Committing work deployed on 2026-09-17 that had been left uncommitted, so canonical intent stops disagreeing with the running host. The deployed /opt/docker/conf/searxng/searxng-settings.yml is byte-identical to the canonical file here, verified before this commit. Search requests and their DNS now exit via socks5h://10.0.50.65:1080 on esh-scale (CT 108), an application-level proxy rather than a host-wide exit node; no route or firewall changes. microsocks runs as nobody under searxng-egress.service, binds only 10.0.50.65:1080, and bypasses SOCKS auth for source 10.100.50.40 alone — every other source must supply a password regenerated at each start and never distributed. Verified active and enabled. There is deliberately no direct-NH3 fallback: an ESH outage must fail the search rather than silently revert egress. ⚠ THE CHANGE HAS NOT ACHIEVED ITS PURPOSE AS DEPLOYED. Two independent live queries, 2026-09-18, both report brave "Suspended: too many requests", duckduckgo "CAPTCHA" and startpage "Suspended: CAPTCHA", leaving google cse as the only answering engine. Moving egress off NH3's residential address is what this change did, and CAPTCHA avoidance was the stated reason searxng sits at NH3 at all. The README anticipated the risk in its Dependency note; it has materialised. Rollback procedure is in the README and the pre-change config is kept on the host as searxng-settings.yml.pre-esh-20260917. Measured egress also drifted from the value recorded at cutover: the README notes 154.50.58.126, the proxy now exits 128.177.138.182. Expected — the README pins no public IP and calls out WAN failover — but recorded here so the number in the doc is not mistaken for current. Also retargets seat-inventory.py's default host from the mesh address 100.64.0.7 to fv-ml1's LAN address 10.251.50.54, routed by the site gateway.
79 lines
2.9 KiB
YAML
79 lines
2.9 KiB
YAML
# SearXNG — PFI fleet meta-search. Deployed on nh3-docker (10.100.50.40:9996).
|
|
#
|
|
# ⚠ WHY NH3 AND NOT THE COLO. Measured 2026-09-03:
|
|
# ana-docker egress 38.120.12.42 (datacenter) -> DuckDuckGo + Startpage CAPTCHA
|
|
# nh3-docker egress 70.230.226.88 (residential) -> no CAPTCHA
|
|
# Since 2026-09-17, search requests exit via a restricted SOCKS5 listener on
|
|
# esh-scale (10.0.50.65:1080), per operator request. Hosting remains at NH3.
|
|
# No host default-route or mesh routing changes. See stacks/searxng/README.md.
|
|
|
|
use_default_settings:
|
|
engines:
|
|
remove:
|
|
# Onion engines: no Tor proxy is configured here, so they only ever
|
|
# contribute timeouts.
|
|
- ahmia
|
|
- torch
|
|
# ⚠ Removal keys must match the engine's REAL name, spaces and all.
|
|
# `karmasearch.videos` (dotted) did NOT match on the old instance and the
|
|
# engine kept appearing in unresponsive_engines despite being "removed".
|
|
# The name is "karmasearch videos".
|
|
- karmasearch
|
|
- karmasearch videos
|
|
|
|
general:
|
|
instance_name: "SearXNG"
|
|
instance_about_url: false
|
|
contact_url: false
|
|
debug: false
|
|
# Public metrics page off — smaller attack surface on an unauthenticated
|
|
# internal service.
|
|
enable_metrics: false
|
|
|
|
search:
|
|
safe_search: 0
|
|
autocomplete: ""
|
|
default_lang: "auto"
|
|
# `json` is what makes this usable as a tool rather than only a web page.
|
|
# Removing it breaks every non-browser consumer, including Claude sessions.
|
|
formats:
|
|
- html
|
|
- json
|
|
# 3s is too tight for slower engines; 8s covers them without hanging the UI.
|
|
request_timeout: 8.0
|
|
# Ban an engine only briefly when it raises suspended-time. The default 86400
|
|
# means one bad afternoon silences an engine for a day.
|
|
ban_time_on_fail: 60
|
|
max_ban_time_on_fail: 600
|
|
|
|
server:
|
|
# secret_key comes from SEARXNG_SECRET in the environment — never hardcode it
|
|
# here. Generated + vaulted at nh3-docker/searxng-secret.
|
|
bind_address: "0.0.0.0"
|
|
port: 8080
|
|
# Enable ONLY with a limiter.toml AND a proxy that forwards X-Real-IP;
|
|
# otherwise it logs "X-Forwarded-For nor X-Real-IP header is set!" forever.
|
|
limiter: false
|
|
public_instance: false
|
|
# ⚠ Kept in sync with BASE_URL in compose.yaml. The old instance still said
|
|
# `https://searxng.pfi.local/` here — a name retired on 2026-08-19 — while the
|
|
# environment said something else. The env wins, so nothing broke, and the
|
|
# file quietly lied to everyone who read it.
|
|
base_url: "http://10.100.50.40:9996/"
|
|
method: "GET"
|
|
compression: true
|
|
image_proxy: false
|
|
|
|
# Outgoing pool — low-traffic private instance.
|
|
outgoing:
|
|
request_timeout: 6.0
|
|
max_request_timeout: 12.0
|
|
pool_connections: 100
|
|
pool_maxsize: 20
|
|
enable_http2: true
|
|
# ESH-only search egress; resolve engine hostnames at the proxy.
|
|
# No direct fallback: an ESH outage must not silently switch back to NH3.
|
|
proxies:
|
|
all://:
|
|
- socks5h://10.0.50.65:1080
|