diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index bca7396..6a587ec 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -374,6 +374,16 @@ the no-Zero-Trust face is never exposed on a node. On the control-plane node the break-glass console reaches it by resolving that Service's ClusterIP and dialing `:8081`. +The face speaks plain HTTP, and the tokens cross it in the clear. That holds up because +no hop leaves the node: the proxy runs on the node and dials the ClusterIP, and the +login pod and the build Job are pods on the same node, so reading the traffic takes root +there, which also reads the tokens from disk. Pods reach the face only where a policy +opens it: `felis-login-to-internal-api` for the login pod and `felis-build-egress` for +the build Job; `felis-server-egress` keeps every other game server (lobby included) off +all private ranges, 8081 among them. A Velocity on another host would put the `velocity` +token on the wire, which is one more reason the proxy belongs on the node (§1 of +`docs/operations.md`); a multi-node shape would need TLS on this face first. + - **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service is missing or its selector no longer matches the api pods. `kubectl -n felis get svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name diff --git a/plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java b/plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java index 43dfe8a..62f5b4e 100644 --- a/plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java +++ b/plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java @@ -65,8 +65,10 @@ public final class LinkConfigLoader { + "# Both values are normally injected via environment variables\n" + "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n" + "#\n" - + "# " + KEY_URL + ": base URL of the felis-api internal face, e.g.\n" - + "# http://felis-api.felis.svc.cluster.local:8080\n" + + "# " + KEY_URL + ": base URL of the felis-api internal face: the ClusterIP\n" + + "# of Service felis-api-internal, port 8081, e.g. http://10.43.0.10:8081\n" + + "# (kubectl -n felis get svc felis-api-internal). The installer writes it for\n" + + "# the proxy; it is reachable from the k3s node and permitted pods only.\n" + KEY_URL + "=\n" + "#\n" + "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n"