docs(link): 写明内部面明文 HTTP 的单节点前提与放行范围,修正配置模板里的内部面地址

This commit is contained in:
Lemon-miaow committed 2026-09-25 23:03:02 +08:00
1 parent 0fb43232b5
commit f1414b5cc8
2 files changed
+14 -2

No files matched your search

+10
View File
@@ -374,6 +374,16 @@ the no-Zero-Trust face is never exposed on a node. On the control-plane node the
break-glass console reaches it by resolving that Service's ClusterIP and dialing break-glass console reaches it by resolving that Service's ClusterIP and dialing
`:8081`. `:8081`.
The face speaks plain HTTP, and the tokens cross it in the clear. That holds up because
no hop leaves the node: the proxy runs on the node and dials the ClusterIP, and the
login pod and the build Job are pods on the same node, so reading the traffic takes root
there, which also reads the tokens from disk. Pods reach the face only where a policy
opens it: `felis-login-to-internal-api` for the login pod and `felis-build-egress` for
the build Job; `felis-server-egress` keeps every other game server (lobby included) off
all private ranges, 8081 among them. A Velocity on another host would put the `velocity`
token on the wire, which is one more reason the proxy belongs on the node (§1 of
`docs/operations.md`); a multi-node shape would need TLS on this face first.
- **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service - **Internal calls fail to *connect* (not 401)** → the `felis-api-internal` Service
is missing or its selector no longer matches the api pods. `kubectl -n felis get is missing or its selector no longer matches the api pods. `kubectl -n felis get
svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name svc felis-api-internal` must show a ClusterIP with 8081; a bare `felis-api` name
@@ -65,8 +65,10 @@ public final class LinkConfigLoader {
+ "# Both values are normally injected via environment variables\n" + "# Both values are normally injected via environment variables\n"
+ "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n" + "# (" + ENV_URL + ", " + ENV_TOKEN + "); this file is the fallback.\n"
+ "#\n" + "#\n"
+ "# " + KEY_URL + ": base URL of the felis-api internal face, e.g.\n" + "# " + KEY_URL + ": base URL of the felis-api internal face: the ClusterIP\n"
+ "# http://felis-api.felis.svc.cluster.local:8080\n" + "# of Service felis-api-internal, port 8081, e.g. http://10.43.0.10:8081\n"
+ "# (kubectl -n felis get svc felis-api-internal). The installer writes it for\n"
+ "# the proxy; it is reachable from the k3s node and permitted pods only.\n"
+ KEY_URL + "=\n" + KEY_URL + "=\n"
+ "#\n" + "#\n"
+ "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n" + "# " + KEY_TOKEN + ": the internal service token (keep this secret).\n"