// Rcon.Enabled is part of the condition because `players` is only a real tally// when the probe above ran: with RCON off it keeps its zero value, which this// branch would read as "empty" and use to stop a server full of people.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
问题
spec.rcon是后来才加进 CRD 的,已部署安装上的四台 MinecraftServer CR 全都是rcon.enabled = <none>。RCON 从来没有真正启用过。这一条静默地关掉了三样东西,而它们各自看起来像是独立的毛病:
reconciler.go:143-146里玩家采样整段挂在if server.Spec.Rcon.Enabled下面;而且 idle auto-stop 也跟着一起哑了:
reconciler.go:175的条件是server.Spec.Rcon.Enabled && server.Spec.Idle.AutoStopEnabled && ...。证据
Identified by Claude Opus 5 (claude-opus-5) while auditing the RCON subsystem against the live cluster on 2026-07-28.
internal/operator/reconciler.go:175::170-174的注释写明了为什么必须带这个条件:三台都要人工 patch,但原因是两个:
ensureSystemServers,但 CR 上的 spec 字段不在refreshDerivedEnv的白名单里,已存在的 CR 从systemservers.go:316的skipped: "already exists"直接返回。ensureSystemServers(plans里只有 login 和 lobby)。就算 #1 那条收敛路径修好了,也够不到这两台。验收
kubectl get minecraftserver lobby demo demo2 -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.spec.rcon.enabled}{"\n"}{end}'三台都是true,面板控制台能执行命令,在线玩家数不再恒为 0。备注
两条硬性约束,顺序和范围都是载重的:
顺序:镜像先,patch 后。 CR 打上
rcon.enabled=true之后 reconciler 会把就绪判定挂到 RCON 探针上。如果镜像里还没有能应答的 RCON 监听器,服务器就永远出不了 Starting,markFailed之后前门跟着下线。绝对不要给
login开。 login 跑的是 LOOHP/Limbo,它根本不提供 RCON 监听器。给它开 = 探针永远失败 = 那台服务器进不了 Ready = 所有人被锁在门外。这台是唯一必须排除的。需要
kubectl patch minecraftserver,我这边执行不了,所以挂help wanted。注记(收敛路径已成产品——保持打开做老装机待办跟踪):
lobby 属系统服:重跑
deploy/bootstrap.sh重建镜像后,sudo felis converge(c57daaf)会把spec.rcon{enabled,secretRef}填回 CR——只在仍为零值时填、运维自设值不覆盖;本 VM 真机演练(剥字段 → converge → 填回 → operator 收敛 Running)已过。demo/demo2 是用户服务器,本条自己的更正已标明不在范围;其 rcon 由管理员按服务器配置处理(产品路径)。两条路径都已实现并在 VM 上跑通。
sudo felis converge按ensureSystemServers的期望补上spec.rcon,已有的 CR 不再停在already exists。felis converge -user-rcon。不带 flag 时只报告哪些用户服务器没有 RCON;带上 flag 时补RconSpec{Enabled:true, SecretRef: <name>-rcon},已自定义过 RCON 的服务器和系统服务器(含 login)不碰。第二遍是空操作。login被排除:系统角色的 CR 不在-user-rcon范围内,felis converge对 login 的期望也不含 RCON。VM 实测(本 VM 上没有 demo/demo2,用户服务器是 resolvecheck 和 test-one):
启动后
RconReached=True,reason "RCON list reply read"(lobby 与 resolvecheck 都是),也就是面板控制台和在线人数采样用的那条通道已经通。