From 47f6e7d78b794c54bbb52e69dcce49a8e8558ce4 Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 30 Sep 2026 15:13:25 +0200 Subject: [PATCH] mailu: admin asks the machine's resolver, not Mailu's own MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit admin is the one container here that reaches something by a mesh name: the database, bound in database.env. A mesh name is answered by the machine's resolver, which the runtime hands every container that does not name its own (novox/hq ADR 0148); Mailu's unbound knows no mesh name, and since the mesh stopped copying names into containers admin could not find its database. The others keep unbound — rspamd needs a validating resolver for DNSBL lookups and asks for no mesh name. --- modules/mailu/module.json | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/modules/mailu/module.json b/modules/mailu/module.json index 581595e..b7e7c60 100644 --- a/modules/mailu/module.json +++ b/modules/mailu/module.json @@ -120,7 +120,7 @@ "port": 7080, "protocol": "tcp", "from": "mesh", - "why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy" + "why": "the web front over http; only the ACME HTTP-01 passthrough is routed here — everything else 301s to https and would loop a proxy" }, { "name": "web-tls", @@ -315,10 +315,7 @@ "${dir:data-data}:/data", "${dir:data-dkim}:/dkim" ], - "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified", - "dns": [ - "192.168.203.254" - ] + "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified" }, { "id": "imap",