4 Commits

Author SHA1 Message Date
b3cb6bf1eb Merge pull request 'fix(docs): clear the quickstart drift the upstream fixes caused' (#11) from fix/quickstart-drift-and-installer-note into main
Some checks failed
PR checks / checks (push) Has been cancelled
Reviewed-on: #11
Reviewed-by: Colby Whitlock <whitlocktech@gmail.com>
2026-08-24 17:32:49 +00:00
e8cb6061fe fix(facts): installer v0.1.1 is released, so the note names a version
All checks were successful
PR checks / checks (pull_request) Successful in 9m22s
Recovering installer's orphan tag published v0.1.1, which moved the platform
under this branch and turned checkFacts red -- the check working exactly as it
should, since a version this site quotes had changed.

  FAIL  release installer
        platform.json says : v0.1.0
        installer releases/latest says : v0.1.1

The 500 that orphaned the tag was a race with the tag push one second earlier,
not a structural failure: re-running the workflow took the built-in orphan-tag
recovery path and published all four assets unchanged.

So the stale-path Aside stops saying "v0.1.0 is still the current download",
which is no longer true, and says the durable thing instead -- v0.1.0 prints
the old path, v0.1.1 prints the real one -- which stays correct however many
releases follow. platform.json and the PLAN.md version table move to v0.1.1,
and the phase 7 findings record the pipeline defect as a fourth finding.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-24 11:50:38 -05:00
a993b872ac fix(docs): clear the quickstart drift the upstream fixes caused
All checks were successful
PR checks / checks (pull_request) Successful in 1m1s
The three defects phase 7 found are fixed and merged: website#163
(SECRET_ENC_KEY missing from the root .env.example, plus BOT_INTERNAL_KEY in
the README's "set at least" list) and installer#22 + docs#174 (the handoff
printing /admin/shard).

website#163 turned checkQuickstart red here, which is precisely what the
declaration was built to do -- it fails the moment a declared key appears
upstream, so the note describing the omission cannot outlive the defect. The
SECRET_ENC_KEY entry is deleted and notInUpstreamEnvExample is now empty; the
export stays so the next divergence gets an entry rather than passing quietly.

The stale-path Aside on Connect a game server is pinned to v0.1.0 rather than
calling the installer permanently wrong, and now says WHY the old path is worse
than a 404: the SPA has no route for it, so it redirects to the dashboard and
the link looks like it worked.

v0.1.0 is still the current download, and not only because releases lag. The
release run for installer#22 built every artifact and pushed tag v0.1.1, then
took a 500 creating the release -- so the tag is orphaned and no binaries were
published. Raised on installer; nothing is worked around here.

This also recovers 084ee0b, which was pushed to feat/phase-7-docs after PR #10
had already merged f499f2b, and so never reached main.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-24 11:39:36 -05:00
bcb633403f Merge pull request 'docs(journey): phase 7 — the installation path and administration' (#10) from feat/phase-7-docs into main
All checks were successful
PR checks / checks (push) Successful in 1m7s
Reviewed-on: #10
2026-08-24 15:24:18 +00:00
4 changed files with 34 additions and 24 deletions

17
PLAN.md
View File

@@ -86,7 +86,7 @@ All values re-read from the Gitea API on **2026-08-19**, after revision 1.
| **Current bundle** | **2026.08.19** (protocol 4, generated 09:05:52Z) | `installer` branch `bundles` → `current.json` |
| uo-link sidecar | **v2.0.0** (2026-08-19) | release; in bundle 2026.08.19 |
| Plugin overlay | **v1.0.0** (2026-08-19) | release; in bundle 2026.08.19 |
| Installer | **v0.1.0** (2026-08-07) | release |
| Installer | **v0.1.1** (2026-08-24) | release |
| `module-uo` | **v1.0.1** (2026-08-19) | release |
| Android app | **v0.5.0** (2026-08-08), id `com.runicgateway.app` | release; `app/build.gradle.kts` |
| ServUO | **57.4** — min version, and the only version the patch tier is verified against | bundle `overlay.servuo` |
@@ -909,16 +909,21 @@ Hero editor into Branding and theming, Web Bot Activity into Authentication.
it is **missing from website's root `.env.example`**, the file Compose actually reads. It is
present in `server/.env.example`, which is the file local development copies, which is why this
has never bitten anyone in dev. The quickstart carries it, declared as an upstream omission so the
check fails the day it is fixed — **fixed in website#163**, which also adds `BOT_INTERNAL_KEY` to
the README's "set at least" list for the same reason. When that merges, `checkQuickstart` goes red
here by design and the declaration is deleted in a one-line follow-up.
check fails the day it is fixed. **Fixed in website#163** (merged 2026-08-24), which also adds
`BOT_INTERNAL_KEY` to the README's "set at least" list — required in production even on a
deployment running no bot. The declaration did exactly what it was built to do: this repo went red
on the next run, and the entry is deleted here.
- **The installer points operators at a screen that no longer exists.** It prints
`<site>/admin/shard`, and INSTALL.md §5 repeats it. Since the module-system cutover a module owns
one path segment, and the screen is **`/admin/uo/link`**, labelled *Shard (uo-link)*. The old path
does not even 404 — the SPA sends the operator to the dashboard, so the link looks like it worked
and the four values have nowhere to go. **Fixed in installer#22** (the path is a named constant and
both handoff tests assert it) **and docs#174**; the journey names the real path and pins the note to
v0.1.0, which is what operators download until the next release.
both handoff tests assert it) **and docs#174**, both merged 2026-08-24, and shipped in installer
**v0.1.1**. Getting there found a fourth defect, in `installer`'s release pipeline: the run for the
fix built every artifact and pushed tag `v0.1.1`, then took a `500` from `POST /releases` one
second later, leaving an orphan tag and no binaries. Re-running the workflow published it — the
failure was a race with the tag push, not a structural one — so the note here names v0.1.0 as the
version that prints the old path rather than describing the installer as currently wrong.
- **The admin "Restart the server" button opens a `window.confirm`.** Its text is the honest
warning that a deployment with no supervisor does not come back — which is exactly why
`restart: unless-stopped` is called out as load-bearing on the install page rather than left as

View File

@@ -107,10 +107,16 @@ sidebar — `/admin/uo/link`. Tick *Enable the shard integration*, paste **Base
immediately.
<Aside type="caution" title="Installer v0.1.0 prints an older path for that screen">
It prints `…/admin/shard`. Since the shard screens became part of the `uo` module — and a
module owns one path segment wherever it appears — the screen moved to **`/admin/uo/link`**.
The old path does not fail visibly: the site sends you to the dashboard, which looks like the
link worked. Use the sidebar, or the path above. Fixed for the next release.
v0.1.0 prints `…/admin/shard`. Since the shard screens became part of the `uo` module — and
a module owns one path segment wherever it appears — the screen moved to
**`/admin/uo/link`**.
The old path does not fail visibly: the site has no route for it, so it sends you to the
dashboard, and that looks like the link worked. The four values you were just told to paste
then have nowhere to go. Use the sidebar, or the path above.
Fixed in **v0.1.1**, which prints the real path. Only matters if you are running the older
binary.
</Aside>
The token is encrypted at rest and **never returned to any client** — losing it means

View File

@@ -27,7 +27,7 @@
"releases": {
"link": "v2.0.0",
"installer": "v0.1.0",
"installer": "v0.1.1",
"Module-uo": "v1.0.1",
"Android-app": "v0.5.0"
},

View File

@@ -110,22 +110,21 @@ export const env = [
];
/**
* `SECRET_ENC_KEY` is in this quickstart and NOT in upstream's `.env.example`, which is why
* it needs a declaration rather than passing quietly.
* Keys this quickstart sets that upstream's `.env.example` does not, each with the reason.
*
* Found by booting this exact file against the published image (phase 7): the server calls
* `resolveKey()` in `utils/secretBox.js` at require time and throws
* `SECRET_ENC_KEY must be set in production`, so the container crash-loops before it ever
* listens. It is documented in `server/.env.example` — the file local development copies —
* and missing from the root `.env.example` that Compose actually reads.
* **Empty, and that is the point.** Its one entry was `SECRET_ENC_KEY`: phase 7 booted this
* exact file against the published image and the container crash-looped before it ever
* listened, because `resolveKey()` in `utils/secretBox.js` throws
* `SECRET_ENC_KEY must be set in production` at require time. The variable was documented in
* `server/.env.example` — the file local development copies — and missing from the root
* `.env.example` that Compose actually reads.
*
* The check treats the omission as upstream's bug, not as licence: it fails the moment the
* variable appears in `.env.example`, so this note cannot outlive the defect it describes.
* The declaration was written so it could not outlive the defect: the check fails the moment
* a declared key appears upstream. website#163 fixed `.env.example`, this repo went red on
* the next run, and the entry was deleted. Keep the export — the next divergence gets an
* entry here rather than passing quietly.
*/
export const notInUpstreamEnvExample = {
SECRET_ENC_KEY:
"the app refuses to start in production without it (utils/secretBox.js), but website's root .env.example does not list it",
};
export const notInUpstreamEnvExample = {};
/**
* Variables upstream's `.env.example` carries that the quickstart leaves out, each with the