Skip to content

sing-box — 配置结构 ​

sing-box 启动时读取单个 JSON 文档。根对象映射到 option/options.go:14 中的 Go 结构体 _Options(通过类型别名导出为 Options,其 UnmarshalJSONContext 启用了严格的未知字段检查 —— 配置中的拼写错误会直接导致启动失败,而不是被静默忽略)。

根字段 ​

键Go 字段类型页面描述
$schemaSchemastring(无)供编辑器补全 / 校验的 JSON Schema URI;对运行时无影响。sing-box schema 可生成与当前构建匹配的 schema。
logLog*LogOptions日志严重级别、输出、时间戳、禁用开关。
dnsDNS*DNSOptionsDNSDNS 服务器、规则、hosts、fakeip。
ntpNTP*NTPOptionsNTP可选的内嵌 NTP 客户端。
certificateCertificate*CertificateOptions证书TLS 校验使用的根 CA 来源。
certificate_providersCertificateProviders[]CertificateProviderTLS可复用的证书提供方(acme、tailscale、cloudflare-origin-ca),由入站 TLS 的 certificate_provider 按 tag 引用。
http_clientsHTTPClients[]HTTPClient(无)可复用的 HTTP 客户端(引擎、版本、拨号、TLS、HTTP/2 / QUIC 参数),供远程规则集、证书提供方与 DERP verify_client_url 使用。
network_namespacesNetworkNamespaces[]NetworkNamespaceTUNLinux 网络命名空间(default、unshare),由 TUN、监听与拨号字段中的 netns 按 tag 引用。
endpointsEndpoints[]Endpoint端点端点形式的入站 / 出站(WireGuard、Tailscale、OpenVPN 客户端 / 服务端与 OpenConnect)。
inboundsInbounds[]Inbound入站监听服务列表。
outboundsOutbounds[]Outbound出站上游目标列表。
routeRoute*RouteOptions路由路由规则、rule-set、默认出站。
servicesServices[]Service服务后台服务(resolved、derp、ssm-api、api、hysteria-realm、usbip-server / usbip-client)。
experimentalExperimental*ExperimentalOptions实验性缓存文件、Clash API、V2Ray API、pprof 调试。

每个 DNS 服务器都需声明 type;不支持无类型的 "address": "tls://…" 格式(参见 DNS)。

一览 ​

json
{
  "log": { "level": "info", "timestamp": true },
  "dns": { "servers": [{ "type": "tls", "tag": "google", "server": "8.8.8.8" }] },
  "ntp": { "enabled": true, "server": "time.cloudflare.com" },
  "certificate": { "store": "system" },
  "inbounds": [],
  "outbounds": [],
  "route": { "final": "direct" },
  "experimental": {
    "cache_file": { "enabled": true },
    "clash_api": { "external_controller": "127.0.0.1:9090" }
  }
}

源码: option/options.go:14-31 · v1.14.2 (af6e64c)

由 Argsment 出品的 Core Tutorial