Loading docs/troubleshooting.md +10 −0 Changes for docs/troubleshooting.md: 10 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -374,6 +374,16 @@ the no-Zero-Trust face is never exposed on a node. On the control-plane node the break-glass console reaches it by resolving that Service's ClusterIP and dialing `:8081`. The face speaks plain HTTP, and the tokens cross it in the clear. That holds up because no hop leaves the node: the proxy runs on the node and dials the ClusterIP, and the login pod and the build Job are pods on the same node, so reading the traffic takes root there, which also reads the tokens from disk. Pods reach the face only where a policy opens it: `felis-login-to-internal-api` for the login pod and `felis-build-egress` for the build Job; `felis-server-egress` keeps every other game server (lobby included) off all private ranges, 8081 among them. A Velocity on another host would put the `velocity` token on the wire, which is one more reason the proxy belongs on the node (§1 of `docs/operations.md`); a multi-node shape would need TLS on this face first. - **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service is missing or its selector no longer matches the api pods. `kubectl -n felis get svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name Loading plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java +4 −2 Changes for plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java: 4 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -65,8 +65,10 @@ public final class LinkConfigLoader { + "# Both values are normally injected via environment variables\n" + "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n" + "#\n" + "# " + KEY_URL + ": base URL of the felis-api internal face, e.g.\n" + "# http://felis-api.felis.svc.cluster.local:8080\n" + "# " + KEY_URL + ": base URL of the felis-api internal face: the ClusterIP\n" + "# of Service felis-api-internal, port 8081, e.g. http://10.43.0.10:8081\n" + "# (kubectl -n felis get svc felis-api-internal). The installer writes it for\n" + "# the proxy; it is reachable from the k3s node and permitted pods only.\n" + KEY_URL + "=\n" + "#\n" + "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n" Loading Loading
docs/troubleshooting.md +10 −0 Changes for docs/troubleshooting.md: 10 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -374,6 +374,16 @@ the no-Zero-Trust face is never exposed on a node. On the control-plane node the break-glass console reaches it by resolving that Service's ClusterIP and dialing `:8081`. The face speaks plain HTTP, and the tokens cross it in the clear. That holds up because no hop leaves the node: the proxy runs on the node and dials the ClusterIP, and the login pod and the build Job are pods on the same node, so reading the traffic takes root there, which also reads the tokens from disk. Pods reach the face only where a policy opens it: `felis-login-to-internal-api` for the login pod and `felis-build-egress` for the build Job; `felis-server-egress` keeps every other game server (lobby included) off all private ranges, 8081 among them. A Velocity on another host would put the `velocity` token on the wire, which is one more reason the proxy belongs on the node (§1 of `docs/operations.md`); a multi-node shape would need TLS on this face first. - **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service is missing or its selector no longer matches the api pods. `kubectl -n felis get svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name Loading
plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java +4 −2 Changes for plugins/shared/src/main/java/best/lolicon/felis/link/LinkConfigLoader.java: 4 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -65,8 +65,10 @@ public final class LinkConfigLoader { + "# Both values are normally injected via environment variables\n" + "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n" + "#\n" + "# " + KEY_URL + ": base URL of the felis-api internal face, e.g.\n" + "# http://felis-api.felis.svc.cluster.local:8080\n" + "# " + KEY_URL + ": base URL of the felis-api internal face: the ClusterIP\n" + "# of Service felis-api-internal, port 8081, e.g. http://10.43.0.10:8081\n" + "# (kubectl -n felis get svc felis-api-internal). The installer writes it for\n" + "# the proxy; it is reachable from the k3s node and permitted pods only.\n" + KEY_URL + "=\n" + "#\n" + "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n" Loading