# Stream SNI additions (Native mTLS tunnel · V5) Two SNI routes must be **merged into the existing** `stream { map $ssl_preread_server_name … }` block on the VPS (`/etc/nginx/stream-relay.conf`). They add the frp control channel and the `*.terminal` data path to the single shared `:443` `ssl_preread` listener. > **This is a MERGE, not a file to ship.** Do **not** drop a full stream conf here — that would > clobber the live one. Only the two `map` body lines below are new. ## The two additive lines Add these **inside the existing `map` body** (exact match wins over wildcard, so order is not load-bearing, but keep the exact `frp.terminal` line above the `*.terminal` wildcard for clarity): ```nginx frp.terminal.yaojia.wang 127.0.0.1:7000; # frps control channel (TLS passthrough) *.terminal.yaojia.wang 127.0.0.1:8470; # nginx :8470 TLS-term + device-CA mTLS (frp-mtls.conf) ``` ### Later addition — expired-leaf recovery (recover-mtls.conf) ```nginx recover.terminal.yaojia.wang 127.0.0.1:8472; # expired-leaf re-issue (recover-mtls.conf) ``` **Order IS load-bearing for this one**: it must sit ABOVE the `*.terminal.yaojia.wang` wildcard, the same way `enroll.terminal.yaojia.wang` does. `hostnames` gives exact matches priority over wildcards in nginx's `map`, so a correctly-placed line wins regardless — but keep the exact-match lines grouped above the wildcard so a future editor cannot mis-read the intent. No DNS work is needed: the zone is already served by the wildcard record `*.terminal.yaojia.wang → `. ## Coexistence warning (do NOT retype the existing lines) The existing `map` body already contains — and MUST be preserved **verbatim**: ```nginx # ... existing hostnames directive ... *.term.yaojia.wang 127.0.0.1:8443; # E2E browser relay — DO NOT RETYPE / REORDER default 127.0.0.1:10443; # xray Reality — DO NOT RETYPE / REORDER ``` - `*.term.yaojia.wang` (browser relay) and `*.terminal.yaojia.wang` (this tunnel) are **different parent labels** — `term` vs `terminal`. `ssl_preread` matches the full SNI, so they never collide. - Re-type nothing you did not author. Capture the current body first (`nginx -T | sed -n '/map \$ssl_preread_server_name/,/}/p'`), then append only the two lines above. ## Deploy gate ```bash cp /etc/nginx/stream-relay.conf{,.bak.$(date +%s)} # snapshot first # ...edit: append the two lines into the map body... nginx -t && systemctl reload nginx # NEVER reload on a failed -t ``` After reload, run the 4-zone SNI oracle (`openssl s_client -servername …` for `frp.terminal` / `.terminal` / `.term` / default) to confirm all four routes still resolve to the right backend (PLAN V5 / M1 #7).