mailu: the manifest matches the machine, provides smtp, and carries automx
Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
[automx2]
|
||||
# A typical production setup would use loglevel = WARNING
|
||||
loglevel = WARNING
|
||||
# Echo SQL commands into log? Used for debugging.
|
||||
db_echo = false
|
||||
|
||||
|
||||
# In-memory SQLite database
|
||||
# db_uri = sqlite:///:memory:
|
||||
|
||||
# SQLite database in a UNIX-like file system
|
||||
db_uri = sqlite:////data/db.sqlite
|
||||
|
||||
# MySQL database on a remote server. This example does not use an encrypted
|
||||
# connection and is therefore *not* recommended for production use.
|
||||
#db_uri = mysql://username:password@server.example.com/db
|
||||
|
||||
# Number of proxy servers between automx2 and the client (default: 0).
|
||||
# If your logs only show 127.0.0.1 or ::1 as the source IP for incoming
|
||||
# connections, proxy_count probably needs to be changed.
|
||||
proxy_count = 1
|
||||
Reference in New Issue
Block a user