fix(platform): minecraft 命名空间强制 PodSecurity baseline,reaper 世界根目录改走静态 hostPath PV

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:28:12 +08:00
1 parent 346a93921e
commit 5521e498a9
8 files changed
+315 -51

No files matched your search

+4 -12
View File
@@ -2496,18 +2496,10 @@ deploy_bundle() {
# always travels with it because it must equal the [archive] local_path written above.
if [ -n "$FELIS_WORLDS_HOST_PATH" ]; then
log "retention enabled: the daily reaper will read worlds from ${FELIS_WORLDS_HOST_PATH}"
# The reaper pod runs as the tree's non-root uid (1000, platform.workloads.nonRootUID)
# and must traverse into the per-volume directories under this root. k3s's own storage
# root ships 0700 root:root, so grant traverse — an ACL entry when the host has setfacl,
# otherwise the equivalent o+x. Traverse only: no listing either way, and the per-volume
# directories themselves are world-accessible (local-path creates them 0777).
if [ -d "$FELIS_WORLDS_HOST_PATH" ]; then
if command -v setfacl >/dev/null 2>&1; then
setfacl -m u:1000:x "$FELIS_WORLDS_HOST_PATH" || chmod o+x "$FELIS_WORLDS_HOST_PATH"
else
chmod o+x "$FELIS_WORLDS_HOST_PATH"
fi
else
# The reaper reads this root as root with DAC_OVERRIDE (platform.reaperPodSecurityContext)
# through a static hostPath PV, so the host directory keeps k3s's own 0700 root:root and
# needs no extra grant. It must exist, though: the PV declares type Directory.
if [ ! -d "$FELIS_WORLDS_HOST_PATH" ]; then
warn "worlds root ${FELIS_WORLDS_HOST_PATH} does not exist yet; the reaper CronJob cannot start until it does (hostPath type Directory)"
fi
manifest_args+=(--worlds-host-path "$FELIS_WORLDS_HOST_PATH" --archive-local-path "$FELIS_ARCHIVE_LOCAL_PATH")
+7 -3
View File
@@ -670,6 +670,7 @@ run_bundle_flags() { # backup-pvc worlds-host-path
kube() { cat; }
myManifests() { printf "%s\n" "$@"; }
setfacl() { printf "SETFACL %s\n" "$*"; }
chmod() { printf "CHMOD %s\n" "$*"; }
node_global_cidrs() { printf "203.0.113.7/32\n2001:db8::7/128\n"; }
run_bundle() {
'"$mblock"'
@@ -723,11 +724,14 @@ missing="/tmp/felis-worlds-root-must-not-exist-$$"
out="$(run_bundle_flags felis-backups "$missing")"
expect "a missing worlds root is warned about, not silently skipped" "WARN: worlds root $missing does not exist yet" "$out"
# The reaper pod is non-root (uid 1000) and k3s ships the storage root 0700 root:root, so
# the installer must grant traverse or every archive dies with permission denied.
# The reaper reads the root as root with DAC_OVERRIDE through a static PV, so an existing
# root is left exactly as k3s shipped it: uid 1000 is now the game servers' uid, and a
# traverse grant for it on the node's storage root would serve nothing but them.
wdir="$(mktemp -d)"
out="$(run_bundle_flags felis-backups "$wdir")"
expect "enabling retention grants the reaper uid traverse on the worlds root" "SETFACL -m u:1000:x $wdir" "$out"
case "$out" in
*SETFACL*|*CHMOD*|*WARN*) echo "FAIL: an existing worlds root must get no grant and no warning: $out"; fails=$((fails + 1)) ;;
esac
# --- the registry mirror writer -----------------------------------------------------------
# k3s only consults registries.yaml at agent start, so a CONTENT change must restart k3s and