From 6e79042ec8479b2338644e1dfc5271c30a57520c Mon Sep 17 00:00:00 2001 From: AB Date: Thu, 12 Feb 2026 01:08:46 +0200 Subject: [PATCH] Added RBAC mtproxy --- k8s/apps/mtproxy/daemonset.yaml | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/k8s/apps/mtproxy/daemonset.yaml b/k8s/apps/mtproxy/daemonset.yaml index e4c482a..f0202dd 100644 --- a/k8s/apps/mtproxy/daemonset.yaml +++ b/k8s/apps/mtproxy/daemonset.yaml @@ -44,11 +44,16 @@ spec: secretKeyRef: name: tgproxy-secret key: PORT + volumeMounts: + - name: data + mountPath: /data command: - /bin/bash - -c - | set -e + curl -s https://core.telegram.org/getProxySecret -o /data/proxy-secret + curl -s https://core.telegram.org/getProxyConfig -o /data/proxy-multi.conf NAMESPACE=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace) SERVER=$(kubectl get node "${NODE_NAME}" -o jsonpath='{.metadata.labels.mtproxy}') if [ -z "${SERVER}" ]; then @@ -78,17 +83,14 @@ spec: - /bin/sh - -c - >- - cat /etc/*release* && \ - # /usr/bin/curl -s https://core.telegram.org/getProxySecret -o proxy-secret && \ - # /usr/bin/curl -s https://core.telegram.org/getProxyConfig -o proxy-multi.conf && \ mtproto-proxy -u nobody -p 8888 -H $(PORT) -M 1 -S $(SECRET) - --aes-pwd proxy-secret - proxy-multi.conf + --aes-pwd /data/proxy-secret + /data/proxy-multi.conf env: - name: SECRET valueFrom: