fix(platform): minecraft 命名空间强制 PodSecurity baseline,reaper 世界根目录改走静态 hostPath PV
This commit is contained in:
8 files changed
+315
-51
No files matched your search
+4
-12
@@ -2496,18 +2496,10 @@ deploy_bundle() {
|
||||
# always travels with it because it must equal the [archive] local_path written above.
|
||||
if [ -n "$FELIS_WORLDS_HOST_PATH" ]; then
|
||||
log "retention enabled: the daily reaper will read worlds from ${FELIS_WORLDS_HOST_PATH}"
|
||||
# The reaper pod runs as the tree's non-root uid (1000, platform.workloads.nonRootUID)
|
||||
# and must traverse into the per-volume directories under this root. k3s's own storage
|
||||
# root ships 0700 root:root, so grant traverse — an ACL entry when the host has setfacl,
|
||||
# otherwise the equivalent o+x. Traverse only: no listing either way, and the per-volume
|
||||
# directories themselves are world-accessible (local-path creates them 0777).
|
||||
if [ -d "$FELIS_WORLDS_HOST_PATH" ]; then
|
||||
if command -v setfacl >/dev/null 2>&1; then
|
||||
setfacl -m u:1000:x "$FELIS_WORLDS_HOST_PATH" || chmod o+x "$FELIS_WORLDS_HOST_PATH"
|
||||
else
|
||||
chmod o+x "$FELIS_WORLDS_HOST_PATH"
|
||||
fi
|
||||
else
|
||||
# The reaper reads this root as root with DAC_OVERRIDE (platform.reaperPodSecurityContext)
|
||||
# through a static hostPath PV, so the host directory keeps k3s's own 0700 root:root and
|
||||
# needs no extra grant. It must exist, though: the PV declares type Directory.
|
||||
if [ ! -d "$FELIS_WORLDS_HOST_PATH" ]; then
|
||||
warn "worlds root ${FELIS_WORLDS_HOST_PATH} does not exist yet; the reaper CronJob cannot start until it does (hostPath type Directory)"
|
||||
fi
|
||||
manifest_args+=(--worlds-host-path "$FELIS_WORLDS_HOST_PATH" --archive-local-path "$FELIS_ARCHIVE_LOCAL_PATH")
|
||||
|
||||
@@ -670,6 +670,7 @@ run_bundle_flags() { # backup-pvc worlds-host-path
|
||||
kube() { cat; }
|
||||
myManifests() { printf "%s\n" "$@"; }
|
||||
setfacl() { printf "SETFACL %s\n" "$*"; }
|
||||
chmod() { printf "CHMOD %s\n" "$*"; }
|
||||
node_global_cidrs() { printf "203.0.113.7/32\n2001:db8::7/128\n"; }
|
||||
run_bundle() {
|
||||
'"$mblock"'
|
||||
@@ -723,11 +724,14 @@ missing="/tmp/felis-worlds-root-must-not-exist-$$"
|
||||
out="$(run_bundle_flags felis-backups "$missing")"
|
||||
expect "a missing worlds root is warned about, not silently skipped" "WARN: worlds root $missing does not exist yet" "$out"
|
||||
|
||||
# The reaper pod is non-root (uid 1000) and k3s ships the storage root 0700 root:root, so
|
||||
# the installer must grant traverse or every archive dies with permission denied.
|
||||
# The reaper reads the root as root with DAC_OVERRIDE through a static PV, so an existing
|
||||
# root is left exactly as k3s shipped it: uid 1000 is now the game servers' uid, and a
|
||||
# traverse grant for it on the node's storage root would serve nothing but them.
|
||||
wdir="$(mktemp -d)"
|
||||
out="$(run_bundle_flags felis-backups "$wdir")"
|
||||
expect "enabling retention grants the reaper uid traverse on the worlds root" "SETFACL -m u:1000:x $wdir" "$out"
|
||||
case "$out" in
|
||||
*SETFACL*|*CHMOD*|*WARN*) echo "FAIL: an existing worlds root must get no grant and no warning: $out"; fails=$((fails + 1)) ;;
|
||||
esac
|
||||
|
||||
# --- the registry mirror writer -----------------------------------------------------------
|
||||
# k3s only consults registries.yaml at agent start, so a CONTENT change must restart k3s and
|
||||
|
||||
Reference in new issue
Block a user