Files
amqp-email-forwarder/module.json
T
jschoubben 90eeb082ef Become a nox mesh module: smtp granted, the shared channel accepted
The mailu smtp grant replaces the hand-carried mailbox credential — the
module contributes account amqp-forwarder and composes its login from
the binding, the de-spiegel pattern. The AMQP side stays the operator's
on purpose: EMAILDELIVERY_T is a vhost external publishers share, which
the consumer-owned-vhost provision deliberately cannot express, so the
URL rides as an accepted secret. Built from source; the old image's
registry no longer exists.
2026-09-26 19:23:13 +02:00

66 lines
1.9 KiB
JSON

{
"module": "amqp-email-forwarder",
"version": "1",
"slug": "forwarder",
"capabilities": [
"container-runtime"
],
"requires": [
"smtp"
],
"contributes": {
"smtp": {
"account": "amqp-forwarder"
}
},
"binds": {
"smtp": "${dir:state}/smtp.json"
},
"secrets": {
"smtp": "${dir:state}/smtp.secret"
},
"own-secrets": {
"amqp-url": "${dir:state}/amqp-url.secret"
},
"resources": [
{
"id": "state",
"type": "directory",
"place": ".",
"mode": "0700"
},
{
"id": "env",
"type": "file",
"path": "${dir:state}/forwarder.env",
"mode": "0600",
"content": "AMQP_URL=${secret:amqp-url}\nAMQP_EXCHANGE=News.TransactionalEmailing.Command\nAMQP_QUEUE=email-forwarder\nSMTP_HOST=${bound:smtp:at}\nSMTP_PORT=${bound:smtp:port}\nSMTP_USER=amqp-forwarder@${bound:smtp:domain}\nSMTP_PASSWORD=${secret:smtp}\nNOTIFY_FROM=amqp-forwarder@${bound:smtp:domain}\nNOTIFY_TO=jochen.schoubben@mediahuis.be\n"
},
{
"id": "server",
"type": "container",
"name": "amqp-email-forwarder",
"artifact": "server",
"env-file": [
"${dir:state}/forwarder.env"
],
"secrets-in-environment": "the application reads AMQP_URL and SMTP_PASSWORD from the environment (app.js); converting is this repository's change. The AMQP credential is the operator's: the EMAILDELIVERY_T vhost is a channel external publishers share, which the consumer-owned-vhost amqp provision deliberately cannot express, so the mesh carries the credential as an accepted secret rather than minting one nobody else would know"
}
],
"build": {
"on": [
{
"arg": "NODE_BASE",
"image": "node@sha256:0a7108bf6c7bf5de370ffb1a3ed6be93d405b43ff159f681a8d18c0e2bc2e402"
}
],
"artifacts": [
{
"name": "server",
"kind": "image",
"from": "Dockerfile"
}
]
}
}