Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
33 lines
1.2 KiB
Docker
33 lines
1.2 KiB
Docker
# automx2 — the autoconfig/autodiscover responder, carried by the mailu module as its own
|
|
# artifact: it is a config-baked sidecar of this mail server, not a standalone application
|
|
# (novox/hq ADR 0015 draws that line at applications).
|
|
#
|
|
# The base is named rather than pinned (novox/hq issue 044): declared in module.json's
|
|
# `build.on`. The build context is the module's own directory; every ADD says so.
|
|
ARG PYTHON_BASE
|
|
|
|
FROM ${PYTHON_BASE}
|
|
RUN apk add --no-cache bash sqlite
|
|
WORKDIR /automx2
|
|
|
|
ADD automx/files/setupvenv.sh /automx2/setupvenv.sh
|
|
ADD automx/files/start /automx2/start
|
|
ADD automx/files/setup /automx2/setup
|
|
ADD automx/files/setup-db /automx2/setup-db
|
|
ADD automx/files/add-domains /automx2/add-domains
|
|
RUN chmod u+x setupvenv.sh start add-domains setup setup-db
|
|
|
|
RUN ./setupvenv.sh \
|
|
&& . .venv/bin/activate \
|
|
&& pip install automx2
|
|
|
|
ENV AUTOMX2_CONF=/etc/automx2.conf
|
|
ADD automx/files/automx2.conf /etc/automx2.conf
|
|
|
|
# VOLUME deliberately absent: the anonymous /data volume is exactly what lost db.sqlite on
|
|
# every recreate (measured on novox 2026-08-10). The manifest binds a real directory instead.
|
|
ENTRYPOINT ["/bin/sh"]
|
|
CMD ["./start"]
|
|
|
|
EXPOSE 4243
|