Unverified Commit f1414b5c authored by Lemon-miaow's avatar Lemon-miaow
Browse files

docs(link): 写明内部面明文 HTTP 的单节点前提与放行范围,修正配置模板里的内部面地址

parent 0fb43232
Loading
Loading
Loading
Loading
+10 −0
Changes for docs/troubleshooting.md: 10 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -374,6 +374,16 @@ the no-Zero-Trust face is never exposed on a node. On the control-plane node the
break-glass console reaches it by resolving that Service's ClusterIP and dialing
`:8081`.

The face speaks plain HTTP, and the tokens cross it in the clear. That holds up because
no hop leaves the node: the proxy runs on the node and dials the ClusterIP, and the
login pod and the build Job are pods on the same node, so reading the traffic takes root
there, which also reads the tokens from disk. Pods reach the face only where a policy
opens it: `felis-login-to-internal-api` for the login pod and `felis-build-egress` for
the build Job; `felis-server-egress` keeps every other game server (lobby included) off
all private ranges, 8081 among them. A Velocity on another host would put the `velocity`
token on the wire, which is one more reason the proxy belongs on the node (§1 of
`docs/operations.md`); a multi-node shape would need TLS on this face first.

- **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service
  is missing or its selector no longer matches the api pods. `kubectl -n felis get
  svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name
+4 −2
Changes for plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java: 4 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -65,8 +65,10 @@ public final class LinkConfigLoader {
                + "# Both values are normally injected via environment variables\n"
                + "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n"
                + "#\n"
                + "# " + KEY_URL + ": base URL of the felis-api internal face, e.g.\n"
                + "#   http://felis-api.felis.svc.cluster.local:8080\n"
                + "# " + KEY_URL + ": base URL of the felis-api internal face: the ClusterIP\n"
                + "# of Service felis-api-internal, port 8081, e.g. http://10.43.0.10:8081\n"
                + "# (kubectl -n felis get svc felis-api-internal). The installer writes it for\n"
                + "# the proxy; it is reachable from the k3s node and permitted pods only.\n"
                + KEY_URL + "=\n"
                + "#\n"
                + "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n"