fix(operator): 游戏 Pod 改以 UID 1000 运行并丢弃全部能力,prepare-data 初始化容器修正旧存档属主

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:23:49 +08:00
1 parent c1796bea17
commit 346a93921e
25 files changed
+555 -91

No files matched your search

+5 -7
View File
@@ -88,13 +88,11 @@ type Config struct {
CPULimit string
MemLimit string
// RunAsUser / RunAsGroup / FSGroup are the Pod's runtime identity. They default
// to ROOT (0:0) for the same reason the operator's forwarding-init container
// runs as root: the world volume is written by the game image's own UID (root
// for every Paper image we ship), and Paper saves files a non-root uid can
// never read — level.dat is written mode 0600 (tar walk: permission denied,
// verified live). DAC_OVERRIDE on the container covers images whose UID is
// neither root nor ours. Set 0/0/0 explicitly for root; FSGroup is omitted
// when zero.
// to ROOT (0:0): the world volume is written by the game uid (naming.GameUID),
// or by root in a world an older release wrote, and Paper saves files no other
// non-root uid can read — level.dat is written mode 0600 (tar walk: permission
// denied, verified live). DAC_OVERRIDE on the container reads them whichever
// uid owns them. Set 0/0/0 explicitly for root; FSGroup is omitted when zero.
RunAsUser int64
RunAsGroup int64
FSGroup int64
+4 -4
View File
@@ -183,7 +183,7 @@ func BackupJob(p JobParams) (*batchv1.Job, error) {
ServiceAccountName: p.ServiceAccount,
AutomountServiceAccountToken: boolPtr(false),
// Root by default (see Config.RunAsUser): the world volume's
// owner is the game image's UID, so only an owner-matching or
// owner is the game uid, so only an owner-matching or
// DAC-overriding uid can read it. FSGroup is omitted when unset
// so a root pod never triggers a volume chgrp.
SecurityContext: backupPodSecurityContext(p),
@@ -248,9 +248,9 @@ func int32Ptr(i int32) *int32 { return &i }
func int64Ptr(i int64) *int64 { return &i }
// backupPodSecurityContext pins the Pod identity. RunAsNonRoot is false because
// the default identity is root: worlds are owned by the game image's UID (root
// for the images we ship), and Paper writes mode-0600 files a non-root reader
// cannot open. FSGroup stays unset unless configured — a root executor must not
// the default identity is root: worlds are owned by the game uid (or root, for a
// world an older release wrote), and Paper writes mode-0600 files any other
// non-root reader cannot open. FSGroup stays unset unless configured — a root executor must not
// needlessly chgrp the world volume.
func backupPodSecurityContext(p JobParams) *corev1.PodSecurityContext {
sc := &corev1.PodSecurityContext{