Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

conf2proxy v4.1

conf2proxy converts a V2Ray-compatible client config or share link into a local SOCKS5/HTTP proxy container.

This version makes build-time and runtime values explicit in .env.

Where TARGETARCH and TARGETVARIANT are set

TARGETARCH and TARGETVARIANT are Docker build args, not container runtime environment variables. They are used only while building the image to choose the correct V2Ray binary.

They are now defined in .env and passed through compose.yaml:

build:
args:
V2RAY_VERSION: "${V2RAY_VERSION:-5.49.0}"TARGETARCH: "${TARGETARCH:-amd64}"TARGETVARIANT: "${TARGETVARIANT:-}"

Default .env values:

TARGETARCH=amd64TARGETVARIANT=

For ARM64:

TARGETARCH=arm64TARGETVARIANT=

For ARMv7:

TARGETARCH=armTARGETVARIANT=v7

Local proxy mode

Choose what this container exposes locally by changing .env:

LOCAL_PROXY_PROTOCOL=socks5PROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=httpPROXY_PORT=1080

or:

LOCAL_PROXY_PROTOCOL=bothSOCKS_PORT=1080HTTP_PORT=1081

Containerized V2Ray-compatible config-to-proxy gateway. It accepts either a native config.json, a single V2Ray-compatible share link, an environment variable link, or a base64 subscription file. It then exposes a local proxy listener selected by environment variable.

What changed in v4

  • Removed upstream input support for socks://, socks5://, http://, and https:// links.
  • Local exposed proxy is now selected with LOCAL_PROXY_PROTOCOL in compose.yaml.
  • Default local listener is SOCKS5 on 127.0.0.1:1080.
  • HTTP proxy mode can use the same exposed port, so you do not need two ports unless you choose both.

Supported generated link inputs

  • vmess://
  • vless:// with security=tls or security=none
  • trojan:// with security=tls or security=none
  • ss:// Shadowsocks SIP002 and legacy base64 body

Not supported in this V2Ray-only image

  • socks://, socks5://, http://, https:// as upstream input links.
  • vless://...security=reality... and most flow=xtls-rprx-vision configs: these are Xray-side patterns.
  • hy2://, hysteria2://, tuic://, wireguard://: these are not V2Ray-core outbound share links.
  • ssr://: ShadowsocksR is not normal Shadowsocks SIP002.

Use a native config with the correct core if you need these protocols.

File layout

.
├── compose.yaml
├── Dockerfile
├── docker-entrypoint.sh
├── link2config.py
├── v2ray/
└── link.txt

Run with SOCKS5 local proxy

This is the default mode.

LOCAL_PROXY_PROTOCOL: "socks5"PROXY_PORT: "1080"

Start:

nano v2ray/link.txt
docker compose up -d --build

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

Run with HTTP local proxy

Change only this in compose.yaml:

environment:
LOCAL_PROXY_PROTOCOL: "http"PROXY_PORT: "1080"

Keep the same port mapping:

ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

Start and test:

docker compose up -d --build
curl -x http://127.0.0.1:1080 https://ifconfig.me

Run with both SOCKS5 and HTTP local proxies

Use this only if you really need both protocols at the same time.

environment:
LOCAL_PROXY_PROTOCOL: "both"SOCKS_PORT: "1080"HTTP_PORT: "1081"ports:
- "127.0.0.1:${HOST_PROXY_PORT:-1080}:${SOCKS_PORT:-1080}/tcp"
- "127.0.0.1:${HOST_HTTP_PORT:-1081}:${HTTP_PORT:-1081}/tcp"

Test:

curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
curl -x http://127.0.0.1:1081 https://ifconfig.me

Run with native config.json

Place your complete V2Ray client config at:

v2ray/config.json

Then start:

docker compose up -d --build

When native config.json exists and is non-empty, it takes priority over link.txt.

Run with environment variable

V2RAY_LINK='vless://...' docker compose up -d --build

V2RAY_LINK has the highest priority.

Optional authentication

For LAN/public exposure, enable authentication first:

environment:
PROXY_AUTH: "password"PROXY_USER: "proxyuser"PROXY_PASS: "change-me"ports:
- "0.0.0.0:${HOST_PROXY_PORT:-1080}:${PROXY_PORT:-1080}/tcp"

For SOCKS5:

curl --socks5-hostname proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

For HTTP:

curl -x http://proxyuser:change-me@127.0.0.1:1080 https://ifconfig.me

Important environment variables

VariableDefaultDescription
LOCAL_PROXY_PROTOCOLsocks5Local exposed protocol: socks5, http, or both
PROXY_PORT1080Main local inbound port for socks5 or http mode
SOCKS_PORT1080SOCKS5 port when LOCAL_PROXY_PROTOCOL=both
HTTP_PORT1081HTTP proxy port when LOCAL_PROXY_PROTOCOL=both
PROXY_AUTHnoauthSet to password to enable inbound auth
PROXY_USERemptyInbound auth username
PROXY_PASSemptyInbound auth password
ENABLE_SOCKS_UDPtrueEnable UDP on SOCKS inbound
ENABLE_SNIFFINGtrueEnable V2Ray sniffing for HTTP/TLS/QUIC destination override
ROUTE_PRIVATE_DIRECTtrueRoute private IP/domain ranges directly
LOGLEVELwarningV2Ray log level
ENABLE_MUXfalseEnable V2Ray mux on generated proxy outbound
V2RAY_LINKemptyDirect link input without mounting a file

Production notes

The container runs as non-root, drops Linux capabilities, uses no-new-privileges, mounts /etc/v2ray read-only, and uses tmpfs for generated runtime config.

Keep the host binding as 127.0.0.1 unless this proxy is intentionally shared. If you expose it on LAN or public network, enable PROXY_AUTH=password and use a strong password.

Validate parser locally

python3 -m py_compile link2config.py
python3 link2config.py v2ray/link.txt /tmp/active-config.json
python3 -m json.tool /tmp/active-config.json >/dev/null

If you have pytest installed:

pytest -q

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages