fix(operator): 游戏 Pod 改以 UID 1000 运行并丢弃全部能力,prepare-data 初始化容器修正旧存档属主

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:23:49 +08:00
1 parent c1796bea17
commit 346a93921e
25 files changed
+555 -91

No files matched your search

+11 -16
View File
@@ -20,18 +20,14 @@ const forwardingSecretEnv = "FELIS_FORWARDING_SECRET"
// config/ and server.properties live under it.
const defaultForwardingDataDir = "/data"
// fwd*Mode make the written config readable AND rewritable by the main server
// container, whose UID we do not control (an arbitrary user image). The
// initContainer runs as root (see buildStatefulSet) so it can write into a data
// volume of unknown ownership; 0666/0777 then let a non-root Paper rewrite the
// same files on boot.
//
// This relies on the initContainer running as root to write into a volume of
// unknown ownership; that is how the operator schedules it. If that ever changes,
// give the server pod an fsGroup so the shared volume is group-writable instead.
// fwd*Mode are the modes the written config lands with. The initContainer runs as
// the same uid as the server container (naming.GameUID, pinned by the operator in
// the pod securityContext) after the prepare-data initContainer has handed the
// whole volume to that uid, so owner read/write is all the server needs to rewrite
// these files on boot and nothing else on the node gets write access to them.
const (
fwdFileMode os.FileMode = 0o666
fwdDirMode os.FileMode = 0o777
fwdFileMode os.FileMode = 0o644
fwdDirMode os.FileMode = 0o755
)
// cmdInitForwarding is the felis-image initContainer entrypoint that makes an
@@ -96,9 +92,8 @@ func writePaperGlobal(dataDir, secret string) error {
if err := os.MkdirAll(dir, fwdDirMode); err != nil {
return fmt.Errorf("create %s: %w", dir, err)
}
// MkdirAll honours the process umask (root's is typically 022 → 0755); chmod
// does not, and a non-root main container must be able to place/replace the
// file in this directory on boot.
// MkdirAll honours the process umask; chmod does not, so a directory an older
// release left at 0777 is brought back to fwdDirMode here.
if err := os.Chmod(dir, fwdDirMode); err != nil {
return fmt.Errorf("chmod %s: %w", dir, err)
}
@@ -188,8 +183,8 @@ func upsertProperty(content []byte, key, value string) []byte {
}
// writeFileMode writes data then forces the mode, since WriteFile honours the
// umask (root's is typically 022 → 0644) but a non-root main container must be
// able to rewrite these files on boot.
// umask and leaves an existing file's mode alone: a file an older release wrote
// world-writable (0666) is tightened back to fwdFileMode on the next boot.
func writeFileMode(path string, data []byte) error {
if err := os.WriteFile(path, data, fwdFileMode); err != nil {
return fmt.Errorf("write %s: %w", path, err)