The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in, serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to the journal and declare a jail reading it by container name. The base is strict: three in a day for a day, twice banned in two weeks for four; the mesh's range stays never banned.
mailu
Mail — Mailu, with its provisioner (the smtp provision) and tools, on the tool runtime.
Settings
A definition names no mesh (novox/hq ADR 0112, ADR 0155), so the values that are this
installation's are settings on the assignment, settings set mailu <file>:
{"domain": "…", "sitename": "…", "website": "https://…", "proxy-address": "…"}
domain is the mail domain (also the provisioner's, for a consumer's address); sitename and
website are shown by the web front; proxy-address is what REAL_IP_FROM trusts a real-IP
header from — the address the proxy forwards with. The front's own hostname is the name of its
web route, told to it by the mesh.