The mailu smtp grant replaces the hand-carried mailbox credential — the module contributes account amqp-forwarder and composes its login from the binding, the de-spiegel pattern. The AMQP side stays the operator's on purpose: EMAILDELIVERY_T is a vhost external publishers share, which the consumer-owned-vhost provision deliberately cannot express, so the URL rides as an accepted secret. Built from source; the old image's registry no longer exists.
66 lines
1.9 KiB
JSON
66 lines
1.9 KiB
JSON
{
|
|
"module": "amqp-email-forwarder",
|
|
"version": "1",
|
|
"slug": "forwarder",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"smtp"
|
|
],
|
|
"contributes": {
|
|
"smtp": {
|
|
"account": "amqp-forwarder"
|
|
}
|
|
},
|
|
"binds": {
|
|
"smtp": "${dir:state}/smtp.json"
|
|
},
|
|
"secrets": {
|
|
"smtp": "${dir:state}/smtp.secret"
|
|
},
|
|
"own-secrets": {
|
|
"amqp-url": "${dir:state}/amqp-url.secret"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"place": ".",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "env",
|
|
"type": "file",
|
|
"path": "${dir:state}/forwarder.env",
|
|
"mode": "0600",
|
|
"content": "AMQP_URL=${secret:amqp-url}\nAMQP_EXCHANGE=News.TransactionalEmailing.Command\nAMQP_QUEUE=email-forwarder\nSMTP_HOST=${bound:smtp:at}\nSMTP_PORT=${bound:smtp:port}\nSMTP_USER=amqp-forwarder@${bound:smtp:domain}\nSMTP_PASSWORD=${secret:smtp}\nNOTIFY_FROM=amqp-forwarder@${bound:smtp:domain}\nNOTIFY_TO=jochen.schoubben@mediahuis.be\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "amqp-email-forwarder",
|
|
"artifact": "server",
|
|
"env-file": [
|
|
"${dir:state}/forwarder.env"
|
|
],
|
|
"secrets-in-environment": "the application reads AMQP_URL and SMTP_PASSWORD from the environment (app.js); converting is this repository's change. The AMQP credential is the operator's: the EMAILDELIVERY_T vhost is a channel external publishers share, which the consumer-owned-vhost amqp provision deliberately cannot express, so the mesh carries the credential as an accepted secret rather than minting one nobody else would know"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "NODE_BASE",
|
|
"image": "node@sha256:0a7108bf6c7bf5de370ffb1a3ed6be93d405b43ff159f681a8d18c0e2bc2e402"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|