The mesh-mailu container goes with its Dockerfile, the mesh-tools build bases and its bus credential; automx keeps its own image. The code reached the admin API by its name on the mailu network, which a process on the machine cannot, so the admin container publishes 8080 to this machine only and the bundle reaches it on loopback at that port. Mail is still read through docker exec into mailu-imap, so the runtime's account needs the docker socket as nextcloud's does.
mailu
Mail — Mailu, with its provisioner (the smtp provision) and tools, on the tool runtime.
Settings
A definition names no mesh (novox/hq ADR 0112, ADR 0155), so the values that are this
installation's are settings on the assignment, settings set mailu <file>:
{"domain": "…", "sitename": "…", "website": "https://…", "proxy-address": "…"}
domain is the mail domain (also the provisioner's, for a consumer's address); sitename and
website are shown by the web front; proxy-address is what REAL_IP_FROM trusts a real-IP
header from — the address the proxy forwards with. The front's own hostname is the name of its
web route, told to it by the mesh.