flyemoji 28d3638952 fix(nano): stop following redirects from upstream Yggdrasil roots
authHTTPClient kept net/http's default redirect policy, so a configured
third-party root that answered hasJoined with a 3xx made this host fetch
whatever URL it named, up to ten hops. That is a blind SSRF into
anything the host can reach, and it includes the multiplexer's own
listener: a root that redirects back to /session/minecraft/hasJoined
re-enters the handler, which queries Mojang and every source again and
gets redirected again, until the outer 5s client timeout fires. With a
50ms Mojang stub, one login produced 86 nested handler calls and 86
Mojang requests from this host's egress IP. The loopback default does
not help, because the redirect target is resolved from this host.

Return the 3xx as the response instead. resolveHasJoined already skips
any non-200 answer and closes its body, so a redirecting source is now
treated like one that is down, and the next source gets its turn. The
same probe now makes one handler call and one Mojang request.
Neither Mojang's nor LittleSkin's hasJoined redirects.

The new subtest puts a redirecting root ahead of an honest one and
checks that the redirect target is never contacted and the honest
source's player is returned. The pre-fix handler fails it.
2026-09-22 12:50:56 +09:00
2026-07-20 18:53:25 +09:00
2026-07-20 18:53:25 +09:00
2026-07-12 01:42:07 +08:00

Felis

A Kubernetes-driven Minecraft server hosting platform — one command to deploy, automatic lifecycle, backup, and security.
一款 Kubernetes 驱动的 Minecraft 服务器托管平台,一行命令部署,自动管理生命周期与安全。

简体中文 | English

Table of Contents

Features

  • Wake on Join: Servers start automatically when a player connects, and stop when idle — like hibernate for your server.
  • Web Dashboard: Monitor server status, online players, and resource usage from your browser, with backup and restore management.
  • Auto Backup & Restore: Scheduled world backups with one-click rollback from any backup point.
  • World Reaper: Worlds idle for more than 15 days are automatically backed up and removed to free disk space.
  • Multi-core Support: Compatible with Paper, Fabric, Forge, and NeoForge, federated behind a Velocity proxy.
  • Modpack Submission: Players submit custom modpacks; admin approval triggers automatic build and deployment.
  • Passkey Login: Passwordless authentication via fingerprint, face recognition, or hardware security keys.
  • Zero Trust Security: Panel traffic protected by Cloudflare Access; the internal API is never exposed to the internet.

Getting Started

On a prepared Linux host, run:

curl -fsSL https://raw.githubusercontent.com/MliroLirrorsIngenuity/Felis/main/deploy/bootstrap.sh | sudo bash

The script installs K3s, deploys the control plane, and launches a setup wizard. Once done, open your browser at the configured domain.

Build from Source

Felis is built with Go and Node.js:

# Backend (Go 1.26+)
go build -o felis ./cmd/felis

# Frontend (Node.js 22+)
cd panel
npm ci
npm run build

# Docker image
docker build -t felis:custom .

License

The source code is released under AGPL-3.0-only.

License Notes

  1. Derivative works are AGPL too: Any distribution of this project or of software derived from it must be released under AGPL-3.0 and must include the original copyright notice and license statement.
  2. Running it as a network service also triggers the source obligation (AGPL section 13): if you host a modified Felis for other people to use, you must offer those users the complete source of your modified version — even if you never distribute a binary. This is the one substantive difference between AGPL and GPL, and since Felis is a hosting platform reached over a network, it will essentially always apply.
  3. Disclaimer: This project is provided "as is", without warranty of any kind.

Acknowledgements

Languages
Go 62.7%
TypeScript 22.5%
Shell 7.4%
Java 7.1%
Dockerfile 0.2%
Other 0.1%