feat(breakglass): add halt-a-server op to the recovery console (§B4)

Add a root-gated "Halt a running server" operation to the break-glass
console. The operator picks a server from the live fleet and the console
flips that MinecraftServer CRD's spec.desiredState to Stopped via a
spec-only merge patch, disjoint from the operator's status writes, so it
cannot race or clobber reconciliation. It is the panel-independent
emergency stop for when the box still has root plus a kubeconfig.

System servers (login/lobby) are allowed but flagged: a system tag in the
picker and an explicit WARNING in the post-exit summary, since halting
login takes the shared auth front door down with no fallback. Audit is
best-effort so a halt still works with the audit sink down. Already-stopped
is a distinct no-op. The core (halt.go) is unit-tested against a real
controller-runtime fake client that applies the patch.
This commit is contained in:
flyemoji committed 2026-07-06 23:50:09 +09:00
1 parent abad137a01
commit c2ee21ae05
8 files changed
+649 -10

No files matched your search

+2
View File
@@ -14,6 +14,7 @@ type bgOperation int
const (
bgProvisionOwner bgOperation = iota
bgAddOperator
bgHaltServer
)
// menuChoiceMsg is emitted to the root once the operator picks an operation. The
@@ -50,6 +51,7 @@ func (m *menuModel) build() *huh.Form {
// recovery flow, and landing on it keeps that path a single Enter.
huh.NewOption("Provision or reset the Owner account", bgProvisionOwner),
huh.NewOption("Add an Operator account", bgAddOperator),
huh.NewOption("Halt a running server", bgHaltServer),
),
// A dim footnote spelling out the one behavioural difference that matters:
// Owner-reset re-enables local-password login, operator-add never touches the