Unverified Commit 2d04e0e6 authored by Lemon-miaow's avatar Lemon-miaow
Browse files

fix(rotate-token): 加确认步骤、velocity 热加载免踢人,补齐 registry/forwarding/db 轮换

parent d112a43c
Loading
Loading
Loading
Loading
+8 −2
Changes for cmd/felis/domain.go: 8 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -235,7 +235,7 @@ func verifyTOMLEdit(orig, edited []byte, edits []tomlStringEdit) error {
		t[e.key] = e.value
	}
	if !reflect.DeepEqual(want, got) {
		return errors.New("a line edit would change more than the domain keys (a multi-line value, or a quoted or dotted key?)")
		return errors.New("a line edit would change more than the keys it sets (a multi-line value, or a quoted or dotted key?)")
	}
	return nil
}
@@ -591,9 +591,15 @@ type tomlTarget struct{ path, real string }
// tomlTargets are the host and pod copies, and felis.toml when it is a file of
// its own rather than the link to the host copy.
func (h domainHost) tomlTargets() ([]tomlTarget, error) {
	return tomlTargetsOf(h.paths.hostTOML, h.paths.podTOML, h.paths.defaultTOML)
}

// tomlTargetsOf is the host copy, the pod copy, and def when it exists and is
// not a link to one of them.
func tomlTargetsOf(host, pod, def string) ([]tomlTarget, error) {
	var out []tomlTarget
	seen := map[string]bool{}
	for i, p := range []string{h.paths.hostTOML, h.paths.podTOML, h.paths.defaultTOML} {
	for i, p := range []string{host, pod, def} {
		real, err := filepath.EvalSymlinks(p)
		if errors.Is(err, fs.ErrNotExist) && i == 2 {
			continue
+597 −67

File changed.

Preview size limit exceeded, changes collapsed.

+650 −50

File changed.

Preview size limit exceeded, changes collapsed.

+1 −1
Changes for cmd/felis/run.go: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -31,7 +31,7 @@ Commands:
  apply             Create a MinecraftServer CRD (direct K8s write; use -f server.json)
  setup             Run host bootstrap + first-run setup console (TUI; requires root/sudo)
  converge          Fill in fields a newer desired spec added to already-installed system servers
  rotate-token      Replace one internal caller's token and restart what holds it (velocity|limbo|build|ops; requires root/sudo)
  rotate-token      Replace a generated credential and restart what reads it (velocity|limbo|build|ops|registry|forwarding|db; prints the plan, -yes applies; requires root/sudo)
  domain            Move the install to a new root domain on every surface that carries it, or check each one (set|check; requires root/sudo)
  watchdog          Check the platform once and mail the owners what has gone wrong (run by felis-watchdog.timer)
  version           Print the build stamp of this binary
+12 −5
Changes for deploy/bootstrap.sh: 12 added lines, 5 removed lines.
Original line number Diff line number Diff line
@@ -3859,13 +3859,20 @@ EOF
# velocity_fingerprint hashes what the proxy process runs: its unit (JVM flags and system
# properties), the JRE, the jars and the files the installer writes for it. The Via config
# and whatever else plugins write at runtime stay out; Via rewrites its config on every load.
# So does the service-token line of felis-link.properties: the plugin re-reads it on its own
# (`felis rotate-token velocity` counts on that), and a restart for it would only disconnect
# every player.
velocity_fingerprint() {
  local f
  local f sum
  for f in "$VELOCITY_SERVICE" "${JRE_DIR}/release" "${VELOCITY_DIR}/velocity.jar" \
      "${VELOCITY_DIR}/velocity.toml" "${VELOCITY_DIR}/forwarding.secret" \
      "${VELOCITY_DIR}/plugins/felis-link/felis-link.properties" "${VELOCITY_DIR}"/plugins/*.jar; do
    [ -f "$f" ] || continue
    printf '%s %s\n' "$(sha256sum <"$f" | cut -d' ' -f1)" "$f"
    case "$f" in
      */felis-link.properties) sum="$({ grep -v '^service-token=' "$f" || true; } | sha256sum | cut -d' ' -f1)" ;;
      *) sum="$(sha256sum <"$f" | cut -d' ' -f1)" ;;
    esac
    printf '%s %s\n' "$sum" "$f"
  done | sha256sum | cut -d' ' -f1
}

@@ -4187,12 +4194,13 @@ load_or_make_secrets() {
  # to its own routes and a leak is contained to that caller: SERVICE_TOKEN is the
  # proxy's (felis-link.properties), LIMBO_TOKEN the login gate's, BUILD_TOKEN what a
  # build Job fetches its context with, OPS_TOKEN what `felis backup-now` presents.
  # `felis rotate-token <caller>` rewrites the matching line here.
  # `felis rotate-token <caller>` replaces one of them, and `felis rotate-token
  # registry|forwarding|db` the other values persisted below: every line of secrets.env
  # has a rotation that rewrites it (cmd/felis TestInstallerSecretsAreAllRotatable).
  SERVICE_TOKEN="${SERVICE_TOKEN:-$(openssl rand -hex 32)}"
  LIMBO_TOKEN="${LIMBO_TOKEN:-$(openssl rand -hex 32)}"
  BUILD_TOKEN="${BUILD_TOKEN:-$(openssl rand -hex 32)}"
  OPS_TOKEN="${OPS_TOKEN:-$(openssl rand -hex 32)}"
  SESSION_SECRET="${SESSION_SECRET:-$(openssl rand -hex 32)}"
  # The Velocity modern-forwarding key. It is what makes a backend's UUID trustworthy:
  # the proxy does the Mojang handshake and HMACs the resulting profile with this key,
  # and a backend that cannot verify it would fall back to an offline UUID derived from
@@ -4213,7 +4221,6 @@ SERVICE_TOKEN=${SERVICE_TOKEN}
LIMBO_TOKEN=${LIMBO_TOKEN}
BUILD_TOKEN=${BUILD_TOKEN}
OPS_TOKEN=${OPS_TOKEN}
SESSION_SECRET=${SESSION_SECRET}
FORWARDING_SECRET=${FORWARDING_SECRET}
REGISTRY_PLATFORM_TOKEN=${REGISTRY_PLATFORM_TOKEN}
REGISTRY_BUILD_TOKEN=${REGISTRY_BUILD_TOKEN}
Loading