Skip to content
AIex2204Public

About

Self-hosted web UI for Mihomo (Clash Meta) — rules, proxies, and proxy-groups, safely, without touching YAML by hand.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

4 Commits

Folders and files

Repository files navigation

MCPOr

A self-hosted web control panel for Mihomo (Clash Meta core) — manage the service, routing rules, proxy servers and proxy-groups from a browser, without hand-editing config.yaml or restarting the service yourself.

Not affiliated with the Mihomo/Clash Meta project.

MCPOr screenshot

Why not yacd / metacubexd?

Those are excellent dashboards for Mihomo's own Clash-compatible API, but that API is read/control-only - there's no way to add a rule or add a proxy server through it. MCPOr edits config.yaml directly instead (safely - see below), on top of everything the Clash API already gives you (live delay tests, connection stats, group switching).

Features

  • Service control: start/stop/restart Mihomo, run mihomo -t config validation, see live status.
  • Rule constructor: add/delete/reorder simple rules (domain, domain-suffix, domain-keyword, IP-CIDR, RULE-SET, ...) through a form - no YAML by hand.
  • Rule-provider management: point a rule at any external auto-updating domain list (ad-block lists, category lists, anything published in Clash's rule-providers format) - Mihomo refreshes it on its own schedule, no scripting needed on your end.
  • Proxy servers: add by pasting a share link (hysteria2://, trojan://, vpn:// for AmneziaWG in its classic WireGuard-config format), with a preview you must confirm before anything is written. Delete, force a delay test.
  • Proxy-groups: change type (select/url-test/fallback/ load-balance/relay) and parameters, manage membership and order, see live per-member connection stats.
  • Safe apply workflow: every change is backed up, written, validated with mihomo -t, and only then applied via a debounced service restart (batches rapid edits into one restart instead of hammering systemctl) with an automatic revert-on-timeout watchdog if the new config doesn't come up healthy.
  • English/Russian UI, light/dark theme.

Requirements

  • Linux with systemd, Mihomo already installed and running as a systemd service (tested against a root-owned /root/.config/mihomo install - see Configuration below if yours differs).
  • Python 3.11+.
  • Root (needed for systemctl and for writing Mihomo's config file).
  • Tested on Debian/Ubuntu. Other distros should work but python3-venv may have a different package name.

Quickstart

git clone https://github.com/<you>/mcpor /opt/mihomo-control
cd /opt/mihomo-control
sudo ./install.sh

The installer asks a handful of questions (Mihomo's config directory, binary path, service name, Clash API address, the port MCPOr itself should listen on, and - if you're putting it behind a reverse proxy - that proxy's IP), then sets up a venv, generates an admin password (printed once - save it, e.g. in a password manager), and registers/starts the mihomo-control systemd unit.

Open http://<host>:8097 (or whatever port you chose) and log in.

Read install.sh before running it as root - it's short and worth understanding, especially since it's about to manage your network's routing.

Configuration

Settings live in /opt/mihomo-control/.env (or wherever install.sh was pointed), read by app/settings.py. All are optional - defaults match a standard root-owned Mihomo install:

Variable Default Meaning
MCPOR_MIHOMO_CONFIG_DIR /root/.config/mihomo Directory containing config.yaml
MCPOR_MIHOMO_BINARY /usr/local/bin/mihomo Path to the mihomo binary (used for -t validation)
MCPOR_MIHOMO_SERVICE mihomo.service systemd unit name for Mihomo itself
MCPOR_CLASH_API_BASE http://127.0.0.1:9090 Mihomo's Clash-compatible API address
MCPOR_APP_DIR /opt/mihomo-control Where MCPOr's own files (venv, secrets) live
MCPOR_TRUSTED_PROXY_IPS (empty) Comma-separated IP(s) of a reverse proxy in front of MCPOr, if any - see Security below

To change a setting after install, edit the .env file and systemctl restart mihomo-control.

Security notes

  • Single admin password (bcrypt-hashed, never stored in plaintext), session cookie, exponential-backoff rate limiting on login attempts.
  • MCPOr is meant for a trusted network (your LAN) or behind your own authentication layer. If you expose it beyond your LAN (e.g. via a reverse proxy with TLS), also set MCPOR_TRUSTED_PROXY_IPS to that proxy's IP - otherwise the rate limiter can be trivially bypassed by spoofing X-Forwarded-For (which uvicorn itself will also blindly trust from that same address unless you additionally restrict it - install.sh handles this for you when you answer the reverse-proxy question).
  • MCPOr runs as root and rewrites live routing config - review changes before running an unattended upgrade, and keep an eye on the automatic config backups it creates (config.yaml.bak-<timestamp>, pruned to the most recent 30).
  • No telemetry, no calls to anything other than your own Mihomo instance and whatever rule-provider URLs you configure.

Updating

cd /opt/mihomo-control
git pull
sudo ./install.sh
systemctl restart mihomo-control

Updates are never automatic - you decide when to pull.

License

MIT - see LICENSE.

Reporting a security issue

See SECURITY.md - please don't open a public issue.

About

Self-hosted web UI for Mihomo (Clash Meta) — rules, proxies, and proxy-groups, safely, without touching YAML by hand.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages