Rigel SOCKS5 proxy shop v1 — no-KYC auth, BTCPay, Nord+IPRoyal inventory

This commit is contained in:
drjones
2026-09-09 19:42:35 -07:00
commit 90f7414172
2 changed files with 410 additions and 0 deletions

38
README.md Normal file
View File

@@ -0,0 +1,38 @@
# Rigel — no-KYC SOCKS5 Proxy Shop
Self-hosted SOCKS5 proxy storefront. Sells access to residential/mobile/datacenter proxies. Bitcoin via BTCPay. No KYC — username + email + password + arithmetic captcha.
## Stack
- **App**: Flask single-page app, `/opt/rigel/app.py` (SQLite, no-KYC auth)
- **CT**: 158 `rigel` @ `10.30.20.116`, Debian 12, nginx :80 → Flask :5000
- **Service**: `rigel.service` (systemd)
- **Payments**: BTCPay store `[redacted]` / key `[redacted]` (webhook → `/api/btcpay/webhook`)
- **Public**: `https://rigel.thetempleofdoom.com` (fleet tunnel `1aeb1ac0`, REMOTE-MANAGED config via CF API)
## Inventory
| Location | Type | Endpoint |
|---|---|---|
| Tokyo | datacenter (Nord exit) | CT680 `10.30.20.154:1080` |
| London | datacenter (Nord exit) | CT681 `10.30.20.71:1080` |
| Sydney | datacenter (Nord exit) | CT682 `10.30.20.189:1080` |
| Residential | rotating/sticky | IPRoyal `geo.iproyal.com:12321` |
| Mobile 4G | rotating | IPRoyal `4g.iproyal.com` |
## API
- `POST /api/register` — `{username, email, password, captcha_id, captcha}`
- `POST /api/login` — `{username, password}`
- `GET /api/captcha` — arithmetic challenge
- `POST /api/buy` — `{plan_id}` → creates BTCPay invoice + pending subscription
- `GET /api/subscriptions` — user's active proxies
- `POST /api/btcpay/webhook` — activates subscription + issues creds on payment
## Deploy
```
tar czf rigel.tar.gz app.py
scp rigel.tar.gz root@10.30.20.85:/tmp/
ssh root@10.30.20.85 "pct push 158 /tmp/rigel.tar.gz /tmp/rigel.tar.gz && pct exec 158 -- bash -c 'cd /opt/rigel && tar xzf /tmp/rigel.tar.gz && systemctl restart rigel'"
```
## Gotchas
- Fleet tunnel is REMOTE-MANAGED — edit ingress via CF API (`/accounts/<id>/cfd_tunnel/1aeb1ac0.../configurations`), NOT the local `config-fleet.yml`. Local edits are ignored.
- BTCPay webhook secret wired via `BTCPAY_WEBHOOK_SECRET` env in `rigel.service`.