# Deliberate re-domain. Allowed -- there is no other route to it -- but it is not a
# thing this script finishes: the panel certificate, the two secrets, the velocity
# config and the login CR all still carry the old name.
warn "FELIS_ROOT_DOMAIN (${FELIS_ROOT_DOMAIN}) differs from the installed ${persisted}."
warn "This re-domains the install. The write-once panel certificate is NOT reissued and"
warn "will keep the old hostnames; the proxy and login config need the same treatment."
die "FELIS_ROOT_DOMAIN (${FELIS_ROOT_DOMAIN}) differs from the installed ${persisted}. The installer keeps the installed domain; to move the install, rerun it without FELIS_ROOT_DOMAIN, then run: sudo felis domain set ${FELIS_ROOT_DOMAIN} (docs/operations.md, Changing the root domain)"
# Third-party Yggdrasil sources federated by the hasJoined multiplexer. Mojang is
@@ -4092,8 +4153,8 @@ summary() {
echo
systemctl --no-pager--full status felis-velocity 2>/dev/null | head-n 4 ||true
echo
log "Player panel: https://console.${FELIS_ROOT_DOMAIN} — served on 443 once your edge/Cloudflare Tunnel routes it here."
log "Operator console (Op/Admin/Owner): https://op.console.${FELIS_ROOT_DOMAIN} — the Owner runs 'felis setup' and onboards here."
log "Player panel: https://$(auth_hostname panel_hostname "console.${FELIS_ROOT_DOMAIN}") — served on 443 once your edge/Cloudflare Tunnel routes it here."
log "Operator console (Op/Admin/Owner): https://$(auth_hostname admin_hostname "op.console.${FELIS_ROOT_DOMAIN}") — the Owner runs 'felis setup' and onboards here."
log "Before the edge is ready: direct + self-signed at https://${NODE_IP}:${FELIS_PANEL_NODEPORT} (browser will warn on first visit)."