- §8e: the executor-mirror recipe now pushes into the internal registry (the node's 127.0.0.1:5000, or a kubectl port-forward from another machine) instead of advising bare node-containerd imports — GC collects those and an air-gapped box cannot restore them. - §13b: after an image GC the images come back on their own (registry + the registries.yaml mirror); keeps the operator checks (registry pod, mirror file, re-mirror a tag) and the old fallback for unmirrored images. - §15: rollout undo no longer needs a manual re-import for installer-built tags. - §9: documents the loopback hostPort/mirror pair as one unit and the 2Gi registry memory floor (audit #46). - deploy/{limbo,lobby}/README: manual image builds publish into the registry and point felis.toml at the registry ref.
49 lines
2.0 KiB
Markdown
49 lines
2.0 KiB
Markdown
# Lobby image (Paper + felis-paper)
|
|
|
|
The always-on **lobby** hub. `felis setup` provisions it as a system service
|
|
(`DesiredState=Running`, reaper-exempt) when `[velocity] lobby_image` is set in
|
|
`felis.toml`.
|
|
|
|
> **Code-only.** Not built by the Go CI. It compiles the `plugins/paper`
|
|
> `/menu` face and bundles it onto a Paper server.
|
|
|
|
## Topology & the one invariant
|
|
|
|
```
|
|
connect → login (limbo auth gate) → lobby (/menu hub) → target backend
|
|
```
|
|
|
|
The lobby is reached **only** when the login gate transfers an authenticated
|
|
player onward. It is never a fallback or waiting-park target — routing a fresh
|
|
connection to the lobby would drop the player past authentication. Felis enforces
|
|
this at every layer:
|
|
|
|
- the login system service has **no** fallback (refuse if down);
|
|
- the lobby and every user server fall back to **login**, never to the lobby;
|
|
- `buildSystemServer` refuses to construct any service whose fallback is `lobby`;
|
|
- `felis setup` prints the off-cluster Velocity wiring: default landing and
|
|
waiting-park both point at `login`.
|
|
|
|
## Build
|
|
|
|
```
|
|
docker build -f deploy/lobby/Dockerfile \
|
|
--build-arg PAPER_JAR_URL=https://<mirror>/paper-1.21.x-<build>.jar \
|
|
--build-arg PAPER_JAR_SHA256=<sha256 of that jar> \
|
|
-t felis-lobby:demo .
|
|
# Publish into the cluster's registry (on the node; docker treats 127.0.0.1 as
|
|
# insecure by default — or through a `kubectl -n felis port-forward svc/registry
|
|
# 5000:5000`, which is equivalent: only the path after the host matters).
|
|
docker tag felis-lobby:demo 127.0.0.1:5000/felis/lobby:demo
|
|
docker push 127.0.0.1:5000/felis/lobby:demo
|
|
# felis.toml → [velocity] lobby_image = "registry.felis.svc:5000/felis/lobby:demo"
|
|
sudo felis setup
|
|
```
|
|
|
|
## Configure (deployer's responsibility)
|
|
|
|
- Game port must be `25565` (the CRD `GamePort`).
|
|
- Align `online-mode` / player forwarding with the off-cluster Velocity proxy.
|
|
- The lobby speaks only the `felis:control` plugin-message channel; it holds no
|
|
felis-api token by design (spec §12).
|