wtclaude 4c9b2e7e9c docs(website): settle phase 4's shape — delivery
Phase 3 closed with core at 158 routes and module-uo releasable; phase 4 is
the first phase that is not about the boundary. It answers how a module gets
onto a box an operator owns, and how it comes off again.

Adds MODULE_SYSTEM.md §2.7.2 recording the measured starting state (the
producer side is finished — module-uo's release.yml already publishes the
tarball, the install manifest and SHA256SUMS, and module.json declares
purge.sql — while core has the installed_modules provenance columns and
nothing that fetches, verifies, unpacks or purges), the four org-lead
decisions, the five slices, the unpack threat model and the acceptance table.

The four decisions:

1. Restart is a button. Install, uninstall and re-enable only take effect at
   boot; recording a pending change and telling the operator to restart the
   container contradicts §2.4's "no shell access to the box", so an admin
   action runs the shutdown and exits, and the supervisor the shipped compose
   file already declares brings it back.
2. The install source is a pasted manifest URL, not a catalog — a catalog
   would make core's release cadence decide which modules exist. Safety is the
   declared sha256 plus an https host allowlist, which also stops the endpoint
   being an SSRF primitive.
3. Disable dispatches that one module's onShutdown before flipping the guard.
   As built, disable makes a module invisible rather than stopped — module-uo
   keeps its sidecar socket open and keeps ingesting into shard_* tables —
   which is wrong for the case the button exists for. Enable is not the mirror:
   there is no onBoot re-dispatch and the hooks were never promised re-entrant,
   so enable flips the row and offers the restart.
4. The declarative Docker set is an environment variable, resolved before the
   server starts, idempotent and offline-safe: an already-unpacked module at
   the declared version is a no-op.

Amends §2.4 (disable is no longer a pure guard flip) and §2.5 (what "admin
selects the module" and "restart" concretely mean). Records re-entrant
lifecycle hooks as a second candidate for a future MODULE_API major bump,
beside the identity-provider gap the rust dry run found.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-12 02:31:20 -05:00

Runic Gateway — Documentation

Central documentation for the Runic Gateway platform. The docs here were extracted from the two code repositories (with full commit history preserved) so they live in one place, independent of either codebase.

Layout

website/    docs from the website core (Node/Express + MariaDB + React/Vite)
modules/    docs for installable game modules — one directory per module id
link/       docs from the ServUO bridge (C# plugin + Rust sidecar + Node WS)
android/    docs from the native Android client (Kotlin + Jetpack Compose)
installer/  docs for the installer that deploys a shard's bridge components
ci/         cross-cutting CI/quality notes

Setting up a shard? installer/INSTALL.md is the operator guide, and the installer is the supported path: one binary deploys the plugin overlay, installs the uo-link sidecar as a service, and hands you the values the website needs.

website/

Doc What it covers
BACKEND_DESIGN.md API contract, DB schema, security model
HERO_EDITOR.md Hero canvas editor feature spec
THEMING_AND_NAV.md Admin-configurable theme, brand assets and navigation — build contract
MODULE_SYSTEM.md Making the site game-agnostic: game logic becomes an installable module — design of record
MODULE_API.md The module ↔ core contract: ctx, the register* calls, the client registry and the loader's obligations
WIKI_UPGRADE.md Wiki subsystem upgrade notes
SHARD_VISIBILITY.md Who sees which shard data — the admin-configurable audience framework
SPAWN_ATLAS.md The bestiary / spawn atlas: what the shard contains, parsed from its own ServUO tree
CLILOCS.md UO's id → name table: converting one from your client so items have names
UOFIDDLER.md Operator runbook — step-by-step extraction from your own UO client (cliloc table, creature art)
MARKETPLACE.md The player-vendor index: how it is gathered, what it costs, how to tune it
website-README.md Snapshot of the website repo's README (setup/run reference)
PROJECT_TREE.md Auto-generated snapshot of the repo's tracked file layout

modules/

Documentation for installable game modules aggregates here rather than in each module's repo (MODULE_SYSTEM.md §2.10). The website core knows nothing about any particular game; a module is what makes it a site for one.

Doc What it covers
uo/ module-uo — the Ultima Online module: what it serves, what it owns, and what an operator needs
rust-dryrun.md A written, deliberately unimplemented module-rust — the test that the module contract generalises past the game it was extracted from
Doc What it covers
INTEGRATION.md How the website integrates with the uo-link sidecar
PROTOCOL_2.md Protocol 2.0 / 2.1 design
v3.md Protocol 3.0 design — shard content/standings streams + the visibility framework
ADMIN_CONTROLS.md Staff write-plane (kick/ban/broadcast, page queue)
SHARD_PREREQS.md Shard-side prerequisites for the bridge
PLAN.md uo-link build plan
RESEARCH.md Research notes
link-README.md Snapshot of the link repo's README
PROJECT_TREE.md Auto-generated snapshot of the repo's tracked file layout

android/

Doc What it covers
PLAN.md Android client build plan / milestones
COVERAGE_PLAN.md Test-coverage rollout plan
APP_LINKS.md Android App Links / deep-link setup
theme-plan.md Theming plan
TRUSTED_DEVICES_APP_HANDOFF.md Trusted-devices app handoff notes
PROJECT_TREE.md Auto-generated snapshot of the repo's tracked file layout

installer/

Doc What it covers
INSTALL.md Start here to set up a shard — the installer deploys the plugin overlay and the uo-link sidecar, registers the service, and connects it to the website. Appendix A is the same thing by hand, still supported
PLAN.md Installer design of record — phases, locked decisions, the bundle/compat-matrix model

Provenance

  • website/* was extracted from RunicGateway/website via git filter-repo.
  • link/* was extracted from RunicGateway/link via git filter-repo.

Commit history and authorship for each doc are preserved. The two source repos retain a short pointer to this repo in their own READMEs; the authoritative copy of each document now lives here.


License

Runic Gateway's documentation is free: licensed under the GNU General Public License v3.0 or later — see LICENSE.md.

Copyright (C) 2026 Runic Gateway

This documentation is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY. You may redistribute and/or modify it under the terms of
the GNU General Public License as published by the Free Software Foundation,
either version 3 of the License, or (at your option) any later version.

Contributions are welcome — please read CONTRIBUTING.md (note the AI-usage disclosure requirement) and our Code of Conduct.

Description
No description provided
Readme 8.4 MiB
Languages
Markdown 100%