Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
22 lines
714 B
Plaintext
22 lines
714 B
Plaintext
[automx2]
|
|
# A typical production setup would use loglevel = WARNING
|
|
loglevel = WARNING
|
|
# Echo SQL commands into log? Used for debugging.
|
|
db_echo = false
|
|
|
|
|
|
# In-memory SQLite database
|
|
# db_uri = sqlite:///:memory:
|
|
|
|
# SQLite database in a UNIX-like file system
|
|
db_uri = sqlite:////data/db.sqlite
|
|
|
|
# MySQL database on a remote server. This example does not use an encrypted
|
|
# connection and is therefore *not* recommended for production use.
|
|
#db_uri = mysql://username:password@server.example.com/db
|
|
|
|
# Number of proxy servers between automx2 and the client (default: 0).
|
|
# If your logs only show 127.0.0.1 or ::1 as the source IP for incoming
|
|
# connections, proxy_count probably needs to be changed.
|
|
proxy_count = 1
|