mailu: the manifest matches the machine, provides smtp, and carries automx
Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
# automx2 — the autoconfig/autodiscover responder, carried by the mailu module as its own
|
||||
# artifact: it is a config-baked sidecar of this mail server, not a standalone application
|
||||
# (novox/hq ADR 0015 draws that line at applications).
|
||||
#
|
||||
# The base is named rather than pinned (novox/hq issue 044): declared in module.json's
|
||||
# `build.on`. The build context is the module's own directory; every ADD says so.
|
||||
ARG PYTHON_BASE
|
||||
|
||||
FROM ${PYTHON_BASE}
|
||||
RUN apk add --no-cache bash sqlite
|
||||
WORKDIR /automx2
|
||||
|
||||
ADD automx/files/setupvenv.sh /automx2/setupvenv.sh
|
||||
ADD automx/files/start /automx2/start
|
||||
ADD automx/files/setup /automx2/setup
|
||||
ADD automx/files/setup-db /automx2/setup-db
|
||||
ADD automx/files/add-domains /automx2/add-domains
|
||||
RUN chmod u+x setupvenv.sh start add-domains setup setup-db
|
||||
|
||||
RUN ./setupvenv.sh \
|
||||
&& . .venv/bin/activate \
|
||||
&& pip install automx2
|
||||
|
||||
ENV AUTOMX2_CONF=/etc/automx2.conf
|
||||
ADD automx/files/automx2.conf /etc/automx2.conf
|
||||
|
||||
# VOLUME deliberately absent: the anonymous /data volume is exactly what lost db.sqlite on
|
||||
# every recreate (measured on novox 2026-08-10). The manifest binds a real directory instead.
|
||||
ENTRYPOINT ["/bin/sh"]
|
||||
CMD ["./start"]
|
||||
|
||||
EXPOSE 4243
|
||||
@@ -0,0 +1,49 @@
|
||||
#!/usr/bin/env bash
|
||||
set -e
|
||||
|
||||
echo "${MAIL_DOMAINS}"
|
||||
|
||||
# Split domains into array
|
||||
IFS=', ' read -r -a array <<< "${AMX_MAIL_DOMAINS}"
|
||||
|
||||
# User configurable section -- START
|
||||
PROVIDER_ID=001
|
||||
SQL_CMD="";
|
||||
|
||||
# Iterate domains resulting from split on second arg
|
||||
for element in "${array[@]}"
|
||||
do
|
||||
# Set vars
|
||||
DOMAIN=$element
|
||||
PROVIDER_NAME=$DOMAIN
|
||||
PROVIDER_SHORTNAME=$DOMAIN
|
||||
|
||||
# Optional LDAP server
|
||||
#LDAP_SERVER="ldap.${DOMAIN}"
|
||||
# User configurable section -- END
|
||||
s1_id=$((PROVIDER_ID + 1))
|
||||
s2_id=$((PROVIDER_ID + 2))
|
||||
s3_id=$((PROVIDER_ID + 3))
|
||||
dom_id=$((PROVIDER_ID + 4))
|
||||
|
||||
s3_id='NULL'
|
||||
|
||||
SQL_CMD=$(cat <<EOT
|
||||
$SQL_CMD
|
||||
INSERT INTO provider(id, name, short_name) VALUES(${PROVIDER_ID}, '${PROVIDER_NAME}', '${PROVIDER_SHORTNAME}');
|
||||
INSERT INTO server(id, port, type, name, socket_type, user_name, authentication)
|
||||
VALUES(${s1_id}, ${AMX_IMAP_PORT}, 'imap', '${AMX_IMAP_SERVER}', 'STARTTLS', '%EMAILADDRESS%', 'password-cleartext');
|
||||
INSERT INTO server(id, port, type, name, socket_type, user_name, authentication)
|
||||
VALUES(${s2_id}, ${AMX_SMTP_PORT}, 'smtp', '${AMX_SMTP_ADDRESS}', 'STARTTLS', '%EMAILADDRESS%', 'password-cleartext');
|
||||
INSERT INTO domain(id, name, provider_id, ldapserver_id) VALUES(${dom_id}, '${DOMAIN}', ${PROVIDER_ID}, ${s3_id});
|
||||
INSERT INTO server_domain(server_id, domain_id) VALUES(${s1_id}, ${dom_id});
|
||||
INSERT INTO server_domain(server_id, domain_id) VALUES(${s2_id}, ${dom_id});
|
||||
EOT
|
||||
)
|
||||
|
||||
PROVIDER_ID=$((PROVIDER_ID+10))
|
||||
|
||||
done
|
||||
|
||||
echo -e ${SQL_CMD}
|
||||
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite
|
||||
@@ -0,0 +1,21 @@
|
||||
[automx2]
|
||||
# A typical production setup would use loglevel = WARNING
|
||||
loglevel = WARNING
|
||||
# Echo SQL commands into log? Used for debugging.
|
||||
db_echo = false
|
||||
|
||||
|
||||
# In-memory SQLite database
|
||||
# db_uri = sqlite:///:memory:
|
||||
|
||||
# SQLite database in a UNIX-like file system
|
||||
db_uri = sqlite:////data/db.sqlite
|
||||
|
||||
# MySQL database on a remote server. This example does not use an encrypted
|
||||
# connection and is therefore *not* recommended for production use.
|
||||
#db_uri = mysql://username:password@server.example.com/db
|
||||
|
||||
# Number of proxy servers between automx2 and the client (default: 0).
|
||||
# If your logs only show 127.0.0.1 or ::1 as the source IP for incoming
|
||||
# connections, proxy_count probably needs to be changed.
|
||||
proxy_count = 1
|
||||
@@ -0,0 +1,12 @@
|
||||
#!/usr/bin/env bash
|
||||
set -e
|
||||
|
||||
if [ ! -e /data/db.sqlite ]; then
|
||||
# DB SETUP
|
||||
echo "SETTING UP DB"
|
||||
./setup-db
|
||||
|
||||
echo "ADDING DOMAINS"
|
||||
# Add the domains
|
||||
./add-domains
|
||||
fi
|
||||
@@ -0,0 +1,83 @@
|
||||
#!/usr/bin/env bash
|
||||
set -e
|
||||
|
||||
# LDAP-Server
|
||||
LDAP=$(cat <<EOT
|
||||
CREATE TABLE ldapserver(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
port INT NOT NULL,
|
||||
use_ssl INT NOT NULL,
|
||||
search_base TEXT NOT NULL,
|
||||
search_filter TEXT NOT NULL,
|
||||
attr_uid TEXT NOT NULL,
|
||||
attr_cn TEXT NOT NULL,
|
||||
bind_password TEXT NOT NULL,
|
||||
bind_user TEXT NOT NULL
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Provider
|
||||
PROVIDER=$(cat <<EOT
|
||||
CREATE TABLE provider(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
short_name TEXT NOT NULL
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Server
|
||||
SERVER=$(cat <<EOT
|
||||
CREATE TABLE server(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
port INT NOT NULL,
|
||||
type TEXT NOT NULL,
|
||||
socket_type TEXT NOT NULL,
|
||||
user_name TEXT NOT NULL,
|
||||
authentication TEXT NOT NULL
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Domain
|
||||
DOMAIN=$(cat <<EOT
|
||||
CREATE TABLE domain(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
provider_id INT NOT NULL,
|
||||
ldapserver_id INT NULL,
|
||||
FOREIGN KEY(ldapserver_id) REFERENCES ldapserver(id),
|
||||
FOREIGN KEY(provider_id) REFERENCES provider(id)
|
||||
);
|
||||
CREATE UNIQUE INDEX domain_name ON domain(name);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Server-Domain
|
||||
SERVER_DOMAIN=$(cat <<EOT
|
||||
CREATE TABLE server_domain(
|
||||
server_id INT NOT NULL,
|
||||
domain_id INT NOT NULL,
|
||||
FOREIGN KEY(server_id) REFERENCES server(id),
|
||||
FOREIGN KEY(domain_id) REFERENCES domain(id)
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
## TODO Foreign keys
|
||||
|
||||
SQL_CMD=$(cat <<EOT
|
||||
$LDAP
|
||||
$PROVIDER
|
||||
$SERVER
|
||||
$DOMAIN
|
||||
$SERVER_DOMAIN
|
||||
EOT
|
||||
)
|
||||
|
||||
echo -e ${SQL_CMD}
|
||||
|
||||
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite
|
||||
@@ -0,0 +1,38 @@
|
||||
#!/usr/bin/env bash
|
||||
# vim:ts=4:sw=4:noet
|
||||
#
|
||||
# Creates a Python 3 virtual environment. The target directory can be passed
|
||||
# as a parameter. The default path is '.venv' in the current directory.
|
||||
|
||||
dir="${1:-.venv}"
|
||||
echo "Setup dir $dir"
|
||||
|
||||
set -e
|
||||
if [ -d "${dir}" ]; then
|
||||
echo >&2 "Directory '${dir}' already exists, exiting."
|
||||
exit 1
|
||||
fi
|
||||
python3 -m venv "${dir}"
|
||||
source "${dir}/bin/activate"
|
||||
|
||||
set +e
|
||||
pip install -U pip setuptools wheel || true
|
||||
|
||||
#set -e
|
||||
## vim:tabstop=4:noexpandtab
|
||||
##
|
||||
## Creates a Python 3 virtual environment. The target directory can be passed
|
||||
## as a parameter. The default path is 'venv' in the current directory.
|
||||
#
|
||||
#dir="${1:-venv}"
|
||||
#
|
||||
#set -e
|
||||
#if [ -d "${dir}" ]; then
|
||||
# echo "Directory '${dir}' already exists, exiting." >&2
|
||||
# exit 1
|
||||
#fi
|
||||
#python3 -m venv "${dir}"
|
||||
#. "${dir}/bin/activate"
|
||||
#
|
||||
#set +e
|
||||
#pip install -U pip setuptools || true
|
||||
@@ -0,0 +1,8 @@
|
||||
#!/usr/bin/env bash
|
||||
set -e
|
||||
|
||||
# Setup
|
||||
./setup
|
||||
|
||||
# Start
|
||||
./.venv/scripts/flask.sh run --host=0.0.0.0 --port=4243
|
||||
Reference in New Issue
Block a user