fix(preflight): 探测 k3s 安装器在 SELinux 主机上要用的 rpm.rancher.io,运维手册列出 FELIS_ARTIFACT_DIR 安装仍要放行的地址,README 不再说内网主机能装

This commit is contained in:
Lemon-miaow committed 2026-09-27 17:34:48 +08:00
1 parent cc0672557c
commit db7fbfec46
4 files changed
+87 -7

No files matched your search

+1 -1
View File
@@ -35,7 +35,7 @@ curl -fsSL https://raw.githubusercontent.com/FelisMC/Felis/main/deploy/bootstrap
脚本将自动安装 K3s,在 K3s 内部署 PostgreSQL 与控制平面,并启动设置向导。完成后浏览器访问已配置的域名进入控制面板即可使用。
安装发布版时,二进制、全部镜像与 Velocity 插件都取自该版本在 CI 里预构建好的 release 附件,逐个核对 `SHA256SUMS` 后导入,主机上无需 Docker、Gradle 或 Go,也不从 Docker Hub 拉取;某个附件缺失或校验不符时,只有那一个镜像退回到本机构建,并给出提示(见 [故障排查 §15c](docs/troubleshooting.md))。内网或受限网络的主机可以先把 release 附件拷到本机,再用 `FELIS_ARTIFACT_DIR=<绝对路径>` 安装(见 [运维手册 §1](docs/operations.md#1-supported-hosts))。旧版本装在宿主上的 PostgreSQL 会在重跑时整库迁进 K3s,宿主上的那份停用保留,供回退(见 [运维手册 §4](docs/operations.md#4-upgrading-the-pieces-around-felis))。
安装发布版时,二进制、全部镜像与 Velocity 插件都取自该版本在 CI 里预构建好的 release 附件,逐个核对 `SHA256SUMS` 后导入,主机上无需 Docker、Gradle 或 Go,也不从 Docker Hub 拉取;某个附件缺失或校验不符时,只有那一个镜像退回到本机构建,并给出提示(见 [故障排查 §15c](docs/troubleshooting.md))。附件也可以先拷到本机,再用 `FELIS_ARTIFACT_DIR=<绝对路径>` 安装,Felis 自己的二进制、镜像和插件就都取自这个目录;k3s 及其镜像、JRE、cloudflared、Velocity 和 Via 插件照旧从 GitHub 与 PaperMC 下载,RHEL、Fedora、openSUSE Leap 这类开着 SELinux 的主机还要从 rpm.rancher.io 装 k3s-selinux,系统软件包来自发行版的源。所以出网受限的主机要放行这几处的 HTTPS(或设 `https_proxy`),preflight 会在改动主机之前逐个探测,完全断网的主机目前装不了(地址清单见 [运维手册 §1](docs/operations.md#1-supported-hosts))。旧版本装在宿主上的 PostgreSQL 会在重跑时整库迁进 K3s,宿主上的那份停用保留,供回退(见 [运维手册 §4](docs/operations.md#4-upgrading-the-pieces-around-felis))。
动手之前,脚本先检查内存、磁盘、端口、网段冲突、已有的 Kubernetes 和外网连通,把所有问题一次列出并停下,主机上什么都没改(检查项见 [运维手册 §1](docs/operations.md#1-supported-hosts))。
+20 -1
View File
@@ -1228,6 +1228,20 @@ systemd_is_init() { [ -d /run/systemd/system ]; }
mem_total_kb() { awk '/^MemTotal:/ { print $2 }' /proc/meminfo; }
# k3s_adds_selinux_rpm reports whether k3s's install.sh will install k3s-selinux from
# Rancher's RPM repository (rpm.rancher.io), mirroring its setup_selinux and
# install_selinux_rpm: on a host with an SELinux policy directory that is Red Hat-like (one
# of these release files) or names suse first in ID_LIKE. dnf or zypper failing to reach the
# repository fails the k3s install. $1 is a root to read under, for the tests.
k3s_adds_selinux_rpm() {
local root="${1:-}" f
[ -d "${root}/usr/share/selinux" ] || return 1
for f in redhat-release centos-release oracle-release fedora-release system-release; do
[ -r "${root}/etc/${f}" ] && return 0
done
[ "${OS_ID_LIKE%% *}" = suse ]
}
preflight_platform() {
case "$(uname -m)" in
x86_64|amd64|aarch64|arm64) ;;
@@ -1436,7 +1450,12 @@ preflight_hosts() {
printf '%s\n' "api.github.com required"
fi
fi
[ -x "$K3S_BIN" ] || printf '%s\n' "raw.githubusercontent.com required"
if ! [ -x "$K3S_BIN" ]; then
printf '%s\n' "raw.githubusercontent.com required"
if k3s_adds_selinux_rpm; then
printf '%s\n' "rpm.rancher.io required"
fi
fi
[ -n "$FELIS_VELOCITY_FORK_JAR" ] || printf '%s\n' "fill-data.papermc.io required"
if host_builds_expected; then
printf '%s\n' "registry-1.docker.io required"
+42 -1
View File
@@ -3473,7 +3473,8 @@ run_pf() {
pid_unit() { printf "%s\n" "${PF_UNITS:-}" | awk -v p="$1" "\$1 == p { print \$2 }"; }
existing_ancestor() { printf "%s\n" "$1"; }
path_populated() { case " ${PF_POPULATED:-} " in *" $1 "*) return 0 ;; esac; return 1; }
preflight; echo "WENT ON"' 2>&1
k3s_adds_selinux_rpm() { [ -n "${PF_SELINUX_RPM:-}" ]; }
if [ -n "${PF_HOSTS:-}" ]; then preflight_hosts; else preflight; echo "WENT ON"; fi' 2>&1
}
out="$(run_pf)"
expect "a healthy host passes preflight" "OK: preflight passed" "$out"
@@ -3580,6 +3581,46 @@ out="$(PF_TUI=1 PF_DOWN=api.github.com run_pf)"
expect "the setup console only warns without it: its binary is already here" "WARN: preflight: cannot reach api.github.com" "$out"
expect "and goes on" "OK: preflight passed" "$out"
# k3s's install.sh installs k3s-selinux from Rancher's RPM repository on an SELinux host of
# the Red Hat or SUSE family (the CentOS Stream VM has its rancher-k3s-common.repo), and the
# k3s install fails when dnf cannot reach it.
out="$(PF_SELINUX_RPM=1 PF_DOWN=rpm.rancher.io run_pf)"
expect "k3s's SELinux package repository is required where its installer adds it" "cannot reach rpm.rancher.io over HTTPS" "$out"
out="$(PF_DOWN=rpm.rancher.io run_pf)"
expect "and not probed where it does not" "OK: preflight passed" "$out"
: > "$pfroot/k3s"; chmod +x "$pfroot/k3s"
out="$(PF_SELINUX_RPM=1 PF_DOWN=rpm.rancher.io run_pf)"
expect "nor once k3s is installed" "OK: preflight passed" "$out"
rm -f "$pfroot/k3s"
# The same test install.sh makes, against a root laid out as each family's host is.
selroot="$(mktemp -d)"
adds_rpm() { OS_ID_LIKE="$1" bash -c "$(awk '/^k3s_adds_selinux_rpm\(\) \{/,/^}/' "$BS")"'
if k3s_adds_selinux_rpm "$0"; then echo yes; else echo no; fi' "$selroot"; }
mkdir -p "$selroot/etc"
: > "$selroot/etc/centos-release"
expect "a Red Hat-like host without an SELinux policy directory gets no k3s-selinux" no "$(adds_rpm "rhel fedora")"
mkdir -p "$selroot/usr/share/selinux"
rm "$selroot/etc/centos-release"
for f in redhat-release centos-release oracle-release fedora-release system-release; do
: > "$selroot/etc/$f"
expect "a host with /etc/$f and an SELinux policy directory gets k3s-selinux" yes "$(adds_rpm "")"
rm "$selroot/etc/$f"
done
expect "so does one whose ID_LIKE names suse first (openSUSE Leap)" yes "$(adds_rpm "suse opensuse")"
expect "install.sh adds no repository where suse comes second (Tumbleweed)" no "$(adds_rpm "opensuse suse")"
expect "nor on Debian with SELinux policies installed" no "$(adds_rpm debian)"
rm -rf "$selroot"
# docs/operations.md lists the hosts an install from FELIS_ARTIFACT_DIR still downloads from,
# for a network that admits only those: every host preflight probes there must be in it.
ops="$(dirname "$BS")/../docs/operations.md"
artdoc="$(awk '/^`FELIS_ARTIFACT_DIR=<absolute path>` installs/,/^### /' "$ops" 2>/dev/null)"
hosts="$(PF_HOSTS=1 PF_ARTIFACT_DIR=/srv/felis-release PF_SELINUX_RPM=1 run_pf)"
expect "an install from FELIS_ARTIFACT_DIR probes GitHub" "github.com required" "$hosts"
for h in $(printf '%s\n' "$hosts" | awk '{ print $1 }'); do
expect "operations.md names ${h} for an install from FELIS_ARTIFACT_DIR" "| \`${h}\`" "$artdoc"
done
# Three problems, one report, nothing done.
out="$(PF_MEM_KB=1000000 PF_ARCH=armv7l PF_DOWN=github.com run_pf)"
expect "every problem is in the one report" "preflight found 3 problem(s); nothing on this host has been changed" "$out"
+24 -4
View File
@@ -60,8 +60,10 @@ once, then stops with nothing touched **[SH-TESTED]**:
(a Docker network there is the usual case); a wider route such as a `10.0.0.0/8` VPN
is a warning;
- HTTPS to the hosts it downloads from: GitHub and PaperMC's download API always, Docker
Hub when it builds images on the host. A host counts as reachable once a TLS handshake
with it completes, and each gets three tries two seconds apart. Installing a release, an
Hub when it builds images on the host, Rancher's RPM repository where k3s's installer
adds it (the list is under "Where the binary and the images come from"). A host counts
as reachable once a TLS handshake with it completes, and each gets three tries two
seconds apart. Installing a release, an
unreachable Docker Hub is a warning (it is needed only if an asset turns out unusable);
from `FELIS_ARTIFACT_DIR` it is not checked.
@@ -144,10 +146,28 @@ the images are in the registry, when:
release's assets downloaded there (every `felis-*` file and `SHA256SUMS`), or the directory
`deploy/build-release-artifacts.sh <version> <dir>` wrote. Nothing of Felis's own is
downloaded or built (except the game images under `FELIS_GAME_STACK=latest`, which no release
ships), so an asset the directory lacks, or one failing its checksum, stops the install; k3s,
the JRE, cloudflared and Velocity still come from GitHub and PaperMC. It
ships), so an asset the directory lacks, or one failing its checksum, stops the install. It
cannot be combined with `FELIS_REF` or `FELIS_SKIP_FETCH`, which name a source too.
The rest of the host's software still downloads, so the host needs outbound HTTPS to these,
directly or through `https_proxy`. A host with no outbound access cannot be installed yet
**[SH-TESTED]**:
| Host | What comes from it |
|---|---|
| `github.com`, and the githubusercontent.com hosts its release downloads redirect to | k3s and its images (`k3s-airgap-images-<arch>.tar.zst`), cloudflared, the Temurin JRE, ViaVersion, ViaBackwards and ViaRewind |
| `raw.githubusercontent.com` | k3s's install script, until k3s is installed |
| `rpm.rancher.io` | k3s-selinux, which k3s's install script adds on an SELinux host of the Red Hat or SUSE family (CentOS Stream, RHEL, Rocky, Alma, Fedora, openSUSE Leap), until k3s is installed |
| `fill-data.papermc.io` | the Velocity jar, unless `FELIS_VELOCITY_FORK_JAR` supplies one |
| the distribution's package mirrors | the base packages (CA certificates, OpenSSL, curl and tar where missing), and container-selinux beside k3s-selinux |
Preflight probes each named host above before it changes anything and lists every one it
cannot reach in one refusal (`cannot reach … over HTTPS`); the package manager reports its
own mirrors. An override adds a host the download itself tries: `FELIS_JRE_VERSION` reads
`api.adoptium.net`, a `FELIS_VELOCITY_VERSION` other than the pinned one reads
`fill.papermc.io`, and `FELIS_GAME_STACK=latest` builds its images on the host from Docker
Hub (which preflight probes), PaperMC, Limbo's CI and LuckPerms.
```
# on a machine with access: the release's assets for the host's architecture
gh release download v1.4.0 --repo FelisMC/Felis --dir felis-v1.4.0 \