docs(readme): give an install command that works against a private repo

The documented one-liner fetches bootstrap.sh from raw.githubusercontent.com
unauthenticated, which 404s for as long as this repository stays private -- so
the single command the README exists to provide did not work for anyone.

The authenticated form goes through the contents API with the raw media type,
matching what github_api already does, and hands the token to curl over stdin
via --config rather than -H. argv is world-readable through /proc, and a token
on the command line would leak to any local user during the install; bootstrap
avoids that in its own fetches for the same reason and the README should not
teach the opposite.

sudo -E, because the installer needs that same token to resolve and download the
release. Without it sudo drops the variable and the run fails later, at the
release lookup, for a reason the operator has no way to connect to this command.

The public one-liner stays first: it is what this becomes once the repository is
public, and the note is scoped to the current state.

Also records that re-running the installer is how felis-api moves to a newer
release, that it now keeps the installed root domain, and that it does not keep
the channel.
This commit is contained in:
flyemoji committed 2026-07-20 21:20:09 +09:00
1 parent ecbeb20761
commit 32be3e17b7
1 file changed
+17
+17
View File
@@ -34,6 +34,23 @@ curl -fsSL https://raw.githubusercontent.com/MliroLirrorsIngenuity/Felis/main/de
脚本将自动安装 K3s、部署控制平面并启动设置向导。完成后浏览器访问已配置的域名进入控制面板即可使用。 脚本将自动安装 K3s、部署控制平面并启动设置向导。完成后浏览器访问已配置的域名进入控制面板即可使用。
> **本仓库当前为私有**,上面这条会返回 404。请改用带凭据的形式;安装器自身也需要同一个 token
> 去解析并下载 release,所以用 `sudo -E` 把它带进去:
>
> ```bash
> export FELIS_GITHUB_TOKEN=<对本仓库有读权限的 token>
> printf 'header = "Authorization: Bearer %s"\n' "$FELIS_GITHUB_TOKEN" \
> | curl -fsSL --config - -H "Accept: application/vnd.github.raw" \
> https://api.github.com/repos/MliroLirrorsIngenuity/Felis/contents/deploy/bootstrap.sh \
> | sudo -E bash
> ```
>
> token 经 stdin 交给 `curl --config -`,不放在命令行上:argv 在 `/proc` 下对本机任意用户可读,
> 而这正是安装器内部 `github_api` 采用同一写法的原因。
重跑这条命令也是把 felis-api 升到新版本的方式(`felis setup` 做不到,它用的是本机已有的二进制)。
重跑会沿用已安装的根域名,但**不会**沿用通道:若本机跟随 main,需一并 `export FELIS_VERSION_BOOTSTRAP=dev`。
## 从源码构建 ## 从源码构建
本项目基于 Go 和 Node.js 开发: 本项目基于 Go 和 Node.js 开发: