docs(bootstrap): pass tunables on the sudo line, not by export

The header said to export tunables before running, but its own
`curl ... | sudo bash` entrypoint resets the environment, so an
exported FELIS_INSTALL_MODE or FELIS_NANO_LISTEN never reached the
installer. The header now shows the two forms that do arrive: the
variable named on the sudo line, or export followed by sudo -E.

The nano summary's hint for a proxy on another machine now prints a
sudo line that can be pasted as is, instead of "re-run with
FELIS_NANO_LISTEN=...". Comment and log text only.
This commit is contained in:
flyemoji committed 2026-09-22 13:52:40 +09:00
1 parent 02c079c893
commit 0758b9c5d7
1 file changed
+8 -3
+8 -3
View File
@@ -26,7 +26,10 @@
# The script is idempotent: re-running it converges rather than duplicating, and # The script is idempotent: re-running it converges rather than duplicating, and
# generated secrets are persisted to /etc/felis/secrets.env so reruns reuse them. # generated secrets are persisted to /etc/felis/secrets.env so reruns reuse them.
# #
# Tunables (export before running to override the demo defaults): # Tunables override the demo defaults. sudo resets the environment, so a variable exported
# before `curl ... | sudo bash` never arrives. Name it on the sudo line, or keep it with -E:
# curl -fsSL <raw-url>/deploy/bootstrap.sh | sudo FELIS_INSTALL_MODE=nano FELIS_NANO_LISTEN=10.0.0.5:8081 bash
# export FELIS_INSTALL_MODE=nano; curl -fsSL <raw-url>/deploy/bootstrap.sh | sudo -E bash
# FELIS_INSTALL_MODE full|nano — skip the prompt (default: ask on a tty, else full; nano # FELIS_INSTALL_MODE full|nano — skip the prompt (default: ask on a tty, else full; nano
# instead on a host that runs felis-nano and no full install) # instead on a host that runs felis-nano and no full install)
# FELIS_NANO_LISTEN listen addr for `felis nano` (default: the address an installed # FELIS_NANO_LISTEN listen addr for `felis nano` (default: the address an installed
@@ -2460,8 +2463,10 @@ summary_nano() {
log " the full https://sessionserver.mojang.com/session/minecraft/hasJoined)" log " the full https://sessionserver.mojang.com/session/minecraft/hasJoined)"
if nano_listen_is_loopback; then if nano_listen_is_loopback; then
log "Bound to loopback: reachable from Velocity on THIS host, and from nowhere else." log "Bound to loopback: reachable from Velocity on THIS host, and from nowhere else."
log "Proxy on another machine? Re-run with FELIS_NANO_LISTEN=<private-ip>:${port} and" log "Proxy on another machine? Re-run with the address on the sudo line (sudo drops"
log "allow ${port}/tcp ONLY from that proxy — hasJoined takes no auth token, so an" log "exported variables):"
log " curl -fsSL <raw-url>/deploy/bootstrap.sh | sudo FELIS_NANO_LISTEN=<private-ip>:${port} bash"
log "and allow ${port}/tcp ONLY from that proxy — hasJoined takes no auth token, so an"
log "internet-facing one is a free auth relay burning your Mojang egress IP." log "internet-facing one is a free auth relay burning your Mojang egress IP."
else else
log "WARNING: bound to ${FELIS_NANO_LISTEN} — hasJoined takes no auth token, so restrict" log "WARNING: bound to ${FELIS_NANO_LISTEN} — hasJoined takes no auth token, so restrict"