feat(bootstrap): game stack 按 lock 文件固定构建并校验 sha256,基础镜像按 digest 固定,JRE 固定补丁版本
This commit is contained in:
13 files changed
+632
-94
No files matched your search
+17
-11
@@ -5,13 +5,13 @@
|
||||
# the POST-auth /menu hub: it is reached only when the login gate transfers an
|
||||
# authenticated player onward, and it must never be a fallback target.
|
||||
#
|
||||
# Build (deploy/bootstrap.sh does this for you; the PAPER_JAR_URL comes from PaperMC's
|
||||
# Fill v3 API — api.papermc.io v2 has returned HTTP 410 since 2026-07-01):
|
||||
# Build (deploy/bootstrap.sh does this for you, with the URLs and digests
|
||||
# deploy/game-stack.lock names):
|
||||
# . <(grep -E '^(PAPER|LUCKPERMS)_' deploy/game-stack.lock)
|
||||
# docker build -f deploy/lobby/Dockerfile \
|
||||
# --build-arg PAPER_JAR_URL=https://fill-data.papermc.io/v1/objects/<sha>/paper-26.2-<build>.jar \
|
||||
# --build-arg PAPER_JAR_SHA256=<that same sha — the objects/ path segment> \
|
||||
# --build-arg LUCKPERMS_JAR_URL="$(curl -fsSL https://metadata.luckperms.net/data/all \
|
||||
# | grep -o 'https://download.luckperms.net/[^"]*/bukkit/loader/[^"]*\.jar')" \
|
||||
# --build-arg PAPER_JAR_URL="$PAPER_JAR_URL" --build-arg PAPER_JAR_SHA256="$PAPER_JAR_SHA256" \
|
||||
# --build-arg LUCKPERMS_JAR_URL="$LUCKPERMS_JAR_URL" \
|
||||
# --build-arg LUCKPERMS_JAR_SHA256="$LUCKPERMS_JAR_SHA256" \
|
||||
# -t felis-lobby:demo .
|
||||
# docker save felis-lobby:demo | sudo k3s ctr images import -
|
||||
# # felis.toml → [velocity] lobby_image = "felis-lobby:demo"
|
||||
@@ -28,7 +28,7 @@
|
||||
# ---- build the felis-paper plugin jar (Paper API is Java 21) ----
|
||||
# gradle:8.14-jdk21 — an official Gradle image on JDK 21 (this tree vendors no Gradle
|
||||
# wrapper, and a bare JDK image ships no `gradle`). JDK 21 matches the Paper API.
|
||||
FROM gradle:8.14-jdk21 AS plugin
|
||||
FROM gradle:8.14-jdk21@sha256:5c4c0c4284de4a19951e82ac78f86dbcda2e136644bbfe159beba7ea3420cc80 AS plugin
|
||||
WORKDIR /src
|
||||
COPY plugins/paper/ ./plugins/paper/
|
||||
COPY plugins/shared/ ./plugins/shared/
|
||||
@@ -41,7 +41,7 @@ RUN cd plugins/paper \
|
||||
# 25-jre, not 21: Paper 26.2 declares `java.version.minimum = 25` (PaperMC Fill v3,
|
||||
# GET /v3/projects/paper/versions/26.2) and refuses to boot on anything older. A 25 JRE
|
||||
# also runs the plugin's Java-21 bytecode, so only the runtime moves.
|
||||
FROM eclipse-temurin:25-jre
|
||||
FROM eclipse-temurin:25-jre@sha256:bb036ed6cfdc57e3da7c22634d15f1b840d2caf76183861c80e81ca4b5104abb
|
||||
ARG PAPER_JAR_URL
|
||||
# Required alongside the URL: Fill's URLs are content-addressed, but nothing enforces
|
||||
# that shape at build time. Checking the digest after the download turns a truncated or
|
||||
@@ -51,10 +51,12 @@ ARG PAPER_JAR_SHA256
|
||||
# (internal/api/handlers_access.go) issues `lp user ...` over RCON, so a lobby built
|
||||
# without it answers every grant with "Unknown command" — a failure the operator only
|
||||
# discovers in production, because the server itself starts and runs perfectly well.
|
||||
# Failing the build is the cheap place to notice. Resolved by URL rather than pinned
|
||||
# here for the same reason PAPER_JAR_URL is: bootstrap.sh asks upstream for the current
|
||||
# build, so this file does not go stale on every LuckPerms release.
|
||||
# Failing the build is the cheap place to notice. Passed in rather than pinned here for
|
||||
# the same reason PAPER_JAR_URL is: deploy/game-stack.lock names the build, so this file
|
||||
# does not change on every LuckPerms release. The digest is required like Paper's; the
|
||||
# jar runs inside the lobby with the server's full permissions.
|
||||
ARG LUCKPERMS_JAR_URL
|
||||
ARG LUCKPERMS_JAR_SHA256
|
||||
WORKDIR /paper
|
||||
RUN set -eu; \
|
||||
if [ -z "${PAPER_JAR_URL:-}" ]; then \
|
||||
@@ -66,11 +68,15 @@ RUN set -eu; \
|
||||
if [ -z "${LUCKPERMS_JAR_URL:-}" ]; then \
|
||||
echo "ERROR: --build-arg LUCKPERMS_JAR_URL=<luckperms bukkit jar> is required" >&2; exit 1; \
|
||||
fi; \
|
||||
if [ -z "${LUCKPERMS_JAR_SHA256:-}" ]; then \
|
||||
echo "ERROR: --build-arg LUCKPERMS_JAR_SHA256=<luckperms jar sha256> is required" >&2; exit 1; \
|
||||
fi; \
|
||||
apt-get update && apt-get install -y --no-install-recommends curl ca-certificates; \
|
||||
mkdir -p /paper/plugins; \
|
||||
curl -fSL "$PAPER_JAR_URL" -o /paper/paper.jar; \
|
||||
echo "$PAPER_JAR_SHA256 /paper/paper.jar" | sha256sum -c; \
|
||||
curl -fSL "$LUCKPERMS_JAR_URL" -o /paper/plugins/LuckPerms.jar; \
|
||||
echo "$LUCKPERMS_JAR_SHA256 /paper/plugins/LuckPerms.jar" | sha256sum -c; \
|
||||
apt-get purge -y curl && apt-get autoremove -y && rm -rf /var/lib/apt/lists/*; \
|
||||
echo "eula=true" > /paper/eula.txt
|
||||
COPY --from=plugin /felis-paper.jar /paper/plugins/felis-paper.jar
|
||||
|
||||
Reference in new issue
Block a user