The pre-work half of MAILU-CUTOVER.md (migration repo) — every change verified against the live stack, not the draft:
Five draft-vs-reality gaps closed:
front published bare 80 (Traefik's port) → the predecessor's own 7080:80/7443:443 plus the dropped 110/143/995 parity ports.
TLS_FLAVOR=cert (nothing supplies files) → letsencrypt, matching the live self-renewing certbot; its HTTP-01 answered through a path-scoped route contribution (priority above the web route).
The web route said http:7080 — the redirect-loop shape; now https 7443, insecure (route-proxy PR #64's capability).
automx existed only in HAL: now a second artifact (Containerfile moved in, base declared per ADR 0097, the anonymous-volume dataloss fix preserved as a bound dir), plus the three autoconfig names as route contributions.
provides: smtp — the reason mailu moved ahead of de-spiegel. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API, applies the minted password every reconcile (ADR 0048), and the domain rides on the binding so consumers compose their own login from mesh facts. de-spiegel's nox-mesh branch already consumes it.
route-adapter learns to say no (tested, 9/9): contributions over https, path-scoped, or policy-carrying are skipped aloud — the file shape cannot say them, and plain-http-into-a-TLS-listener is the concrete wrong file this prevents. Hand-authored files keep covering those routes until route-proxy takes over.
Known limitation, written in the provisioner: withdrawal of a named-account consumer is an operator action — the harness's remove carries only the mesh login, and a mailbox holding mail is not a thing a background loop guesses about.
The cutover itself (secrets carried, admindb pg13→17 into the mesh store, stopped window, verify list, rollback) is planned in MAILU-CUTOVER.md and does not run until this is merged, built, and the operator says go.
The pre-work half of `MAILU-CUTOVER.md` (migration repo) — every change verified against the live stack, not the draft:
**Five draft-vs-reality gaps closed:**
1. `front` published bare `80` (Traefik's port) → the predecessor's own `7080:80`/`7443:443` plus the dropped 110/143/995 parity ports.
2. `TLS_FLAVOR=cert` (nothing supplies files) → `letsencrypt`, matching the live self-renewing certbot; its HTTP-01 answered through a path-scoped route contribution (priority above the web route).
3. The web route said `http:7080` — the redirect-loop shape; now `https 7443, insecure` (route-proxy PR #64's capability).
4. automx existed only in HAL: now a second artifact (Containerfile moved in, base declared per ADR 0097, the anonymous-volume dataloss fix preserved as a bound dir), plus the three autoconfig names as route contributions.
5. **`provides: smtp`** — the reason mailu moved ahead of de-spiegel. A consumer contributes the account it sends as; the provisioner creates `<account>@<domain>` via the admin API, applies the minted password every reconcile (ADR 0048), and the domain rides on the binding so consumers compose their own login from mesh facts. de-spiegel's nox-mesh branch already consumes it.
**route-adapter learns to say no** (tested, 9/9): contributions over https, path-scoped, or policy-carrying are skipped aloud — the file shape cannot say them, and plain-http-into-a-TLS-listener is the concrete wrong file this prevents. Hand-authored files keep covering those routes until route-proxy takes over.
Known limitation, written in the provisioner: withdrawal of a named-account consumer is an operator action — the harness's `remove` carries only the mesh login, and a mailbox holding mail is not a thing a background loop guesses about.
The cutover itself (secrets carried, admindb pg13→17 into the mesh store, stopped window, verify list, rollback) is planned in `MAILU-CUTOVER.md` and does not run until this is merged, built, and the operator says go.
Five gaps between the draft and what actually runs, each verified live
before being written down:
- front published bare 80 — the machine port Traefik holds; now the
predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995
parity ports the draft dropped. Pruning legacy protocols is its own
deliberate change, not a cutover side effect.
- TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt —
mailu runs its own certbot, state already on disk, HTTP-01 answered
through a path-scoped route contribution (priority above the web one).
- the web route said http:7080, the redirect-loop shape; it now says
what the hand-authored file always knew: https 7443, insecure.
- automx was absent entirely: the autoconfig responder is now a second
artifact (its Containerfile moved in from the predecessor's images
dir, base declared per ADR 0097), a container on a real data dir —
the anonymous-volume loss of 2026-08-10 stays fixed — and the three
public names are route contributions.
- and the reason this moved ahead of de-spiegel: mailu now provides
smtp. A consumer contributes the account it sends as; the provisioner
creates <account>@<domain> via the admin API and applies the minted
password every reconcile (ADR 0048). The domain is served on the
binding so a consumer composes its own login from mesh facts.
route-adapter learns to say no: a contribution over https, scoped to a
path, or carrying a policy is skipped aloud rather than written into a
file shape that cannot say it — plain http into a TLS listener was the
concrete wrong file this prevents. The hand-authored files keep covering
those routes until the mesh's own proxy takes over, exactly as today.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The pre-work half of
MAILU-CUTOVER.md(migration repo) — every change verified against the live stack, not the draft:Five draft-vs-reality gaps closed:
frontpublished bare80(Traefik's port) → the predecessor's own7080:80/7443:443plus the dropped 110/143/995 parity ports.TLS_FLAVOR=cert(nothing supplies files) →letsencrypt, matching the live self-renewing certbot; its HTTP-01 answered through a path-scoped route contribution (priority above the web route).http:7080— the redirect-loop shape; nowhttps 7443, insecure(route-proxy PR #64's capability).provides: smtp— the reason mailu moved ahead of de-spiegel. A consumer contributes the account it sends as; the provisioner creates<account>@<domain>via the admin API, applies the minted password every reconcile (ADR 0048), and the domain rides on the binding so consumers compose their own login from mesh facts. de-spiegel's nox-mesh branch already consumes it.route-adapter learns to say no (tested, 9/9): contributions over https, path-scoped, or policy-carrying are skipped aloud — the file shape cannot say them, and plain-http-into-a-TLS-listener is the concrete wrong file this prevents. Hand-authored files keep covering those routes until route-proxy takes over.
Known limitation, written in the provisioner: withdrawal of a named-account consumer is an operator action — the harness's
removecarries only the mesh login, and a mailbox holding mail is not a thing a background loop guesses about.The cutover itself (secrets carried, admindb pg13→17 into the mesh store, stopped window, verify list, rollback) is planned in
MAILU-CUTOVER.mdand does not run until this is merged, built, and the operator says go.