docs(link): 写明内部面明文 HTTP 的单节点前提与放行范围,修正配置模板里的内部面地址
This commit is contained in:
2 files changed
+14
-2
No files matched your search
@@ -374,6 +374,16 @@ the no-Zero-Trust face is never exposed on a node. On the control-plane node the
|
|||||||
break-glass console reaches it by resolving that Service's ClusterIP and dialing
|
break-glass console reaches it by resolving that Service's ClusterIP and dialing
|
||||||
`:8081`.
|
`:8081`.
|
||||||
|
|
||||||
|
The face speaks plain HTTP, and the tokens cross it in the clear. That holds up because
|
||||||
|
no hop leaves the node: the proxy runs on the node and dials the ClusterIP, and the
|
||||||
|
login pod and the build Job are pods on the same node, so reading the traffic takes root
|
||||||
|
there, which also reads the tokens from disk. Pods reach the face only where a policy
|
||||||
|
opens it: `felis-login-to-internal-api` for the login pod and `felis-build-egress` for
|
||||||
|
the build Job; `felis-server-egress` keeps every other game server (lobby included) off
|
||||||
|
all private ranges, 8081 among them. A Velocity on another host would put the `velocity`
|
||||||
|
token on the wire, which is one more reason the proxy belongs on the node (§1 of
|
||||||
|
`docs/operations.md`); a multi-node shape would need TLS on this face first.
|
||||||
|
|
||||||
- **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service
|
- **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service
|
||||||
is missing or its selector no longer matches the api pods. `kubectl -n felis get
|
is missing or its selector no longer matches the api pods. `kubectl -n felis get
|
||||||
svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name
|
svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name
|
||||||
|
|||||||
@@ -65,8 +65,10 @@ public final class LinkConfigLoader {
|
|||||||
+ "# Both values are normally injected via environment variables\n"
|
+ "# Both values are normally injected via environment variables\n"
|
||||||
+ "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n"
|
+ "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n"
|
||||||
+ "#\n"
|
+ "#\n"
|
||||||
+ "# " + KEY_URL + ": base URL of the felis-api internal face, e.g.\n"
|
+ "# " + KEY_URL + ": base URL of the felis-api internal face: the ClusterIP\n"
|
||||||
+ "# http://felis-api.felis.svc.cluster.local:8080\n"
|
+ "# of Service felis-api-internal, port 8081, e.g. http://10.43.0.10:8081\n"
|
||||||
|
+ "# (kubectl -n felis get svc felis-api-internal). The installer writes it for\n"
|
||||||
|
+ "# the proxy; it is reachable from the k3s node and permitted pods only.\n"
|
||||||
+ KEY_URL + "=\n"
|
+ KEY_URL + "=\n"
|
||||||
+ "#\n"
|
+ "#\n"
|
||||||
+ "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n"
|
+ "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n"
|
||||||
|
|||||||
Reference in new issue
Block a user