fs.Var(&velocityCIDRs,"velocity-cidr","CIDR of a Velocity proxy host allowed to reach game port 25565 (repeatable, REQUIRED)")
varpackageCIDRsmultiFlag
fs.Var(&packageCIDRs,"package-cidr","CIDR of a package mirror build Pods may reach (repeatable; default none = no internet egress)")
varserverDenyCIDRsmultiFlag
fs.Var(&serverDenyCIDRs,"server-egress-deny-cidr","extra CIDR game server pods may never reach, e.g. the node's public address (repeatable)")
varserverAllowCIDRsmultiFlag
fs.Var(&serverAllowCIDRs,"server-egress-allow-cidr","private CIDR game server pods may reach despite the private-range block, e.g. a LAN database (repeatable)")
for ref in"$FELIS_IMAGE" docker.io/library/registry:2;do
if k3s_cmd ctr images label "$ref" io.cri-containerd.pinned=pinned >/dev/null 2>&1;then
ok "pinned ${ref} in containerd (exempt from kubelet image GC)"
else
warn "could not pin ${ref} in containerd: if the kubelet's image GC collects it, the registry pod cannot restart until it is re-imported (docs/troubleshooting.md §8e)"
docker tag "$ref""$push_ref"|| die "could not tag ${ref} as ${push_ref} — is docker healthy?"
docker push "$push_ref"|| die "could not mirror ${ref} into the internal registry — check the registry Deployment/pod and its PVC"
docker --config"$REGISTRY_DOCKER_CONFIG"push "$push_ref"|| die "could not mirror ${ref} into the internal registry — check the registry Deployment/pod (both the registry and registry-gate containers) and its PVC"
docker rmi "$push_ref">/dev/null 2>&1 ||true
}
# registry_docker_login logs a throwaway docker config into the registry gate as
# the platform principal: writes are refused anonymously, and this identity is
# the only one allowed under felis/. The config lives in a 0700 temp dir that the
# EXIT trap removes, so the token never lands in root's ~/.docker.
|| die "could not log in to the internal registry at ${REGISTRY_PUSH_HOST} as platform — check the registry-gate container's log and the felis-registry-auth Secret"
}
# Every image this installer builds is hosted in the registry, so the copies it
# imported into containerd are a first-boot cache, not the only copy: kubelet
# re-pulls from the registry after any image GC. Runs AFTER deploy_bundle — the
@@ -2439,6 +2523,7 @@ push_image_to_registry() {
push_images_to_registry(){
local img
systemctl start docker
registry_docker_login
for img in"$FELIS_IMAGE""$FELIS_LIMBO_IMAGE""$FELIS_LOBBY_IMAGE""$FELIS_PAPER_IMAGE";do
[-n"$img"]||continue
push_image_to_registry "$img"
@@ -2871,6 +2956,8 @@ main() {
fetch_source
fi
build_image
# After build_image imported the felis image: the registry pod's gate runs it.