- §8e: the executor-mirror recipe now pushes into the internal registry (the node's 127.0.0.1:5000, or a kubectl port-forward from another machine) instead of advising bare node-containerd imports — GC collects those and an air-gapped box cannot restore them. - §13b: after an image GC the images come back on their own (registry + the registries.yaml mirror); keeps the operator checks (registry pod, mirror file, re-mirror a tag) and the old fallback for unmirrored images. - §15: rollout undo no longer needs a manual re-import for installer-built tags. - §9: documents the loopback hostPort/mirror pair as one unit and the 2Gi registry memory floor (audit #46). - deploy/{limbo,lobby}/README: manual image builds publish into the registry and point felis.toml at the registry ref.
Lobby image (Paper + felis-paper)
The always-on lobby hub. felis setup provisions it as a system service
(DesiredState=Running, reaper-exempt) when [velocity] lobby_image is set in
felis.toml.
Code-only. Not built by the Go CI. It compiles the
plugins/paper/menuface and bundles it onto a Paper server.
Topology & the one invariant
connect → login (limbo auth gate) → lobby (/menu hub) → target backend
The lobby is reached only when the login gate transfers an authenticated player onward. It is never a fallback or waiting-park target — routing a fresh connection to the lobby would drop the player past authentication. Felis enforces this at every layer:
- the login system service has no fallback (refuse if down);
- the lobby and every user server fall back to login, never to the lobby;
buildSystemServerrefuses to construct any service whose fallback islobby;felis setupprints the off-cluster Velocity wiring: default landing and waiting-park both point atlogin.
Build
docker build -f deploy/lobby/Dockerfile \
--build-arg PAPER_JAR_URL=https://<mirror>/paper-1.21.x-<build>.jar \
--build-arg PAPER_JAR_SHA256=<sha256 of that jar> \
-t felis-lobby:demo .
# Publish into the cluster's registry (on the node; docker treats 127.0.0.1 as
# insecure by default — or through a `kubectl -n felis port-forward svc/registry
# 5000:5000`, which is equivalent: only the path after the host matters).
docker tag felis-lobby:demo 127.0.0.1:5000/felis/lobby:demo
docker push 127.0.0.1:5000/felis/lobby:demo
# felis.toml → [velocity] lobby_image = "registry.felis.svc:5000/felis/lobby:demo"
sudo felis setup
Configure (deployer's responsibility)
- Game port must be
25565(the CRDGamePort). - Align
online-mode/ player forwarding with the off-cluster Velocity proxy. - The lobby speaks only the
felis:controlplugin-message channel; it holds no felis-api token by design (spec §12).