fix(panel): diagnose runtime failures and add owner recovery controls
This commit is contained in:
47 files changed
+1590
-102
No files matched your search
@@ -109,6 +109,9 @@ func APIMinecraftRole(p Params) *rbacv1.Role {
|
||||
// restore chains; patch settles a chain by relabelling its safety-snapshot
|
||||
// Job (internal/api restorechain.go).
|
||||
rule([]string{groupBatch}, []string{"jobs"}, []string{"create", "get", "delete", "list", "patch"}),
|
||||
// Emergency shutdown bypasses the operator through the scale subresource.
|
||||
rule([]string{groupApps}, []string{"statefulsets"}, []string{"get"}),
|
||||
rule([]string{groupApps}, []string{"statefulsets/scale"}, []string{"update"}),
|
||||
// Read-side console (spec §8 读=pods/log follow): list pods to find the
|
||||
// server's running pod, then read its log subresource. Two separate rules so
|
||||
// the verbs stay tight — list on pods, get on pods/log, and nothing else.
|
||||
|
||||
@@ -127,6 +127,14 @@ func TestAPIRole_MinecraftPowersExact(t *testing.T) {
|
||||
if hasRule(mc, groupCore, "secrets", "list") || hasRule(mc, groupCore, "secrets", "watch") {
|
||||
t.Error("felis-api must NOT list or watch secrets (RCON reads are a direct Get by name)")
|
||||
}
|
||||
if !hasRule(mc, groupApps, "statefulsets", "get") || !hasRule(mc, groupApps, "statefulsets/scale", "update") {
|
||||
t.Error("API needs read and scale-only emergency shutdown grants")
|
||||
}
|
||||
for _, verb := range []string{"patch", "update", "delete"} {
|
||||
if hasRule(mc, groupApps, "statefulsets", verb) {
|
||||
t.Errorf("API must not mutate StatefulSets directly: %s", verb)
|
||||
}
|
||||
}
|
||||
// WorldVolumeExists reads a claim and lists retained claims on server creation.
|
||||
if !hasRule(mc, groupCore, "persistentvolumeclaims", "get") {
|
||||
t.Error("felis-api must get the world PVC (persistentvolumeclaims:get) for the backup/restore world-volume gate")
|
||||
|
||||
Reference in new issue
Block a user