99c31c1d4eaecd16035823e0ae4de7432dc8d35c
An auth_source url could be http:// to any host. Anyone on the path to a public root, or anyone who can spoof its DNS name, can then answer hasJoined with a 200 and log in as any player of that source, including a third-party account linked to staff. The player's IP also travels in cleartext. Mojang logins are unaffected, since that source is built in over https. Config load now refuses http:// unless the host is localhost or a loopback or private IP address (127.0.0.0/8, ::1, 10/8, 172.16/12, 192.168/16, fc00::/7), so a root on the same host or the LAN still works without TLS. The decision is made on the literal host because nothing is resolved at load time, so a LAN root named by hostname needs its IP address or https. The error says what to change. The new test covers public names and addresses, link-local, 0.0.0.0 and the first address past 172.16/12 (all refused over http, all accepted over https), and the loopback and private forms that stay allowed. It fails on the old check.
Felis
A Kubernetes-driven Minecraft server hosting platform — one command to deploy, automatic lifecycle, backup, and security.
一款 Kubernetes 驱动的 Minecraft 服务器托管平台,一行命令部署,自动管理生命周期与安全。
Table of Contents
Features
- Wake on Join: Servers start automatically when a player connects, and stop when idle — like hibernate for your server.
- Web Dashboard: Monitor server status, online players, and resource usage from your browser, with backup and restore management.
- Auto Backup & Restore: Scheduled world backups with one-click rollback from any backup point.
- World Reaper: Worlds idle for more than 15 days are automatically backed up and removed to free disk space.
- Multi-core Support: Compatible with Paper, Fabric, Forge, and NeoForge, federated behind a Velocity proxy.
- Modpack Submission: Players submit custom modpacks; admin approval triggers automatic build and deployment.
- Passkey Login: Passwordless authentication via fingerprint, face recognition, or hardware security keys.
- Zero Trust Security: Panel traffic protected by Cloudflare Access; the internal API is never exposed to the internet.
Getting Started
On a prepared Linux host, run:
curl -fsSL https://raw.githubusercontent.com/MliroLirrorsIngenuity/Felis/main/deploy/bootstrap.sh | sudo bash
The script installs K3s, deploys the control plane, and launches a setup wizard. Once done, open your browser at the configured domain.
Build from Source
Felis is built with Go and Node.js:
# Backend (Go 1.26+)
go build -o felis ./cmd/felis
# Frontend (Node.js 22+)
cd panel
npm ci
npm run build
# Docker image
docker build -t felis:custom .
License
The source code is released under AGPL-3.0-only.
License Notes
- Derivative works are AGPL too: Any distribution of this project or of software derived from it must be released under AGPL-3.0 and must include the original copyright notice and license statement.
- Running it as a network service also triggers the source obligation (AGPL section 13): if you host a modified Felis for other people to use, you must offer those users the complete source of your modified version — even if you never distribute a binary. This is the one substantive difference between AGPL and GPL, and since Felis is a hosting platform reached over a network, it will essentially always apply.
- Disclaimer: This project is provided "as is", without warranty of any kind.
Acknowledgements
- Kubernetes: Container orchestration engine
- K3s: Lightweight Kubernetes distribution
- Cloudflare Zero Trust: Zero trust security infrastructure
- PostgreSQL: Data persistence
- React: User interface framework
- Vite: Frontend build tool
- TailwindCSS: CSS framework
- Bubble Tea: TUI framework
- Minecraft: What makes this all worthwhile
Description
No description provided
https://felismc.com
9.2 MiB
0 Stars
2 Watchers
0 Forks
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%