Incus 运行 OpenWrt

容器 #

创建 profile #

$ incus profile create openwrt
$ incus profile edit openwrt
config:
  boot.autorestart: "false"
  boot.autostart: "true"
devices:
  eth0:
    name: eth0
    network: incusbr-1000
    type: nic
  root:
    path: /
    pool: default
    type: disk

配置 #

初始化容器:

$ incus init images:openwrt/25.12 my-openwrt -p openwrt

静态 IP:

$ incus config device override my-openwrt eth0 ipv4.address=192.168.20.120

OpenWrt 配置(单 lan 口):

$ incus start my-openwrt
$ incus exec my-openwrt -- ash

[先修改密码]
# passwd root

[关闭 ntp 并设置国内时区]
# /etc/init.d/sysntpd disable
# uci set system.ntp.enabled='0'
# uci set system.@system[0].zonename='Asia/Shanghai'
# uci set system.@system[0].timezone='CST-8'
# uci commit system

[查看:eth0 默认分配给了 wan]
# uci show network.wan
network.wan=interface
network.wan.device='eth0'
network.wan.proto='dhcp'

[查看:wan 区域的入站流量是被拒绝的,此时无法打开网页后台]
# uci show firewall | grep -e 'zone' | grep -E '\.name|\.input'
firewall.@zone[0].name='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[1].name='wan'
firewall.@zone[1].input='REJECT'

[删除 wan]
# uci delete network.wan
# uci delete network.wan6

[添加 lan,设置 dhcp 从上游获取 ip,即从 incus 网桥提供的 DHCP 服务获取地址]
# uci set network.lan=interface
# uci set network.lan.proto='dhcp'
# uci set network.lan.device='eth0'
# uci commit network

[忽略 lan 口的 DHCP 服务,即不在 lan 口提供 DHCP 服务,避免和 incus 的 DHCP 服务冲突]
# uci set dhcp.lan.ignore='1'
# uci commit dhcp

[替换清华源并更新]
# sed -i 's_https\?://downloads.openwrt.org_https://mirrors.tuna.tsinghua.edu.cn/openwrt_' /etc/apk/repositories.d/distfeeds.list
# apk update
# apk upgrade
# reboot

重启后,就能进入网页后台了。

OpenClash #

插件 #

OpenClash 插件:https://github.com/vernesong/OpenClash/releases/latest

$ incus file push luci-app-openclash-0.47.156.apk my-openwrt/root
$ incus exec my-openwrt -- ash
# apk add --allow-untrusted ./luci-app-openclash-0.47.156.apk
# reboot

内核 #

mihomo 内核:https://github.com/MetaCubeX/mihomo/releases/latest

查看 CPU 信息:

$ grep -m1 'flags' /proc/cpuinfo | grep -o 'avx2\|sse4_2'

如果输出包含 avx2,说明可以用 v3;如果只有 sse4_2,可以用 v2;如果都没有,请使用 v1。

$ incus file push mihomo-linux-amd64-v3-v1.19.32.gz my-openwrt/root
$ incus exec my-openwrt -- ash
# gzip -d mihomo-linux-amd64-v3-v1.19.32.gz
# mv mihomo-linux-amd64-v3-v1.19.32 /etc/openclash/core/clash_meta
# chmod +x /etc/openclash/core/clash_meta

设置 #

订阅链接 #

  1. 在首页 Overviews -> 点击 Config File 选项卡的 + 号 -> 选择 Subscripti Link。
  2. Config Subscribe -> 勾选 Auto Update -> Commit Settings。

运行模式 #

在首页 Overviews -> 在 Running Mode 选项卡 -> 选择 Mix。

取消 SOCKS5/HTTP(S) 的认证 #

Overwrite Settings -> General Settings -> Set Authentication of SOCKS5/HTTP(S) -> 取消勾选 -> Apply Settings。

http 代理 #

宿主机测试:

$ proxy='http://192.168.20.120:7890'
$ http_proxy=$proxy https_proxy=$proxy bash
$ curl www.google.com

虚拟机 #

创建 profile #

$ incus profile create openwrtvm
$ incus profile edit openwrtvm
config:
  limits.cpu: "4"
  limits.memory: 1GiB
  boot.autostart: "true"
  boot.autorestart: "false"
  security.secureboot: "false"
devices:
  root:
      path: /
      pool: default
      type: disk
      size: 10GiB
  eth0:
      name: eth0
      network: incusbr-1000
      type: nic

其余设置和容器一样。