66 lines
2.9 KiB
Markdown
66 lines
2.9 KiB
Markdown
# Clean Proxys — "Pleiades"
|
|
|
|
Residential + dedicated proxy store, no-KYC, Bitcoin checkout. SOCKS5 & HTTP.
|
|
`clean-proxys.thetempleofdoom.com` (Cloudflare fleet tunnel). Node CT 777 @ 10.30.20.178.
|
|
|
|
## What it is
|
|
A white-label proxy middleman. Customers (humans *and* AI agents) buy clean
|
|
residential/ISP/datacenter proxies with Bitcoin. The gateway authenticates each
|
|
user, geo-targets their egress through the IPRoyal upstream, and meters GB usage.
|
|
|
|
Three tiers:
|
|
1. **Residential rotating** — per-GB, any country/city on the fly.
|
|
2. **ISP Dedicated** — one clean residential-ISP IP (premium, $4/30d wholesale).
|
|
3. **Datacenter Dedicated** — one static DC IP (budget, $1.80/30d wholesale).
|
|
|
|
## Architecture
|
|
```
|
|
customer / agent
|
|
│ HTTPS
|
|
▼
|
|
CF tunnel → nginx → Flask storefront (gunicorn 127.0.0.1:5000, SQLite)
|
|
│ ├─ BTCPay webhook → activate on payment
|
|
│ ├─ /admin (revenue, users, orders, inventory)
|
|
│ └─ /api/v1/* (agent discovery + one-call purchase)
|
|
▼
|
|
gateway.py (SOCKS5 :1080 + HTTP CONNECT :8080) ← per-user auth → geo → IPRoyal
|
|
▼
|
|
IPRoyal upstream (geo.iproyal.com:12321 residential / dedicated IPs)
|
|
```
|
|
|
|
## Components
|
|
- `gateway.py` — asyncio SOCKS5 + HTTP CONNECT relay. Per-user scrypt auth,
|
|
geo/sticky rewrite, GB byte metering. No traffic-content logging.
|
|
- `app.py` — Flask storefront + admin + agent API + BTCPay webhook.
|
|
- `db.py` — SQLite schema + auth helpers (scrypt).
|
|
- `iproyal.py` — IPRoyal reseller API wrapper (balance/products/orders).
|
|
- `admin.py` — CLI (create-user, set-country, add-balance, list).
|
|
- `provision.py` — dedicated-IP provisioning poll (systemd `provision.timer`).
|
|
|
|
## Services (systemd)
|
|
`gateway.service`, `app.service`, `provision.timer` (5-min poll).
|
|
|
|
## Agent API
|
|
- `GET /llms.txt` — machine-readable service description
|
|
- `GET /api/v1/info`, `GET /api/v1/plans`
|
|
- `POST /api/v1/proxy` — one-call purchase → creds + BTCPay checkout URL
|
|
- `GET /api/v1/order/<id>` — payment status
|
|
- `GET /api/v1/dedicated/locations?product=3|9` — dedicated location catalog
|
|
|
|
## Key facts (IPRoyal)
|
|
- Residential: `geo.iproyal.com:12321`, geo suffix **on the password**
|
|
(`_country-US_city-NewYork_session-XXXXXXXX_lifetime-30m`).
|
|
- Dedicated: connect **directly to the IP** — `socks5://user:pass@IP:12324`,
|
|
`http://user:pass@IP:12323`. Order via `apid.iproyal.com/v1/reseller`
|
|
(`X-Access-Token`), poll `GET /orders/{id}` until `confirmed`, read
|
|
`proxy_data.proxies[0]` = {username, password, ip}.
|
|
|
|
## Deploy
|
|
```bash
|
|
cd ~/pleiades && tar czf /tmp/e.tar.gz . && scp /tmp/e.tar.gz root@10.30.20.85:/tmp/ \
|
|
&& ssh root@10.30.20.85 "pct push 777 /tmp/e.tar.gz /tmp/e.tar.gz && pct exec 777 -- \
|
|
bash -c 'cd /opt/pleiades && tar xzf /tmp/e.tar.gz && systemctl restart gateway app'"
|
|
```
|
|
|
|
`config.json` holds secrets (gitignored); see `config.example.json`.
|