fix(operator): RCON Secret 改走无缓存按名读取,去掉 Secret watch,RBAC 收窄为 secrets get/create,不再缓存全命名空间 Secret

This commit is contained in:
Lemon-miaow committed 2026-09-25 19:25:24 +08:00
1 parent 6ec1b2726c
commit a977e229ca
6 files changed
+110 -18

No files matched your search

+5 -2
View File
@@ -540,8 +540,11 @@ func operatorMetricsService(p Params) *corev1.Service {
// the felis-operator SA and carries controlPlanePodLabels(operator), the second
// pod the allow-rcon peer admits (the readiness prober dials RCON). It takes NO
// config Secret: the operator reads everything from flags + the in-cluster API,
// so it never holds the database URL — a deliberately smaller attack surface than
// the api. It watches the minecraft namespace (--namespace) while running in the
// so it never loads the database URL — a deliberately smaller attack surface than
// the api. Its secrets:get in the minecraft namespace is by name and uncached
// (no list, no informer), yet namespaced RBAC cannot exclude a name, so a
// compromised operator could still fetch the felis-config mirror the Jobs and
// the reaper mount there. It watches the minecraft namespace (--namespace) while running in the
// control namespace, exactly the split cmd/felis/operator.go documents.
func OperatorDeployment(p Params) *appsv1.Deployment {
p = p.withDefaults()