mailu: the manifest matches the machine, provides smtp, and carries automx
Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
#!/usr/bin/env bash
|
||||
set -e
|
||||
|
||||
# LDAP-Server
|
||||
LDAP=$(cat <<EOT
|
||||
CREATE TABLE ldapserver(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
port INT NOT NULL,
|
||||
use_ssl INT NOT NULL,
|
||||
search_base TEXT NOT NULL,
|
||||
search_filter TEXT NOT NULL,
|
||||
attr_uid TEXT NOT NULL,
|
||||
attr_cn TEXT NOT NULL,
|
||||
bind_password TEXT NOT NULL,
|
||||
bind_user TEXT NOT NULL
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Provider
|
||||
PROVIDER=$(cat <<EOT
|
||||
CREATE TABLE provider(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
short_name TEXT NOT NULL
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Server
|
||||
SERVER=$(cat <<EOT
|
||||
CREATE TABLE server(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
port INT NOT NULL,
|
||||
type TEXT NOT NULL,
|
||||
socket_type TEXT NOT NULL,
|
||||
user_name TEXT NOT NULL,
|
||||
authentication TEXT NOT NULL
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Domain
|
||||
DOMAIN=$(cat <<EOT
|
||||
CREATE TABLE domain(
|
||||
id INT PRIMARY KEY NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
provider_id INT NOT NULL,
|
||||
ldapserver_id INT NULL,
|
||||
FOREIGN KEY(ldapserver_id) REFERENCES ldapserver(id),
|
||||
FOREIGN KEY(provider_id) REFERENCES provider(id)
|
||||
);
|
||||
CREATE UNIQUE INDEX domain_name ON domain(name);
|
||||
EOT
|
||||
)
|
||||
|
||||
# Server-Domain
|
||||
SERVER_DOMAIN=$(cat <<EOT
|
||||
CREATE TABLE server_domain(
|
||||
server_id INT NOT NULL,
|
||||
domain_id INT NOT NULL,
|
||||
FOREIGN KEY(server_id) REFERENCES server(id),
|
||||
FOREIGN KEY(domain_id) REFERENCES domain(id)
|
||||
);
|
||||
EOT
|
||||
)
|
||||
|
||||
## TODO Foreign keys
|
||||
|
||||
SQL_CMD=$(cat <<EOT
|
||||
$LDAP
|
||||
$PROVIDER
|
||||
$SERVER
|
||||
$DOMAIN
|
||||
$SERVER_DOMAIN
|
||||
EOT
|
||||
)
|
||||
|
||||
echo -e ${SQL_CMD}
|
||||
|
||||
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite
|
||||
Reference in New Issue
Block a user