Files
Felis/internal/naming/naming.go
T
flyemoji 9ef817f2b3 feat(naming): system-server names, validation, and service-token identifiers
SystemLoginServer/SystemLobbyServer plus ValidateSystemServerName (format rule without the reservation check) let the platform provision the reserved login/lobby names users can never claim. ServiceTokenSecretName/Key are the one source of truth for the internal-API credential Secret, shared by the platform renderer and the operator's login-pod injection.
2026-07-02 19:38:37 +09:00

139 lines
5.3 KiB
Go

// Package naming enforces the portability and admission rules (spec §2, §22):
// a server name matches ^[a-z0-9-]{3,32}$ and is non-reserved, and every
// hostname must be a single label under the configured root_domain. The root
// domain is never hardcoded — it is always supplied by config — so this package
// stays free of any deployment-specific domain.
package naming
import (
"fmt"
"regexp"
"strings"
)
var (
serverNameRE = regexp.MustCompile(`^[a-z0-9-]{3,32}$`)
dnsLabelRE = regexp.MustCompile(`^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$`)
)
// reserved subdomains/server names that users may not claim: proxy/lobby and
// the platform's own faces.
var reserved = map[string]struct{}{
"lobby": {},
"admin": {},
"panel": {},
"api": {},
"felis": {},
"velocity": {},
"registry": {},
"internal": {},
"www": {},
}
// System server names Felis provisions itself. They deliberately live on the
// reserved list so no user can claim them, yet the platform must be able to
// create them — see ValidateSystemServerName.
const (
// SystemLoginServer is the always-on limbo auth gate (LOOHP/Limbo). It is the
// front door every fresh connection lands on and the ONLY safe fallback: a
// stopped/starting backend routes here, never onward past authentication.
SystemLoginServer = "login"
// SystemLobbyServer is the post-auth /menu hub (Paper + felis-paper). It is
// reachable only after the login gate passes a player through, so it must
// never be used as a fallback target (that would bypass the gate).
SystemLobbyServer = "lobby"
)
// ServiceTokenSecretName / ServiceTokenSecretKey name the internal-API bearer
// credential Secret (spec §7). They are one source of truth shared across
// subsystems: the platform renderer wires this Secret into the felis-api
// Deployment, and the operator injects it into the login system server's pod as
// FELIS_SERVICE_TOKEN via a secretKeyRef (never a literal). The Secret itself is
// provisioned out-of-band (deploy/bootstrap.sh) and, for the login gate, replicated
// into the minecraft namespace by `felis setup`; these constants only name it.
const (
ServiceTokenSecretName = "felis-service-token"
ServiceTokenSecretKey = "token"
)
// ValidateServerName checks the §22 name rule and reservation list.
func ValidateServerName(name string) error {
if !serverNameRE.MatchString(name) {
return fmt.Errorf("naming: invalid server name %q: must match ^[a-z0-9-]{3,32}$", name)
}
if strings.HasPrefix(name, "-") || strings.HasSuffix(name, "-") {
return fmt.Errorf("naming: server name %q must not start or end with '-'", name)
}
if _, ok := reserved[name]; ok {
return fmt.Errorf("naming: server name %q is reserved", name)
}
return nil
}
// ValidateSystemServerName checks the §22 format rule (^[a-z0-9-]{3,32}$, no
// leading/trailing dash) but DELIBERATELY skips the reservation check. It is the
// admission path for platform-provisioned system services (login, lobby), which
// carry reserved names on purpose: users can never claim them via
// ValidateServerName, yet setup must still be able to create them. It is not a
// public claim path — only the setup/system-service provisioner calls it.
func ValidateSystemServerName(name string) error {
if !serverNameRE.MatchString(name) {
return fmt.Errorf("naming: invalid system server name %q: must match ^[a-z0-9-]{3,32}$", name)
}
if strings.HasPrefix(name, "-") || strings.HasSuffix(name, "-") {
return fmt.Errorf("naming: system server name %q must not start or end with '-'", name)
}
return nil
}
// IsReserved reports whether label is on the reserved list.
func IsReserved(label string) bool {
_, ok := reserved[label]
return ok
}
// worldVolumeName mirrors operator.dataVolumeName: the per-server StatefulSet's
// volumeClaimTemplate is named "world", so a single-replica server's world PVC
// is "world-<name>-0". This is the one naming convention shared by the operator
// (which creates the PVC), the reaper (which deletes it), and restore (which
// mounts it), so it lives here rather than being duplicated per subsystem.
const worldVolumeName = "world"
// WorldPVCName returns the world PersistentVolumeClaim name for a server,
// matching the operator's StatefulSet volumeClaimTemplate naming
// ("world-<name>-0" for the sole replica).
func WorldPVCName(server string) string {
return worldVolumeName + "-" + server + "-0"
}
// Hostname composes subdomain.rootDomain after validating the subdomain.
func Hostname(subdomain, rootDomain string) (string, error) {
if err := ValidateServerName(subdomain); err != nil {
return "", err
}
if rootDomain == "" {
return "", fmt.Errorf("naming: root domain is empty")
}
return subdomain + "." + rootDomain, nil
}
// ValidateHostname enforces the §2 invariant that host is a single label
// directly under rootDomain.
func ValidateHostname(host, rootDomain string) error {
if rootDomain == "" {
return fmt.Errorf("naming: root domain is empty")
}
suffix := "." + rootDomain
if !strings.HasSuffix(host, suffix) {
return fmt.Errorf("naming: hostname %q must be under %q", host, rootDomain)
}
label := strings.TrimSuffix(host, suffix)
if label == "" || strings.Contains(label, ".") {
return fmt.Errorf("naming: hostname %q must be a single label under %q", host, rootDomain)
}
if !dnsLabelRE.MatchString(label) {
return fmt.Errorf("naming: invalid hostname label %q", label)
}
return nil
}