feat(agent): WARP 域名分流 —— 命中域名走 Cloudflare 干净出口(#29)

节点 sing-box 渲染新增可选 WARP 分流:节点本地 warp.json(默认
<StateDir>/warp.json)配 WARP 凭证 + 域名清单 → 渲染时注入一个 userspace
WireGuard(WARP)endpoint + route(sniff 取 SNI/Host → domain_suffix 命中走
warp,其余 final=direct)。sing-box 1.11+ endpoints 语法,system=false 用户态
不依赖内核 wg 模块。

- 运营改域名只需编辑 warp.json + 重启 agent(sing-box 无热重载),即「配置的方式」。
- warp.json 不存在/enabled=false/域名空/凭证缺/坏 JSON → 一律按未启用,配置与旧
  节点逐字节一致,坏配置绝不产出无法启动的 sing-box config(渲染读失败仅记日志)。
- WARP 凭证节点私有(wgcf 注册免费匿名账号),不入 git、不经控制面。
- 测试:注入 endpoint+route/无配置无 route/禁用或残缺不注入/坏 JSON 优雅退化。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-07-02 13:40:00 +08:00
parent f035552ff5
commit eb7c3c1062
5 changed files with 303 additions and 3 deletions
+7
View File
@@ -54,6 +54,10 @@ type Config struct {
// SingboxConfigPath is where the rendered sing-box config is written.
SingboxConfigPath string
// WarpConfigPath 指向节点本地的 WARP 分流配置(默认 <StateDir>/warp.json)。
// 文件不存在 = WARP 未启用。渲染时读取,支持编辑后重启 agent 生效(#29)。
WarpConfigPath string
// DeriveKey keys the Hy2 password derivation (see DeriveHy2Password).
DeriveKey string
@@ -79,6 +83,9 @@ func (c Config) withDefaults() Config {
if c.SingboxConfigPath == "" {
c.SingboxConfigPath = DefaultSingboxCfg
}
if c.WarpConfigPath == "" {
c.WarpConfigPath = filepath.Join(c.StateDir, "warp.json")
}
if c.HeartbeatInterval == 0 {
c.HeartbeatInterval = DefaultHeartbeatInterval
}