Files
prizma/docker-compose.example.yml
omarandClaude Opus 5 9605b906f7
test / go vet + go test + spa build (push) Successful in 6m41s
release / test gate (push) Successful in 17s
release / binaries + release (push) Successful in 56s
release / docker image (push) Successful in 34s
feat: Prizma — a subscription panel in front of other subscription panels
Upstream panels (Remnawave and friends) pin a subscription to one device
through the x-hwid header. Prizma holds that HWID per source, presents it on
every upstream fetch, and hands out its own link that any number of devices
may use. Everything else — the client's User-Agent, the response body, the
profile-title / subscription-userinfo / announce headers — is proxied through
untouched.

Two link kinds behind /sub/{token}:

  source  byte-for-byte proxy of one upstream, format chosen by the client
  group   several sources merged into one link: parallel fetch, parse, regex
          filtering by node name and by node content, protocol allow-list,
          dedupe, rename template, rendered in the negotiated format

Formats parse and render both ways: URI lists, base64, Clash/Mihomo YAML,
sing-box JSON, and Xray JSON including the Happ-style array of whole configs.
A node keeps the raw payload it was born from, so same-format rendering is
byte-identical and no vendor-specific field is ever dropped.

Access control is HWID-based and self-switching: an empty whitelist means
everyone passes except banned devices; whitelisting a single device locks the
links to the whitelist. Every device that fetches a link is recorded with its
UA, IP, hit count and timestamps, and can be banned, whitelisted or labelled
from the panel.

Ships as one static binary with the React admin panel embedded (CGO-free, so
linux/amd64+arm64, windows and darwin cross-compile from anywhere), as a
docker image, and with Gitea CI that gates releases on the test suite.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-31 13:18:23 +03:00

83 lines
2.7 KiB
YAML

# Prizma — example Compose deployment.
#
# cp docker-compose.example.yml docker-compose.yml
# cp .env.example .env # then edit ADMIN_PASSWORD
# docker compose up -d
#
# Every environment key below is documented in .env.example. `${VAR:-default}`
# means "take it from .env, otherwise use Prizma's own default" — so the only
# key you MUST set is ADMIN_PASSWORD, which uses `${VAR:?...}` instead and stops
# the stack rather than quietly starting with the password "admin".
services:
prizma:
image: git.qomar.pw/omar/prizma:latest
container_name: prizma
restart: unless-stopped
# Uncomment to build from a checkout instead of pulling the published image.
# build:
# context: .
# args:
# VERSION: dev
ports:
# host:container. Bind to 127.0.0.1 when a reverse proxy on the same host
# terminates TLS — Prizma itself serves plain HTTP.
- "127.0.0.1:8080:8080"
environment:
# --- network ---
PRIZMA_ADDR: ":8080"
PUBLIC_URL: "${PUBLIC_URL:-http://localhost:8080}"
# Set TRUST_PROXY only when something in front of you rewrites the client
# IP; a direct listener would let anyone forge X-Forwarded-For.
TRUST_PROXY: "${TRUST_PROXY:-false}"
# --- storage: on the named volume mounted at /data ---
PRIZMA_DB: "/data/prizma.db"
# --- admin auth ---
ADMIN_USER: "${ADMIN_USER:-admin}"
# No default on purpose: leaving this unset starts Prizma with the
# password "admin" and a loud warning in the log. Set it in .env.
ADMIN_PASSWORD: "${ADMIN_PASSWORD:?set ADMIN_PASSWORD in .env}"
# Empty -> generated once and persisted in the DB settings table.
JWT_SECRET: "${JWT_SECRET:-}"
# --- upstream fetching ---
CACHE_TTL: "${CACHE_TTL:-300}"
UPSTREAM_TIMEOUT: "${UPSTREAM_TIMEOUT:-20}"
# --- logging ---
LOG_LEVEL: "${LOG_LEVEL:-info}"
# Container clock, for log timestamps. tzdata is installed in the image.
TZ: "${TZ:-UTC}"
volumes:
# The SQLite DB (plus its -wal/-shm siblings) lives here. This is the only
# state Prizma has: back this up and you have backed up everything.
- prizma-data:/data
# The image's HEALTHCHECK curls /healthz; this only tightens the schedule.
healthcheck:
test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s
# Prizma writes only to /data and never spawns a subprocess.
security_opt:
- no-new-privileges:true
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"
volumes:
prizma-data: