Skip to content

Replace the legacy Minecraft stack with verified one-command setup - #15

Merged
Silthus merged 13 commits into
mainfrom
modernize/agent-ready-template
Oct 1, 2026
Merged

Silthus merged 13 commits into
mainfrom
modernize/agent-ready-template

Conversation

@Silthus

@Silthus Silthus commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

The old 1.17/Waterfall deployment failed to launch because its Compose command/fragments were broken, initialization could report success after EOF, and backup credentials could be empty. This replaces it with one pinned Compose file and ./scripts/minecraft setup --accept-eula --start, which requires explicit EULA acceptance and waits for real Minecraft health and authenticated RCON.

The default is stable Paper 26.2 build 129 on Java 25. Minecraft's current release is 26.3, offered as actually validated standalone Vanilla through --distribution vanilla. Optional profiles retain modern authenticated Velocity forwarding, MariaDB, consistent encrypted world backups and loopback static file/download serving. Backend, SQL, RCON and debug ports are unpublished; protected generated secrets and worlds survive repeat setup and upgrades. Managed pins/project identity resist inherited environment overrides. The derived backup image applies one exact checked readiness patch so overlapping jobs cannot resume saves before taking the shared lock; actual Restic failures return nonzero with redacted output.

Final verification

Latest HEAD CI is green on ba921f8e36198e7d63aeaa7d55134cdbb62ba4cf: local, official-version verification and native AMD64 full Docker execution, with successful artifact uploads. The full gate passes 45 runtime assertions plus nine focused CLI/config cases on both native ARM64 and AMD64. It proves pinned Paper/Vanilla/Velocity artifacts, actual protocol/RCON, persistent scoreboard recreation, separate restored-world boot, genuine forwarded client play and denial probes, real Restic failure/save recovery, safe overlapping jobs, literal MOTDs, SQL authentication/persistence, web serving and protected cleanup.

The fresh final independent review confirms no unresolved findings. It distinguishes the initially reviewed 5cd63b7 from final 1b6a5ee, independently reran 45 full assertions plus nine CLI cases and 14 cold-image assertions plus nine CLI cases, and checked real backup pin transitions, image context exclusions and incompatible-base patch-guard failure. Executable/build hashes still match 1b6a5ee; this final commit adds documentation/proof only.

The single-prompt source-blind execution used archive 5cd63b7 with only the shipped skill, START/docs and CLI help, plus explicit disposable EULA consent. Without clarification or implementation/test/review access, it completed setup, live status/RCON, scheduled/manual snapshots and scoped cleanup. That lane did not request restoration; full gates separately prove recovery.

Validation report, source identity, committed AMD64 proof, preserved original failures, setup skill. Selected independent evidence is redacted and linked; fixtures, generated state, secret values, unrelated inventories and repetitive dumps are omitted.

Reproduce from a fresh checkout:

./scripts/validate local --output /tmp/minecraft-local-proof
./scripts/check-versions > /tmp/minecraft-version-proof.json
./scripts/validate fullDocker --output /tmp/minecraft-runtime-proof

Migration and limits

Retired Waterfall/Bungee wiring, bundled Plan/mapping/web assets, public admin/SQL helpers and fragile fragments are removed. Current plugin/config drop-ins, optional database and static mapping/download output have documented replacements. Migration lists old paths and a backup/restore rehearsal; no production data is migrated automatically. Operations covers backup, restore, upgrades and security.

Arbitrary plugins, production 1.17 migrations, SQL/off-host recovery, public DNS/ACME and completed real-account Mojang login are not certified. Disposable forwarding play temporarily uses offline account authentication while retaining authenticated forwarding, then restores production online authentication. A scheduled startup snapshot and six-hour interval were observed; no elapsed six-hour tick is claimed.

Independent review and all runtime lanes are complete; deployments are cleaned. This PR is ready for Michael's explicit final go. No merge or auto-merge is enabled.

@Silthus
Silthus marked this pull request as ready for review October 1, 2026 08:11
@Silthus
Silthus merged commit 44d36e9 into main Oct 1, 2026
5 checks passed
@Silthus
Silthus deleted the modernize/agent-ready-template branch October 1, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant