Skip to content
Usage

Overrides

Your own options over the subscription — the merge order, what Exodus sets itself, the mixin file and examples.

A subscription is downloaded again on every update, so edits in its file are lost. Your own options go over the profile: Exodus applies them on every start and on every update of the subscription.

The profile for startup is built from three layers, each next one wins over the previous:

  1. Profile — a subscription or an uploaded file.
  2. Mixin file — your Mihomo options.
  3. Exodus settings — the Settings page on Keenetic and Asus, Advanced → Mixin Option in LuCI on OpenWrt. An empty option keeps the value of the profile.

Then Exodus adds what the interception can not work without, see what Exodus sets itself. The result is the profile for startup run/config.yaml. It can be viewed on the Editor page, it is read only and rewritten on every start.

How the layers are merged:

  • Maps by keys. dns: { nameserver: [...] } in the mixin file changes only the servers, the other dns options of the profile are kept.
  • Lists and values as a whole. rules, proxies or proxy-groups in the mixin file replace all rules, proxies or groups of the profile. To add your own to the profile, use the nikki-* keys.
  • Comments are removed, YAML anchors (&, *, <<) are expanded.

The interception rules and the web UI do not work without these options, so the mixin file does not change them:

OptionValue
redir-port, tproxy-port7891, 7892
dns.enable, dns.listentrue, [::]:1053
allow-lantrue
external-controller[::]:9090, the port is API port
external-uiui
profile.store-selected, profile.store-fake-iptrue

From the Settings page, only when the option is filled in:

OptionFrom
log-levelLog level
interface-nameOutbound interface
mixed-portProxy port; when it is neither in the settings nor in the profile — 7890
authenticationAuthentication: on — the username and password of the settings, off — no authentication, even when the profile has it
external-ui-urlPanel
secretAPI secret
routing-mark255 when Traffic of the router is on

When the interception is on (Settings → Enable), after the merge:

  • TUN is turned off: tun.enable: false, listeners with type: tun are removed. TUN would change the routes of the router.
  • For the mark of the chosen proxy the listeners exodus-force-redir and exodus-force-tproxy are added.
  • The names of the router itself are added to dns.fake-ip-filter when fake-ip-filter-mode is blacklist (the default): my.keenetic.net, the KeenDNS and Netcraze domains on Keenetic; router.asus.com, www.asusrouter.com, www.asusnetwork.net, +.asuscomm.com and the local domain on Asus.
  • Asus only: the names of the web interface go to hosts with the LAN address of the router, the local domain goes to dns.nameserver-policy with the DNS of the router. Values of the profile and the mixin file for these names win.

The mode (mode), ipv6 and the DNS mode (dns.enhanced-mode) are not set by Exodus: they come from the profile and can be changed in the mixin file.

Any Mihomo options over the profile. It is edited on the Editor page: /opt/etc/exodus/mixin.yaml on Keenetic and Asus, /etc/nikki/mixin.yaml on OpenWrt.

  • Keenetic and Asus: always applied. While the file holds only comments, it changes nothing.
  • OpenWrt: applied only when Advanced → Mixin Option → Mixin File Content is enabled.

Changes apply on the next start — Save & Restart in the editor. When the profile can not be built with the mixin file (for example, because of a YAML error), on Keenetic and Asus the service does not start and the Exodus log says Mixin failed, check the mixin file and the profile. On an update of the subscription on the fly the core then keeps the running profile.

The nikki-proxies, nikki-proxy-groups and nikki-rules keys add proxies, groups and rules to the beginning of the lists of the profile, without replacing them:

nikki-proxies:
- name: PROXY
type: ss
server: proxy.example.com
port: 443
cipher: chacha20-ietf-poly1305
password: password
nikki-proxy-groups:
- name: PROXY_GROUP
type: select
proxies:
- PROXY
nikki-rules:
- DOMAIN,direct.example.com,DIRECT
- DOMAIN-SUFFIX,proxy.example.com,PROXY_GROUP

A rule refers to a group or a proxy by its name: a group of the profile, DIRECT, REJECT or one added above.

All examples are for the mixin file. Option reference — the Mihomo documentation.

dns:
nameserver:
- https://1.1.1.1/dns-query
- https://dns.google/dns-query

The list replaces nameserver of the profile, the other dns options of the profile are kept. On OpenWrt with Overwrite Nameserver the servers from LuCI win.

dns:
fake-ip-filter:
- +.lan
- +.local
- +.msftconnecttest.com

The list replaces fake-ip-filter of the profile as a whole: copy the entries of the profile you want to keep. Exodus adds the names of the router itself.

hosts:
nas.home: 192.168.1.20
printer.home: 192.168.1.30

The entries are added to hosts of the profile, matching names are replaced.

sniffer:
enable: true
sniff:
HTTP:
ports: [80, 8080-8880]
override-destination: true
TLS:
ports: [443, 8443]
QUIC:
ports: [443, 8443]
skip-domain:
- +.push.apple.com
rule-providers:
my-direct:
type: http
behavior: domain
format: text
url: https://example.com/direct.txt
interval: 86400
nikki-rules:
- RULE-SET,my-direct,DIRECT

The provider is added to the providers of the profile, the rule with it goes to the beginning of the rules.

When the subscription brings its proxies through proxy-providers, the override key changes all proxies of the provider at once:

proxy-providers:
provider-name:
override:
udp: true
additional-prefix: '[Sub] '

provider-name is the name of the provider in the subscription, it is seen in the profile for startup on the Editor page. The other options of the provider are kept. Also useful: skip-cert-verify, dialer-proxy, interface-name, additional-suffix and proxy-name to rename by a pattern. When the subscription lists its proxies right in proxies, there is no provider and override is not needed.