minecraft-server/scripts
s8n 3336f52142 redact: scrub leaked Minecraft secrets from public repo
Replaced literal values with env-var placeholders (${RCON_PASSWORD},
${MGMT_SECRET}, ${MC_RCON_PASSWORD}) across server.properties,
.rcon-cli.env, docker-compose.yml(s), backup scripts, and AUDIT-2026-05-07.md.

Affected secrets:
- Paper management-server-secret (HIGH; mitigated by management-server-enabled=false)
- RCON password '*redacted*' (MEDIUM; bound to 127.0.0.1)
- MC_RCON_PASSWORD backup-pipeline default fallback (MEDIUM; same blast radius)

WARNING: HEAD redaction only — values remain in git history. Treat as
compromised and rotate (closes F-17 audit-finding's deferred TODO).
Originals backed up to private s8n/secrets/minecraft-server/.
2026-05-08 15:36:20 +01:00
..
systemd backup: phase 1 + phase 2 scripts; daily script repaired and deployed 2026-05-07 18:29:30 +01:00
backup.sh redact: scrub leaked Minecraft secrets from public repo 2026-05-08 15:36:20 +01:00
restic-backup-playerdata.sh backup: phase 1 + phase 2 scripts; daily script repaired and deployed 2026-05-07 18:29:30 +01:00
restic-init.sh redact: scrub leaked Minecraft secrets from public repo 2026-05-08 15:36:20 +01:00
test-default-perms.sh docs+pat: fix default-rank /help and Homestead claim flow 2026-05-07 18:19:26 +01:00