fix(operator): 游戏 Pod 改以 UID 1000 运行并丢弃全部能力,prepare-data 初始化容器修正旧存档属主
This commit is contained in:
25 files changed
+555
-91
No files matched your search
@@ -82,6 +82,13 @@ COPY deploy/lobby/entrypoint.sh /usr/local/bin/felis-entrypoint.sh
|
||||
# The operator mounts the world PVC at /data. Runtime state lives there; /paper
|
||||
# remains the immutable image seed copied into the volume by the entrypoint.
|
||||
WORKDIR /data
|
||||
# Run as the game uid (naming.GameUID in the Go tree). The operator pins the same uid in
|
||||
# the pod securityContext whatever USER an image declares; declaring it here as well
|
||||
# keeps a plain `docker run` of this image off root, and chowning the empty /data seed
|
||||
# lets that run write its world. The jar seed above stays root-owned and read-only to
|
||||
# the server.
|
||||
RUN chown 1000:1000 /data
|
||||
USER 1000:1000
|
||||
|
||||
# FELIS_GAME_PORT is the port the entrypoint pins Paper to; it MUST equal the operator's
|
||||
# GamePort (internal/operator/builders.go). Default 25565 — override only in lockstep
|
||||
|
||||
Reference in new issue
Block a user