLESS + XHTTP + TLS certificate (shares :443 or standalone)
shadowsocks Shadowsocks 2022 / legacy ciphers
hysteria2 Hysteria2 on :443/udp; all its traffic is forwarded into a local SOCKS5 inbound of Xray, so Xray does the routing

Outbounds / tunnels

direct, block, and optionally WARP (Cloudflare, docker) or TOR as a second hop that hides the server IP.

Routing templates

Pick at install time (changeable later with xvei template). These are server-side rules — what leaves the VPS on its own real IP, not what the client device does.

  • Country templaterussia / iran / china / none. In-country destinations (geoip:<cc> + local geosite categories) never go direct from the server — a VPS reaching straight into RU/IR/CN networks exposes its real IP to them and risks getting the server blacklisted. That traffic requires --exit warp|tor|block:
    • warp / tor — leaves through a second hop, the server IP stays hidden;
    • block — dropped outright. Everything else (not in-country) follows the regular exit mode:
    • --direct — straight out;
    • --tunnel warp|tor — through a tunnel.
  • "Popular direct" templatepopular. Global, non-country-specific services (geosite:youtube, instagram, google, telegram, netflix, github, etc. — tags present in essentially any geosite.dat build) go direct for speed; everything else requires --tunnel warp|tor.

Editable rule buckets

block, direct, warp, tor — add/remove matchers (geosite:…, geoip:…, domain:…, 1.2.3.0/24, regexp:…) live.

Camouflage site

What a normal browser sees when it opens the domain directly (the nginx fallback for vless-tls / vless-xhttp-tls). Change any time with xvei site:

  • auth — HTTP Basic auth prompt against an empty file, always 401 (default, same as the old script)
  • blank / 404 — a bare page / plain 404
  • static presets — self-contained pages with no external requests (safe, work offline): nebula (solar-system facts), critters (animal encyclopedia), game2048, snake, notes (a personal blog)
  • proxy <url|preset> — reverse-proxy a real upstream. Most sites break when proxied (bot walls, host checks, absolute redirects), so a few known-proxyable ones are presets: example, rfc, cern, gnu, iana.

Install

apt-get update && apt-get -y install curl
bash <(curl -fsSL https://raw.githubusercontent.com/Shark-vil/xray_vless_easy_install_script/master/xvei.sh) install

The first run downloads the script tree to /usr/local/lib/xvei and symlinks xvei into /usr/local/bin, so afterwards just run xvei.

Usage

xvei                     interactive menu (or offer to install)
xvei install             guided first-time setup
xvei edit                interactive menu
xvei apply               regenerate + validate + restart from the current state

xvei add-inbound  <type> [--port N] [--dest SNI] [--method M]
xvei remove-inbound <tag>
xvei add-outbound   <warp|tor>
xvei remove-outbound <warp|tor>
xvei rule <add|remove|list> <block|warp|tor|direct> [matcher ...]
xvei template <russia|iran|china> --exit <warp|tor|block> [--tunnel <warp|tor> | --direct]
xvei template popular --tunnel <warp|tor>
xvei template none [--tunnel <warp|tor> | --direct]
xvei site [list | auth | blank | 404 | <preset> | proxy <url|preset>]

xvei links [tag]         print client share links
xvei qr <tag>            QR code for one inbound
xvei status              services + active template
xvei set-meta [--domain D --email E ...]
xvei update-geo          refresh geoip/geosite (optional; the xray installer ships them)
xvei self-update         re-fetch the script tree
xvei remove              uninstall everything

Examples:

xvei add-inbound vless-xhttp-reality --dest www.samsung.com
xvei add-outbound tor
xvei rule add tor geosite:openai
xvei rule add block geosite:category-ads-all
xvei template russia --exit warp --direct  # RU traffic via WARP, rest direct
xvei template popular --tunnel tor         # popular sites direct, rest via TOR
xvei remove-inbound hy2                    # stops & removes Hysteria2, keeps the rest
xvei site game2048                         # serve a 2048 game on the domain
xvei site proxy gnu                        # reverse-proxy www.gnu.org

Every command that changes the state re-runs generate → xray -test → swap → restart automatically. If validation fails, the live config is left untouched.

A certbot deploy hook (/etc/letsencrypt/renewal-hooks/deploy/xvei-restart.sh) is installed with the certificate: after every Let's Encrypt renewal it refreshes the Hysteria2 cert copy and restarts xray, nginx and hysteria2.

Files

path contents
/usr/local/etc/xray/xvei-state.json source of truth (root, 0600)
/usr/local/etc/xray/config.json generated Xray config (.bak kept)
/etc/hysteria/config.yaml generated Hysteria2 config (+ cert.crt/cert.key)
/etc/nginx/sites-enabled/xvei.conf, /var/www/xvei-site fallback vhost + camouflage site
~/xray_eis/<tag>.link client share link per inbound
~/xray_eis/<tag>.json full Xray client config per inbound (not for hysteria2)

Repository layout

xvei.sh            entry point + bootstrap + subcommand dispatch
lib/*.sh           system side: package install, xray, nginx, certs, hysteria2, warp, tor, apply, menu
pyengine/*.py      config engine (stdlib only): state, inbounds, outbounds, routing, sites, links, editor
assets/sites/*     self-contained camouflage sites (no external requests)

Clients

v2rayNG, NekoBox / nekoray, Hiddify. REALITY and XHTTP need a reasonably recent client build; the hysteria2 inbound needs a Hysteria2-capable client (Hiddify, NekoBox, the official hysteria client).

xvei links prints the share URIs; xvei qr <tag> shows a scannable code. Apps that cannot import a vless:// / ss:// link can load the full config from ~/xray_eis/<tag>.json.

About

This script will help you to easily install and customize the configuration file for Vless / Vless WebSocket / Shadowsocks. All you need to have is a server, domain and mail. All the configuration work is taken care of by the script.

Topics

Resources

Stars

72 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages