release: harden plugin deployment and recovery
Business Plugins CI / check (plugin-admin) (push) Successful in 1m37s
Business Plugins CI / check (subscription-admin) (push) Successful in 1m31s

This commit is contained in:
Qiufeng
2026-08-30 13:14:22 +08:00
parent ada4ab3c21
commit d3ff9be315
16 changed files with 259 additions and 50 deletions
+8 -6
View File
@@ -24,12 +24,14 @@ PLUGIN_CONFIG_KEY=local-development-secret-at-least-32-chars \
go run .
```
`PLUGIN_ALLOW_UNSIGNED=true` is a development-only switch. Production
packages must contain `signature.json`, use Ed25519, and match a trusted key
from `PLUGIN_TRUSTED_PUBLISHERS` (a JSON object of key ID to base64 public
key). `PLUGIN_CONFIG_KEY` is required in every environment; use a randomly
generated secret in production and keep it stable across restarts so encrypted
plugin configuration remains decryptable.
`PLUGIN_ALLOW_UNSIGNED=true` is a development-only switch for business package
uploads. Production `.s2plugin` packages must contain `signature.json`, use
Ed25519, and match a trusted key from `PLUGIN_TRUSTED_PUBLISHERS` (a JSON
object of key ID to base64 public key). Plugin Admin itself is deployed as a
pinned source checkout and binary, not as a `.s2plugin` package. `PLUGIN_CONFIG_KEY`
is required in every environment; use a randomly generated secret in production
and keep it stable across restarts so encrypted plugin configuration remains
decryptable.
When the optional subscription module is enabled, set `PLUGIN_PUBLIC_URL` to
the externally reachable Plugin Admin base URL (without `/admin`), for example