# alexbers/mtprotoproxy config for the tekhnohim Telegram Fake-TLS MTProto proxy. # # The REAL config.py is host-only at /mnt/containers/tailscale-proxy/mtproto/config.py # (mode 0600, owned by uid 10000 = the container's `tgproxy` user, NOT in git), # because USERS holds the proxy secret. This file is the secret-free template. # # Egress: SOCKS5_HOST/SOCKS5_PORT point at the Tailscale userspace SOCKS5 # (ts-proxy:1055), so every Telegram-DC connection exits via the Hetzner exit # node (89.167.72.79). The client-facing side is Fake-TLS (looks like HTTPS to # TLS_DOMAIN), which survives TSPU where the retired raw SOCKS5 did not. PORT = 1080 # username -> 32-hex-char secret (16 bytes). Generate: openssl rand -hex 16 USERS = { "tekhnohim": "00000000000000000000000000000000", } # Fake-TLS only (best obfuscation). classic/secure are easier to fingerprint. MODES = { "classic": False, "secure": False, "tls": True, } # SNI presented in the Fake-TLS handshake. Must be a real, reachable HTTPS host. # Tunable if a given domain is filtered on the client path. TLS_DOMAIN = "www.google.com" # Upstream SOCKS5 = the Tailscale userspace proxy -> Hetzner exit node. SOCKS5_HOST = "ts-proxy" SOCKS5_PORT = 1055 SOCKS5_USER = None SOCKS5_PASS = None