startup:{$ref:'#/components/schemas/StartupStatus',description:Private runtime and startup diagnostics for authorized server managers.}
nodeName:{type:string,description:Execution node; legacy servers report the observed node.}
name:{type:string}
subdomain:{type:string}
@@ -2539,6 +2559,52 @@ paths:
'404':
$ref:'#/components/responses/NotFound'
/api/v1/servers/{name}/emergency-stop:
post:
tags:[servers]
operationId:emergencyStop
summary:Scale an owned game workload to zero independently of Operator and RCON.
description:Owner only; fresh authentication and exact name confirmation required. A 202 acknowledges scaling, not process exit. Normal Pod termination grace is retained.
description:Atomically persists an override shared by all replicas. The admission limit applies to panel, in-game and scheduled starts without restarting. It does not stop existing servers or reserve memory. Wake cooldown applies to panel and in-game wakes.
Changes for docs/troubleshooting.md: 35 added lines, 1 removed line.
Original line number
Diff line number
Diff line
@@ -326,9 +326,23 @@ per-server cooldown → global running cap**. Map the API result:
| `403` | `forbidden` | `autostartPolicy=allowlist` and UUID not allowlisted, or `ownerOnly` and caller is not owner | Add the UUID / claim the server / set `autostartPolicy=public` |
| `409` | `maintenance_in_progress` | A restore, backup or file change holds the server's world volume (§3b) | Wait for the Job to finish |
| `409` | `world_reclaiming` | The idle reaper is archiving the world (§3b item 3); afterwards the server is released with an empty world | Nothing to wait for; the old world stays in the archive |
| `429` | (cooldown) | Wake retried within the 30s per-server `WakeCooldown` | Wait out the cooldown |
| `429` | (cooldown) | Wake retried within the configured per-server cooldown | Wait out the cooldown |
| `503` | `at_capacity` | Global `MaxRunningServers` cap reached | Stop another server or raise the cap |
Owners can change the running-server limit and wake cooldown in **Platform
settings**. Saved values apply on all API replicas without a restart; the running
limit also applies to scheduled starts. Zero disables the corresponding control.
The running limit is an admission check, not an atomic reservation: concurrent
requests can briefly exceed it, and lowering it never stops existing servers.
A server marked Starting need not have launched Java. Its console now reads Pod
scheduling and container state: `Unschedulable` / insufficient memory means it is
waiting for resources, while image-pull failures and container exits show their
reasons. Logs attach once the container can produce them. A status request that
cannot complete within 12 seconds marks the last view as stale, shows its last
successful read time, and retries without overlapping polls. Do not infer game
readiness from an old Starting label or a disconnected log stream.
[GO-TESTED: `handlers_internal_wake_test.go`, cooldown, running-cap shape.] The
operator's RCON probe — **not** the wake call — is the authoritative readiness
gate; the proxy polls `GET /api/v1/internal/servers/{name}/status` every ~2s and