mailu: the manifest matches the machine, provides smtp, and carries automx #73

Merged
jschoubben merged 1 commits from feat/mailu-becomes-real into main 2026-09-25 20:40:08 +00:00
Owner

The pre-work half of MAILU-CUTOVER.md (migration repo) — every change verified against the live stack, not the draft:

Five draft-vs-reality gaps closed:

  1. front published bare 80 (Traefik's port) → the predecessor's own 7080:80/7443:443 plus the dropped 110/143/995 parity ports.
  2. TLS_FLAVOR=cert (nothing supplies files) → letsencrypt, matching the live self-renewing certbot; its HTTP-01 answered through a path-scoped route contribution (priority above the web route).
  3. The web route said http:7080 — the redirect-loop shape; now https 7443, insecure (route-proxy PR #64's capability).
  4. automx existed only in HAL: now a second artifact (Containerfile moved in, base declared per ADR 0097, the anonymous-volume dataloss fix preserved as a bound dir), plus the three autoconfig names as route contributions.
  5. provides: smtp — the reason mailu moved ahead of de-spiegel. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API, applies the minted password every reconcile (ADR 0048), and the domain rides on the binding so consumers compose their own login from mesh facts. de-spiegel's nox-mesh branch already consumes it.

route-adapter learns to say no (tested, 9/9): contributions over https, path-scoped, or policy-carrying are skipped aloud — the file shape cannot say them, and plain-http-into-a-TLS-listener is the concrete wrong file this prevents. Hand-authored files keep covering those routes until route-proxy takes over.

Known limitation, written in the provisioner: withdrawal of a named-account consumer is an operator action — the harness's remove carries only the mesh login, and a mailbox holding mail is not a thing a background loop guesses about.

The cutover itself (secrets carried, admindb pg13→17 into the mesh store, stopped window, verify list, rollback) is planned in MAILU-CUTOVER.md and does not run until this is merged, built, and the operator says go.

The pre-work half of `MAILU-CUTOVER.md` (migration repo) — every change verified against the live stack, not the draft: **Five draft-vs-reality gaps closed:** 1. `front` published bare `80` (Traefik's port) → the predecessor's own `7080:80`/`7443:443` plus the dropped 110/143/995 parity ports. 2. `TLS_FLAVOR=cert` (nothing supplies files) → `letsencrypt`, matching the live self-renewing certbot; its HTTP-01 answered through a path-scoped route contribution (priority above the web route). 3. The web route said `http:7080` — the redirect-loop shape; now `https 7443, insecure` (route-proxy PR #64's capability). 4. automx existed only in HAL: now a second artifact (Containerfile moved in, base declared per ADR 0097, the anonymous-volume dataloss fix preserved as a bound dir), plus the three autoconfig names as route contributions. 5. **`provides: smtp`** — the reason mailu moved ahead of de-spiegel. A consumer contributes the account it sends as; the provisioner creates `<account>@<domain>` via the admin API, applies the minted password every reconcile (ADR 0048), and the domain rides on the binding so consumers compose their own login from mesh facts. de-spiegel's nox-mesh branch already consumes it. **route-adapter learns to say no** (tested, 9/9): contributions over https, path-scoped, or policy-carrying are skipped aloud — the file shape cannot say them, and plain-http-into-a-TLS-listener is the concrete wrong file this prevents. Hand-authored files keep covering those routes until route-proxy takes over. Known limitation, written in the provisioner: withdrawal of a named-account consumer is an operator action — the harness's `remove` carries only the mesh login, and a mailbox holding mail is not a thing a background loop guesses about. The cutover itself (secrets carried, admindb pg13→17 into the mesh store, stopped window, verify list, rollback) is planned in `MAILU-CUTOVER.md` and does not run until this is merged, built, and the operator says go.
jschoubben added 1 commit 2026-09-25 20:39:58 +00:00
Five gaps between the draft and what actually runs, each verified live
before being written down:

- front published bare 80 — the machine port Traefik holds; now the
  predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995
  parity ports the draft dropped. Pruning legacy protocols is its own
  deliberate change, not a cutover side effect.
- TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt —
  mailu runs its own certbot, state already on disk, HTTP-01 answered
  through a path-scoped route contribution (priority above the web one).
- the web route said http:7080, the redirect-loop shape; it now says
  what the hand-authored file always knew: https 7443, insecure.
- automx was absent entirely: the autoconfig responder is now a second
  artifact (its Containerfile moved in from the predecessor's images
  dir, base declared per ADR 0097), a container on a real data dir —
  the anonymous-volume loss of 2026-08-10 stays fixed — and the three
  public names are route contributions.
- and the reason this moved ahead of de-spiegel: mailu now provides
  smtp. A consumer contributes the account it sends as; the provisioner
  creates <account>@<domain> via the admin API and applies the minted
  password every reconcile (ADR 0048). The domain is served on the
  binding so a consumer composes its own login from mesh facts.

route-adapter learns to say no: a contribution over https, scoped to a
path, or carrying a policy is skipped aloud rather than written into a
file shape that cannot say it — plain http into a TLS listener was the
concrete wrong file this prevents. The hand-authored files keep covering
those routes until the mesh's own proxy takes over, exactly as today.
jschoubben merged commit a708666bad into main 2026-09-25 20:40:08 +00:00
jschoubben deleted branch feat/mailu-becomes-real 2026-09-25 20:40:08 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#73