Please disclose if any significant portion of your mod was created using AI tools by adding the 'AI Generated' category. Failing to do so may result in the mod being removed from Thunderstore.
RunicSentinelServer
Server-only Raven's Gate admission, signed policy, enforcement, admin backend, backups, reports, and console tools without client reporting or GUI code.
| Date uploaded | 2 weeks ago |
| Version | 1.1.2 |
| Download link | Chazman-RunicSentinelServer-1.1.2.zip |
| Downloads | 140 |
| Dependency string | Chazman-RunicSentinelServer-1.1.2 |
This mod requires the following mods to function
denikson-BepInExPack_Valheim
BepInEx pack for Valheim. Preconfigured with the correct entry point for mods and preferred defaults for the community.
Preferred version: 5.4.2350Chazman-RunicSafety
Protect valuable items and world state with contextual confirmations, protected-item rules, recovery safeguards, verified backups, and compatibility checks.
Preferred version: 1.0.2README
Runic Sentinel Server 1.1.2
Choose the correct Sentinel package
- Dedicated server: install RunicSentinelServer 1.1.2 and RunicSafety.
- Administrator client or listen host: install RunicSentinel 1.4.2 for the F3 panel.
- Ordinary player: install RunicSentinelClient 1.0.1. Full Sentinel can coexist with SentinelClient.
Do not install full Sentinel and SentinelServer in the same profile. BepInEx rejects the incompatible combination and the F3 panel will not load. If you remove the server-only DLL from a client, fully exit and relaunch Valheim. Preserve existing configuration, policy, and keys.
Runic Sentinel Server is the authority-only Raven's Gate package for a dedicated server or a listen host. It verifies and signs the approved mod policy, challenges each connecting player, enforces admission and bans, accepts authenticated remote-administrator requests, creates bounded reports, and coordinates verified transition backups.
Uses BepInExPack Valheim 5.4.2350 or newer. It gates Valheim 1.0's native invite-secret handshake and backs up both legacy world files and the 1.0 chunked-world directory.
This binary contains no client profile reporter, native client-handshake resume path, administrator window, cursor control, or player-input patch. When accidentally installed in a non-authoritative client profile it watches Valheim's role selection and remains inert. Install Runic Sentinel Client there instead.
Setup
- Install this package and Runic Safety on the server. Do not install the full Runic Sentinel package alongside it; the two authority packages are intentionally incompatible.
- Start with
Remote Admission > Policy = Optional. - Add your account ID to the server's
adminlist.txt. For Steam on Valheim 1.0, useV_<SteamID64>; Sentinel also accepts raw SteamID64 andSteam_<SteamID64>. - Install full Sentinel 1.4.0 or newer on your administrator client, join, press F3, and click Set Up Sentinel once. The server verifies your account, backs up the world, and creates its own signing key and initial administrator policy without a console command. Existing policy/key files are never replaced by this setup. Ordinary players keep Runic Sentinel Client 1.0.1; they cannot claim administrator access. A listen host that wants the panel uses full Sentinel instead of this authority-only package.
- Review and sign the client profile, confirm
runic_sentinel status, then restart with Required admission when ready.
The managed private key remains under
BepInEx/config/RunicSentinel/server-private/RunicSentinel.private.key. Never distribute or package
that directory. Existing full-Sentinel policy, signature, public-key, history, report, and backup
paths are retained so switching authority packages does not fork server security state.
Server administrators inherit Sentinel access by default. Set [Administrator Access] UseServerAdminList = false on the server to require only signed Sentinel roles. Signed roles are
independent: removing someone from adminlist.txt does not remove a separately granted signed role;
remove that role in the People tab too. Signed bans take precedence. New adminlist entries are read
by Valheim on permission checks, with a roughly ten-second refresh interval. Close/reopen F3 after
editing the list. Sentinel access does not itself enable another mod's devcommands.
The manual runic_sentinel bootstrap <authority> <subject> server-console workflow remains available.
Keep admission Optional until the intended client profile has been reviewed; first-time setup is
not an automatic strict allowlist.
Required mode withholds native admission until a fresh, bounded report from the exact direct connection passes the signed server policy. A missing responder, malformed report, stale challenge, banned identity, or policy mismatch reaches a finite denial. Client-reported DLL information remains compatibility evidence from a client-controlled process, not unforgeable anti-cheat proof.
Authority preparation begins at Valheim's earliest server-role selection and binds to the exact server network instance when it is created. If authority startup fails while Required mode is selected, permanent safety gates block world loading and native client admission instead of silently running an unprotected server. Restart after correcting the logged startup error.
Remote server-cap administration
With RunicWorldEngine 1.2.x installed and enabled on this host, administrators using full RunicSentinel 1.4.0 can open F3 → Server Cap. The tab shows current players, the running cap, saved settings, and whether a restart is needed. Choose an override of 2–64 human players and click Save for Next Restart, or turn the override off to restore the vanilla limit after restart. World Engine accounts for the dedicated PlayFab host slot automatically.
The server rechecks administrator access for every request. Saves update only the two World Engine
player-cap settings, retain the previous configuration in
chazman.RunicWorldEngine.cfg.sentinel-cap.bak, and reject stale edits. Nobody is disconnected and
the host is not restarted by this action. Restart it when ready to apply the saved cap and run
World Engine's startup integrity validation. No policy signing or role changes are involved.
World Engine remains optional for other Sentinel features. This server-only package contains the cap handler, not the panel; RunicSentinelClient remains admission-only.
Questions and logs: Runic Mods Discord
CHANGELOG
1.3.0
- Added authenticated selected-player God, Ghost, Fly and No-cost controls and mode-status results.
- Added duration and intensity parameters for selected-player status effects.
- Updated character-action compatibility for RunicSentinel 1.6.0 and RunicSentinelClient 1.0.4.
1.2.0
- Integrated Server Devcommands 1.109 command and feature baseline into Sentinel; no separate Server Devcommands plugin is required.
- Added status-effect duration and intensity, command aliases/chains/waits, bindings, parameter autocomplete, command permissions and gameplay options.
- Preserved Sentinel backend administrator checks and connection-bound command requests; expanded chains authorize each executable command separately.
- Adapted Valheim 1.0 API changes; YAML configuration support is embedded in the shipped DLL.
- Command configuration files use RunicSentinel-prefixed names. Automatic devcommands is available but defaults off.
1.1.6
- Add selected-player actions through a bounded, exact-server/character RPC receiver: raise/reset skills, heal, clear food/status, adrenaline and registered status effects.
- Preserve affected-player cheat confirmation, reject replays and show acknowledged completion or failure.
1.1.5
- Repair the player roster transport with Valheim's bundled JSON serializer.
- Add authenticated native administrator/ban file changes, exact-peer kicking, file backups and role-source visibility.
- Add actual server/world metadata and recent enforcement findings.
- Generate distinct readable health/network reports and authenticated chunked downloads.
1.1.3
- Added server authorization for the F3 command dashboard, named server mod metadata, and administrator-only player reports.
- Added Server Devcommands as an installation dependency. Provider permissions remain required.
- Added per-mod language files using Valheim's selected language, with English fallback and no new plugin dependency.
Changelog
1.1.2 - 2026-09-14
- Fixed administrator connection recognition with ServerSync and Conditional Config Sync buffering sockets, including nested wrappers.
- Preserved native Steam and PlayFab identity verification without changing configuration-sync queues or permissions.
- Added specific diagnostics for unsupported socket wrappers and mismatched connections.
1.1.1 - 2026-09-14
- Fixed administrator setup rejecting Steam session-authenticated players when a connection certificate is unavailable.
- Kept authentication tied to the current connection, with session revocation and disconnect cleanup.
- Added specific connection-verification details to administrator error messages.
1.1.0 - 2026-09-12
- Added the authenticated server handler for full RunicSentinel 1.4.0's F3 Server Cap tab and RunicWorldEngine 1.2.x.
- Added running-cap, saved-cap, connected-player, and restart-status reporting.
- Added backed-up, stale-edit-protected saves for the cap override and 2–64 player limit, applied on the next restart without changing admission policy.
- Kept the server-only package free of client UI and admission-reporting code.
1.0.2 - 2026-09-10
- Added server-verified adminlist.txt access and first-time setup from the full Sentinel F3 panel.
- Added support for Steam raw, Steam_, and Valheim 1.0 V_ administrator ID formats.
- Preserved existing signed roles, bans, policies, and keys; setup leaves admission mode unchanged.
- Added an option to require signed Sentinel roles only and recheck access before cached panel responses.
1.0.1 - 2026-09-09
- Updated Required-mode admission for Valheim 1.0.7's invite-secret server handshake and reject a changed secret on the approved native resume.
- Moved the permanent fail-closed world gate to Valheim 1.0's common server-load boundary so both legacy and chunked saves are covered.
- Added complete chunked-world transition backups through Runic Safety 1.0.2's verified directory sources, with a hard 1,024-file ceiling.
- Updated the release dependency floor to BepInExPack Valheim 5.4.2350.
1.0.0 - 2026-09-09
-
Added a distinct gold-and-ember authority icon with a fortified server-network badge.
-
Added a distinct authority-only Sentinel package for dedicated servers and listen hosts.
-
Added earliest-role preparation, exact authoritative-network lifetime tracking, and permanent Required-mode world-load and native-admission gates for authority-start failures; accidental player-only installations remain inert.
-
Kept the v2 direct admission wire name compatible with Runic Sentinel Client and full Sentinel.
-
Made the server-only and full authority packages mutually incompatible.
Authority package boundary
- Compiled out client profile reporting and administrator GUI code; the dedicated package only contains authority-side handlers.
1.2.1
- Fixed private-field access exceptions that interrupted player login and periodic network updates.
- Removed local-player ghost network hooks from the dedicated server and moved optional position updates out of player-list construction.
1.2.2
- Resolve character IDs from the current peer-owned character ZDO instead of the unused legacy peer PlayerID field.
- Restore matching player-action readiness and accurate roster IDs for administrator teleport targeting.
- Keep exact connection, ownership, character-change and disconnect checks; existing Sentinel Client 1.0.3 and full Sentinel 1.5.1 remain compatible.