feat(bootstrap): verify Paper and Velocity jars against Fill's digest
This commit is contained in:
7 files changed
+168
-9
No files matched your search
@@ -9,6 +9,7 @@
|
||||
# Fill v3 API — api.papermc.io v2 has returned HTTP 410 since 2026-07-01):
|
||||
# docker build -f deploy/lobby/Dockerfile \
|
||||
# --build-arg PAPER_JAR_URL=https://fill-data.papermc.io/v1/objects/<sha>/paper-26.2-<build>.jar \
|
||||
# --build-arg PAPER_JAR_SHA256=<that same sha — the objects/ path segment> \
|
||||
# --build-arg LUCKPERMS_JAR_URL="$(curl -fsSL https://metadata.luckperms.net/data/all \
|
||||
# | grep -o 'https://download.luckperms.net/[^"]*/bukkit/loader/[^"]*\.jar')" \
|
||||
# -t felis-lobby:demo .
|
||||
@@ -42,6 +43,10 @@ RUN cd plugins/paper \
|
||||
# also runs the plugin's Java-21 bytecode, so only the runtime moves.
|
||||
FROM eclipse-temurin:25-jre
|
||||
ARG PAPER_JAR_URL
|
||||
# Required alongside the URL: Fill's URLs are content-addressed, but nothing enforces
|
||||
# that shape at build time. Checking the digest after the download turns a truncated or
|
||||
# tampered fetch into a failed build instead of a lobby booted on the wrong bytes.
|
||||
ARG PAPER_JAR_SHA256
|
||||
# LuckPerms is required, not optional: the panel's whole permission surface
|
||||
# (internal/api/handlers_access.go) issues `lp user ...` over RCON, so a lobby built
|
||||
# without it answers every grant with "Unknown command" — a failure the operator only
|
||||
@@ -55,12 +60,16 @@ RUN set -eu; \
|
||||
if [ -z "${PAPER_JAR_URL:-}" ]; then \
|
||||
echo "ERROR: --build-arg PAPER_JAR_URL=<paper jar> is required" >&2; exit 1; \
|
||||
fi; \
|
||||
if [ -z "${PAPER_JAR_SHA256:-}" ]; then \
|
||||
echo "ERROR: --build-arg PAPER_JAR_SHA256=<paper jar sha256> is required" >&2; exit 1; \
|
||||
fi; \
|
||||
if [ -z "${LUCKPERMS_JAR_URL:-}" ]; then \
|
||||
echo "ERROR: --build-arg LUCKPERMS_JAR_URL=<luckperms bukkit jar> is required" >&2; exit 1; \
|
||||
fi; \
|
||||
apt-get update && apt-get install -y --no-install-recommends curl ca-certificates; \
|
||||
mkdir -p /paper/plugins; \
|
||||
curl -fSL "$PAPER_JAR_URL" -o /paper/paper.jar; \
|
||||
echo "$PAPER_JAR_SHA256 /paper/paper.jar" | sha256sum -c; \
|
||||
curl -fSL "$LUCKPERMS_JAR_URL" -o /paper/plugins/LuckPerms.jar; \
|
||||
apt-get purge -y curl && apt-get autoremove -y && rm -rf /var/lib/apt/lists/*; \
|
||||
echo "eula=true" > /paper/eula.txt
|
||||
|
||||
@@ -29,6 +29,7 @@ this at every layer:
|
||||
```
|
||||
docker build -f deploy/lobby/Dockerfile \
|
||||
--build-arg PAPER_JAR_URL=https://<mirror>/paper-1.21.x-<build>.jar \
|
||||
--build-arg PAPER_JAR_SHA256=<sha256 of that jar> \
|
||||
-t felis-lobby:demo .
|
||||
docker save felis-lobby:demo | sudo k3s ctr images import -
|
||||
# felis.toml → [velocity] lobby_image = "felis-lobby:demo"
|
||||
|
||||
Reference in new issue
Block a user