From 32be3e17b7e1a8091ef0f3cb255bc3e2d22a3e23 Mon Sep 17 00:00:00 2001 From: Minseong Choi Date: Mon, 20 Jul 2026 20:25:51 +0900 Subject: [PATCH] docs(readme): give an install command that works against a private repo The documented one-liner fetches bootstrap.sh from raw.githubusercontent.com unauthenticated, which 404s for as long as this repository stays private -- so the single command the README exists to provide did not work for anyone. The authenticated form goes through the contents API with the raw media type, matching what github_api already does, and hands the token to curl over stdin via --config rather than -H. argv is world-readable through /proc, and a token on the command line would leak to any local user during the install; bootstrap avoids that in its own fetches for the same reason and the README should not teach the opposite. sudo -E, because the installer needs that same token to resolve and download the release. Without it sudo drops the variable and the run fails later, at the release lookup, for a reason the operator has no way to connect to this command. The public one-liner stays first: it is what this becomes once the repository is public, and the note is scoped to the current state. Also records that re-running the installer is how felis-api moves to a newer release, that it now keeps the installed root domain, and that it does not keep the channel. --- README.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/README.md b/README.md index d51ca9f..4a87c96 100644 --- a/README.md +++ b/README.md @@ -34,6 +34,23 @@ curl -fsSL https://raw.githubusercontent.com/MliroLirrorsIngenuity/Felis/main/de 脚本将自动安装 K3s、部署控制平面并启动设置向导。完成后浏览器访问已配置的域名进入控制面板即可使用。 +> **本仓库当前为私有**,上面这条会返回 404。请改用带凭据的形式;安装器自身也需要同一个 token +> 去解析并下载 release,所以用 `sudo -E` 把它带进去: +> +> ```bash +> export FELIS_GITHUB_TOKEN=<对本仓库有读权限的 token> +> printf 'header = "Authorization: Bearer %s"\n' "$FELIS_GITHUB_TOKEN" \ +> | curl -fsSL --config - -H "Accept: application/vnd.github.raw" \ +> https://api.github.com/repos/MliroLirrorsIngenuity/Felis/contents/deploy/bootstrap.sh \ +> | sudo -E bash +> ``` +> +> token 经 stdin 交给 `curl --config -`,不放在命令行上:argv 在 `/proc` 下对本机任意用户可读, +> 而这正是安装器内部 `github_api` 采用同一写法的原因。 + +重跑这条命令也是把 felis-api 升到新版本的方式(`felis setup` 做不到,它用的是本机已有的二进制)。 +重跑会沿用已安装的根域名,但**不会**沿用通道:若本机跟随 main,需一并 `export FELIS_VERSION_BOOTSTRAP=dev`。 + ## 从源码构建 本项目基于 Go 和 Node.js 开发: