backupPVC:=fs.String("backup-pvc","felis-backups","name of the world-archive PVC this bundle renders in the Minecraft namespace and advertises to the backup/restore executors via FELIS_BACKUP_PVC (default: felis-backups; pass an empty value to render none, leaving backup/restore answering 503)")
worldsHostPath:=fs.String("worlds-host-path","","node directory the reaper reads worlds from: each world PVC resolves as <path>/<pvc>, or as the stock local-path directory <path>/<pv-name>_<ns>_<pvc-name> (k3s storage root: /var/lib/rancher/k3s/storage); enables the reaper CronJob (requires --archive-local-path and a non-empty --backup-pvc)")
archiveLocalPath:=fs.String("archive-local-path","","path the backup PVC is mounted at in the reaper CronJob; MUST equal felis.toml [archive] local_path")
registryStorage:=fs.String("registry-storage","","capacity the registry PVC requests (default 10Gi; k3s local-path does not enforce it)")
uploadsStorage:=fs.String("uploads-storage","","capacity the uploads PVC requests (default 5Gi; k3s local-path does not enforce it)")
backupStorage:=fs.String("backup-storage","","capacity the world-archive PVC requests (default 10Gi; k3s local-path does not enforce it)")
reaperNode:=fs.String("reaper-node","","node that holds --worlds-host-path: pins the reaper CronJob's pod there via nodeSelector kubernetes.io/hostname (multi-node clusters need this, or the reaper may schedule where the hostPath is empty)")
varvelocityCIDRsmultiFlag
fs.Var(&velocityCIDRs,"velocity-cidr","CIDR of a Velocity proxy host allowed to reach game port 25565 (repeatable, REQUIRED)")
# pvc_size <namespace> <claim> <wanted> <env name> prints the size to render the claim
# with: its current request when it exists, else the wanted size (empty = the renderer's
# default). A claim's request can only grow, and only on a storage class that allows
# expansion (k3s local-path does not), so re-applying a different size would fail the
# whole apply; a mismatch is reported and left to the operator.
pvc_size(){
local ns="$1"claim="$2"want="$3"env="$4" have
have="$(kube -n"$ns" get pvc "$claim"-ojsonpath='{.spec.resources.requests.storage}' 2>/dev/null ||true)"
if[-z"$have"];then
printf'%s'"$want"
return 0
fi
if[-n"$want"]&&["$want"!="$have"];then
warn "PVC ${ns}/${claim} already requests ${have}; keeping it (${env}=${want} applies to a new claim; grow this one with kubectl patch where its storage class allows expansion)"