Skip to main content

HexRift

Python Build Coverage License uv Ruff

Config generator for the Conglomerate distributed proxy network. Takes a topology definition and produces Xray JSON configs and HAProxy configs for every node. Hub nodes additionally support WireGuard and XDNS inbounds.

[!WARNING] HexRift is in active development. Until the v1.0.0 release, the CLI, topology schema, and generated config output may change at any time — breaking changes can land in any release, including patch versions. Pin an exact version (e.g. hexrift==0.8.0) and check the release notes before upgrading.

Installation

uv sync

Usage

All commands require a topology YAML file:

hexrift --yaml conglomerate.yaml <command>

Commands

Command Description
validate Validate the topology YAML against the schema
show Visualize the network topology (regions, nodes, users, guests, portals)
derive [users|groups|portals|nodes|all] Show derived identifiers (UUIDs, shortIds, emails)
nodes [--names|--domains] [--type exit|hub] List nodes with hostnames; machine-friendly output for automation
gen-keys [NODE_ID|--all] [--force] [--keys-dir PATH] Generate x25519 + ML-KEM 768 keypairs for nodes
build [NODE_ID|--all] --xray|--haproxy [--keys-dir PATH] [--out-dir PATH] Build Xray config.json and/or HAProxy .cfg
gen-portal [PORTAL_ID|--all] [--group ID] [--fp FINGERPRINT] [--out-dir PATH] [--keys-dir PATH] Build Xray bridge config.json for portal(s) from the top-level portals: section
diff NODE_ID [--current-dir PATH] [--keys-dir PATH] Diff generated config against deployed config
share USERNAME [--hub NODE_ID] [--fp FINGERPRINT] [--cdn] [--wg] [--server] [--guest LABEL] [--all-guests] [--bare] [--keys-dir PATH] Generate VLESS share URLs or WireGuard client configs (--wg)

Examples

# Validate topology
hexrift validate

# Visualize topology
hexrift show

# Show all derived identifiers
hexrift derive all

# List all exit node IDs (for scripts)
hexrift nodes --names --type exit

# Generate keys for all nodes
hexrift gen-keys --all

# Build Xray config for a specific node
hexrift build nlA00 --xray --out-dir ./out

# Build all configs (Xray + HAProxy)
hexrift build --all --xray --haproxy --out-dir ./out

# Diff against deployed config
hexrift diff nlA00 --current-dir /etc/xray

# Generate a share link (CDN URL)
hexrift share alice --cdn

# Generate share links for all guests of a user
hexrift share alice --all-guests --bare | clip

# Generate a WireGuard client config
hexrift share alice --wg

Topology options

Beyond the basic hub/exit split:

  • HAProxy-less nodes - by default every node runs HAProxy on :443 in front of Xray. Set haproxy: false to drop HAProxy and have Xray's Reality inbound bind 0.0.0.0:443 (or [::]:443 when ipv6 is supported) directly. build --haproxy then emits a no-op stub haproxy.cfg so managed HAProxy service stays up without touching :443. CDN (cdn_xhttp_path) needs HAProxy TLS termination and cannot be combined with haproxy: false.
  • All-in-one node - set routing.hub_default: direct to make a hub egress everything itself (direct outbound) instead of routing to exit region. This allows topology with hub node(s) and no exit regions - single node clients connect to that proxies straight to the internet. hub_routes still apply for per-domain/user exceptions.

Architecture

hexrift/
  components/
    schema/     # Pydantic models for yaml
    derive/     # Identity derivation (UUIDs, shortIds, emails), defaults resolution,
                # topology->Xray-fragment construction, and WireGuard derivation/configs
    keys/       # x25519 + ML-KEM 768 keypair generation and storage
    render/     # Xray config builder + HAProxy Jinja2 templates
  core/         # BaseApplication / Component / Controller framework
  shared/       # Cross-component helpers (crypto encoding, Xray/xhttp constants)
  templates/    # Jinja2 stubs
    haproxy/
    wireguard/

Derivation

All identifiers are deterministically derived from the topology:

  • NAMESPACE UUID = UUID5(UUID(0), namespace)
  • User UUID = UUID5(NAMESPACE_UUID, username)
  • Server UUID = UUID5(USER_UUID, {username}-server)
  • Portal UUID = UUID5(NAMESPACE_UUID, portal/{id})
  • Guest UUID = UUID5(USER_UUID, {label})
  • Hub-exit UUID = UUID5(NAMESPACE_UUID, {hubId}-{exitId})
  • Warp UUID = Hub-exit UUID with 3rd segment replaced by ffff
  • Group shortId = SHA256{groupId}.{namespace}
  • Hub shortId = SHA256{nodeId}.hub.{namespace}
  • Exit shortId = SHA256{nodeId}.exit.{namespace}
  • WireGuard keypair = x25519(HMAC-SHA256(reality_private_key, {identity_uuid}.wireguard.{namespace}))

Keys

Keypairs are stored in keys/{nodeId}.yaml. Hub nodes in the same region share the same keypair. Key strings follow the format:

  • Decryption (server inbound): {method}.{mode}.{session_time}[.{padding}].{PRIVATE_KEY_b64}
  • Encryption (client outbound): {method}.{mode}.0rtt.{PUBLIC_KEY_b64}

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hexrift-0.11.1.tar.gz (179.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

hexrift-0.11.1-py3-none-any.whl (75.8 kB view details)

Uploaded Python 3

File details

Details for the file hexrift-0.11.1.tar.gz.

File metadata

  • Download URL: hexrift-0.11.1.tar.gz
  • Upload date:
  • Size: 179.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for hexrift-0.11.1.tar.gz
Algorithm Hash digest
SHA256 18722faa19d4819534fb5f613719856e83eacc9b18e0dfe17225b651c258c91b
MD5 b50f98ee41de4234569532a4bfad9a78
BLAKE2b-256 c189598b1f977ba23c6c97b6f5747937940c1ad950300338c63c1835ad8e056e

See more details on using hashes here.

File details

Details for the file hexrift-0.11.1-py3-none-any.whl.

File metadata

  • Download URL: hexrift-0.11.1-py3-none-any.whl
  • Upload date:
  • Size: 75.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for hexrift-0.11.1-py3-none-any.whl
Algorithm Hash digest
SHA256 215295cf40dcef60b75ebe66e6bb2c7609160a4b65e59c6e3389cdb97a98a06b
MD5 8d71b61380f33119e62122baab162df3
BLAKE2b-256 b466b2b92d28630dbe9e27b4abc4ae0d01285d9db5b9dff3ef154a5c005f97ff

See more details on using hashes here.

Release history Release notifications | RSS feed

0.12.3

2 files

0.12.2

2 files

0.12.1

2 files

0.12.0

2 files

0.11.2

2 files

This release

0.11.1 This release

2 files

0.11.0

2 files

0.10.2

2 files

0.10.1

2 files

0.10.0

2 files

0.9.1

2 files

0.9.0

2 files

0.8.0

2 files

0.7.1

2 files

0.7.0

2 files

0.6.0

2 files

0.5.2

2 files

0.5.1

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

0.2.1

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page