fix(operator): 游戏 Pod 改以 UID 1000 运行并丢弃全部能力,prepare-data 初始化容器修正旧存档属主
This commit is contained in:
25 files changed
+555
-91
No files matched your search
@@ -5,7 +5,7 @@
|
||||
# internal/store/migrations/0019_recommended_paper.sql). It is NOT a system server: it
|
||||
# carries no felis-paper /menu plugin, no LuckPerms, and no forwarding-secret gate.
|
||||
#
|
||||
# It writes NO Velocity forwarding config itself. The operator injects a root
|
||||
# It writes NO Velocity forwarding config itself. The operator injects a
|
||||
# `felis init-forwarding` initContainer into every USER server (internal/operator/
|
||||
# builders.go: buildStatefulSet) that writes config/paper-global.yml + server.properties
|
||||
# online-mode=false onto the /data PVC before this container starts. That external step is
|
||||
@@ -54,6 +54,13 @@ COPY deploy/paper/entrypoint.sh /usr/local/bin/felis-entrypoint.sh
|
||||
# on the PVC. /paper stays the immutable image seed: the jar is never copied onto the
|
||||
# volume, so the panel file editor (which sees only /data) cannot tamper with it.
|
||||
WORKDIR /data
|
||||
# Run as the game uid (naming.GameUID in the Go tree). The operator pins the same uid in
|
||||
# the pod securityContext whatever USER an image declares; declaring it here as well
|
||||
# keeps a plain `docker run` of this image off root, and chowning the empty /data seed
|
||||
# lets that run write its world. The jar seed above stays root-owned and read-only to
|
||||
# the server.
|
||||
RUN chown 1000:1000 /data
|
||||
USER 1000:1000
|
||||
|
||||
# FELIS_GAME_PORT is the port the entrypoint pins Paper to; it MUST equal the operator's
|
||||
# GamePort (internal/operator/builders.go). Default 25565 — override only in lockstep with
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
#
|
||||
# A plain Paper backend for a user's OWN world — NOT a system server. Unlike deploy/limbo
|
||||
# and deploy/lobby it writes no Velocity forwarding config and has no secret gate: the
|
||||
# operator injects a root `felis init-forwarding` initContainer that writes
|
||||
# operator injects a `felis init-forwarding` initContainer that writes
|
||||
# config/paper-global.yml + server.properties online-mode=false onto /data BEFORE this
|
||||
# container starts, so forwarding is configured externally and this stays a drop-in Paper
|
||||
# image. With no initContainer (no FELIS_IMAGE) Paper just boots standalone-online —
|
||||
|
||||
Reference in new issue
Block a user