Sign inSign up

80x86/clash

By 80x86

•Updated about 3 years ago

clash image with yacd web UI for Linux and Router

Image
31

10K+

80x86/clash repository overview

⁠warning: web ui port changed from 9092 to 8082 due to conflict with Kafka broker default port

⁠clash for docker

clash image with yacd web UI for Linux and Router

⁠usage

dashboard URL: http://127.0.0.1:8082/ui/⁠ (use your router/NAS IP is you deploy it on a router/NAS)

clash config dir (home dir) in container: /etc/clash

config.yaml recommand port related options:

port: 7890
socks-port: 7891
redir-port: 7892

⁠setup the container

please ref to clash official document⁠ to create your own config.yaml.

put the file named run.clash.sh, in the same directoy of config.yaml

#!/bin/sh

# create the user first
# sudo useradd -c "user for clash" -M -N -s /usr/sbin/nologin -u 1024 clash

docker run --user 1024:100 --name clash -d \
--network host \
--restart=unless-stopped \
-e CLASH_CTL_ADDR="0.0.0.0:8082" \
-e CLASH_SECRET="YOUR-PASSWORD-HERE" \
-v $(pwd)/config.yaml:/etc/clash/config.yaml:ro,z \
-v $(pwd)/GeoIP2-Country-2020-08-18.mmdb:/etc/clash/Country.mmdb:ro,z \
80x86/clash:v1.5.0

run sudo useradd -c "user for clash" -M -N -s /usr/sbin/nologin -u 1024 clash create the user first, if you do not have done this.

go to https://db-ip.com/db/download/ip-to-country-lite⁠ and click the Download IP to Country Lite MMDB button to download the

GeoIP2-Country mmdb file. and remember change GeoIP2-Country-2020-08-18.mmdb to your current file name.

# https://download.db-ip.com/free/dbip-country-lite-2021-06.mmdb.gz

curl -LZ https://download.db-ip.com/free/dbip-country-lite-$(date +%Y-%m).mmdb.gz -o/data/GeoDB/dbip-country-lite-$(date +%Y-%m).mmdb.gz
gunzip dbip-country-lite-$(date +%Y-%m).mmdb.gz

finally, run sudo ./run.clash.sh to create and start the container.

⁠setup DNS

clash must enable DNS feature (set dns.enable to true, see below) if your config.yaml contains DOMAIN-SUFFIX or DOMAIN rules

related config (only part):

port: 7890
socks-port: 7891
redir-port: 7892
tproxy-port: 0
mixed-port: 0
authentication: []
allow-lan: true
bind-address: "*"
mode: rule
log-level: debug
ipv6: false
external-controller: 0.0.0.0:8082
external-ui: ""
secret: ""
interface-name: ""
proxy-providers: {}
hosts: {}
dns:
  enable: true
  ipv6: false
  use-hosts: true
  nameserver:
  - 114.114.114.114
  - 223.5.5.5
  fallback:
  - tls://1.1.1.1:853
  - tls://dns.google
  - tcp://208.67.222.222:443
  fallback-filter:
    geoip: true
    ipcidr:
    - 240.0.0.0/4
    domain: []
  listen: 0.0.0.0:5354
  enhanced-mode: redir-host
  fake-ip-range: 198.18.0.1/16
  fake-ip-filter: []
  default-nameserver:
  - 114.114.114.114
  - 8.8.8.8
experimental: {}
profile:
  store-selected: true

this config, we tell clash listen on UDP 5354 port.

we should config the Linux machine or Router's DNS service to use clash's DNS as upstream.

example systemd-resolved config:

/etc/systemd/resolved.conf

# See resolved.conf(5) for details

[Resolve]
DNS=127.0.0.1:5354 
FallbackDNS=
#Domains=
#DNSSEC=no
#DNSOverTLS=no
#MulticastDNS=yes
#LLMNR=yes
Cache=yes
#DNSStubListener=yes
#DNSStubListenerExtra=
#ReadEtcHosts=yes
#ResolveUnicastSingleLabel=no

and /etc/resolv.conf should contain only one nameserver item:

nameserver 127.0.0.53

127.0.0.53 is the interface address what systemd-resolved is listen on, you can confirm it by this:

❯ sudo ss -tunl | grep ':53 '
udp   UNCONN 0      0                              127.0.0.53%lo:53         0.0.0.0:*          
udp   UNCONN 0      0                              192.168.122.1:53         0.0.0.0:*          
tcp   LISTEN 0      4096                           127.0.0.53%lo:53         0.0.0.0:*          
tcp   LISTEN 0      32                             192.168.122.1:53         0.0.0.0:* 
⁠client IP and DNS setup

for example, the Linux NAS / Router have IP 192.168.8.123,

you client PC / Notebook / Mobile phone should set both gateway and DNS server IP to 192.168.8.123

the gateway is for transparent proxy.

the DNS is for fuck DNS polution.

⁠transparent proxy setup for Linux / Router

(this step is not necessary if you only use http/sock5 proxy)

first we need enable IP forwarding.

check using cat /proc/sys/net/ipv4/ip_forward

temp enable echo 1 > /proc/sys/net/ipv4/ip_forward

enable it permanantly:

edit /etc/sysctl.conf and add:

net.ipv4.ip_forward = 1

download and put this file⁠ to /usr/local/bin/tproxy.sh

you can use systemd to auto execute the shell script.

create the file /etc/systemd/system/tproxy.service, content as below:

[Unit]
Description=Clash transparent proxy iptables rules
After=network-online.target
After=firewalld.target
Wants=network-online.target

After=docker.service
#BindsTo=docker.service
ReloadPropagatedFrom=docker.service

[Service]
Type=oneshot
User=root
RemainAfterExit=yes
ExecStart=/usr/local/bin/tproxy.sh start
ExecStop=/usr/local/bin/tproxy.sh stop

[Install]
WantedBy=multi-user.target

enable and run:

sudo systemctl --enable --now tproxy.service

Tag summary

Content type

Image

Digest

sha256:30709afe1…

Size

60.4 MB

Last updated

about 3 years ago

docker pull 80x86/clash:premium-2023.06.30