mirror of
https://gitverse.ru/kpa39l/infrastructure.git
synced 2026-09-29 18:15:02 +00:00
34 lines
1.1 KiB
Markdown
34 lines
1.1 KiB
Markdown
# tunnel-proxy Specification
|
|
|
|
## Purpose
|
|
TBD - created by archiving change add-vpn-tunnel-proxy. Update Purpose after archive.
|
|
|
|
## Requirements
|
|
|
|
### Requirement: Persistent SOCKS5 Tunnel
|
|
The system MUST maintain a persistent SOCKS5 proxy tunnel from the host to VPS01, listening on 127.0.0.1:1080.
|
|
|
|
#### Scenario: Tunnel starts on boot
|
|
- GIVEN the host boots
|
|
- WHEN systemd starts telegram-tunnel.service
|
|
- THEN the tunnel listens on 127.0.0.1:1080
|
|
- AND the SSH connection is established with key /mnt/yandex-disk/.ssh_box/timewebVPS
|
|
|
|
#### Scenario: Tunnel dies
|
|
- GIVEN the tunnel process exits unexpectedly
|
|
- WHEN systemd detects failure
|
|
- THEN the service restarts automatically (Restart=always)
|
|
|
|
### Requirement: Tunnel Health Monitoring
|
|
The system MUST verify tunnel liveness at least every 60 seconds.
|
|
|
|
#### Scenario: Health check passes
|
|
- GIVEN the tunnel is running
|
|
- WHEN checking connectivity through 127.0.0.1:1080
|
|
- THEN curl through the proxy returns HTTP 200 for a known endpoint
|
|
|
|
#### Scenario: Health check fails
|
|
- GIVEN the tunnel is down
|
|
- WHEN the watchdog fires
|
|
- THEN a notification is raised (no routine "all ok" messages)
|