Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
83 lines
1.4 KiB
Bash
83 lines
1.4 KiB
Bash
#!/usr/bin/env bash
|
|
set -e
|
|
|
|
# LDAP-Server
|
|
LDAP=$(cat <<EOT
|
|
CREATE TABLE ldapserver(
|
|
id INT PRIMARY KEY NOT NULL,
|
|
name TEXT NOT NULL,
|
|
port INT NOT NULL,
|
|
use_ssl INT NOT NULL,
|
|
search_base TEXT NOT NULL,
|
|
search_filter TEXT NOT NULL,
|
|
attr_uid TEXT NOT NULL,
|
|
attr_cn TEXT NOT NULL,
|
|
bind_password TEXT NOT NULL,
|
|
bind_user TEXT NOT NULL
|
|
);
|
|
EOT
|
|
)
|
|
|
|
# Provider
|
|
PROVIDER=$(cat <<EOT
|
|
CREATE TABLE provider(
|
|
id INT PRIMARY KEY NOT NULL,
|
|
name TEXT NOT NULL,
|
|
short_name TEXT NOT NULL
|
|
);
|
|
EOT
|
|
)
|
|
|
|
# Server
|
|
SERVER=$(cat <<EOT
|
|
CREATE TABLE server(
|
|
id INT PRIMARY KEY NOT NULL,
|
|
name TEXT NOT NULL,
|
|
port INT NOT NULL,
|
|
type TEXT NOT NULL,
|
|
socket_type TEXT NOT NULL,
|
|
user_name TEXT NOT NULL,
|
|
authentication TEXT NOT NULL
|
|
);
|
|
EOT
|
|
)
|
|
|
|
# Domain
|
|
DOMAIN=$(cat <<EOT
|
|
CREATE TABLE domain(
|
|
id INT PRIMARY KEY NOT NULL,
|
|
name TEXT NOT NULL,
|
|
provider_id INT NOT NULL,
|
|
ldapserver_id INT NULL,
|
|
FOREIGN KEY(ldapserver_id) REFERENCES ldapserver(id),
|
|
FOREIGN KEY(provider_id) REFERENCES provider(id)
|
|
);
|
|
CREATE UNIQUE INDEX domain_name ON domain(name);
|
|
EOT
|
|
)
|
|
|
|
# Server-Domain
|
|
SERVER_DOMAIN=$(cat <<EOT
|
|
CREATE TABLE server_domain(
|
|
server_id INT NOT NULL,
|
|
domain_id INT NOT NULL,
|
|
FOREIGN KEY(server_id) REFERENCES server(id),
|
|
FOREIGN KEY(domain_id) REFERENCES domain(id)
|
|
);
|
|
EOT
|
|
)
|
|
|
|
## TODO Foreign keys
|
|
|
|
SQL_CMD=$(cat <<EOT
|
|
$LDAP
|
|
$PROVIDER
|
|
$SERVER
|
|
$DOMAIN
|
|
$SERVER_DOMAIN
|
|
EOT
|
|
)
|
|
|
|
echo -e ${SQL_CMD}
|
|
|
|
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite |