Five gaps between the draft and what actually runs, each verified live before being written down: - front published bare 80 — the machine port Traefik holds; now the predecessor's own mappings (7080:80, 7443:443) plus the 110/143/995 parity ports the draft dropped. Pruning legacy protocols is its own deliberate change, not a cutover side effect. - TLS_FLAVOR said cert, which nothing supplies; live is letsencrypt — mailu runs its own certbot, state already on disk, HTTP-01 answered through a path-scoped route contribution (priority above the web one). - the web route said http:7080, the redirect-loop shape; it now says what the hand-authored file always knew: https 7443, insecure. - automx was absent entirely: the autoconfig responder is now a second artifact (its Containerfile moved in from the predecessor's images dir, base declared per ADR 0097), a container on a real data dir — the anonymous-volume loss of 2026-08-10 stays fixed — and the three public names are route contributions. - and the reason this moved ahead of de-spiegel: mailu now provides smtp. A consumer contributes the account it sends as; the provisioner creates <account>@<domain> via the admin API and applies the minted password every reconcile (ADR 0048). The domain is served on the binding so a consumer composes its own login from mesh facts. route-adapter learns to say no: a contribution over https, scoped to a path, or carrying a policy is skipped aloud rather than written into a file shape that cannot say it — plain http into a TLS listener was the concrete wrong file this prevents. The hand-authored files keep covering those routes until the mesh's own proxy takes over, exactly as today.
50 lines
1.5 KiB
Bash
50 lines
1.5 KiB
Bash
#!/usr/bin/env bash
|
|
set -e
|
|
|
|
echo "${MAIL_DOMAINS}"
|
|
|
|
# Split domains into array
|
|
IFS=', ' read -r -a array <<< "${AMX_MAIL_DOMAINS}"
|
|
|
|
# User configurable section -- START
|
|
PROVIDER_ID=001
|
|
SQL_CMD="";
|
|
|
|
# Iterate domains resulting from split on second arg
|
|
for element in "${array[@]}"
|
|
do
|
|
# Set vars
|
|
DOMAIN=$element
|
|
PROVIDER_NAME=$DOMAIN
|
|
PROVIDER_SHORTNAME=$DOMAIN
|
|
|
|
# Optional LDAP server
|
|
#LDAP_SERVER="ldap.${DOMAIN}"
|
|
# User configurable section -- END
|
|
s1_id=$((PROVIDER_ID + 1))
|
|
s2_id=$((PROVIDER_ID + 2))
|
|
s3_id=$((PROVIDER_ID + 3))
|
|
dom_id=$((PROVIDER_ID + 4))
|
|
|
|
s3_id='NULL'
|
|
|
|
SQL_CMD=$(cat <<EOT
|
|
$SQL_CMD
|
|
INSERT INTO provider(id, name, short_name) VALUES(${PROVIDER_ID}, '${PROVIDER_NAME}', '${PROVIDER_SHORTNAME}');
|
|
INSERT INTO server(id, port, type, name, socket_type, user_name, authentication)
|
|
VALUES(${s1_id}, ${AMX_IMAP_PORT}, 'imap', '${AMX_IMAP_SERVER}', 'STARTTLS', '%EMAILADDRESS%', 'password-cleartext');
|
|
INSERT INTO server(id, port, type, name, socket_type, user_name, authentication)
|
|
VALUES(${s2_id}, ${AMX_SMTP_PORT}, 'smtp', '${AMX_SMTP_ADDRESS}', 'STARTTLS', '%EMAILADDRESS%', 'password-cleartext');
|
|
INSERT INTO domain(id, name, provider_id, ldapserver_id) VALUES(${dom_id}, '${DOMAIN}', ${PROVIDER_ID}, ${s3_id});
|
|
INSERT INTO server_domain(server_id, domain_id) VALUES(${s1_id}, ${dom_id});
|
|
INSERT INTO server_domain(server_id, domain_id) VALUES(${s2_id}, ${dom_id});
|
|
EOT
|
|
)
|
|
|
|
PROVIDER_ID=$((PROVIDER_ID+10))
|
|
|
|
done
|
|
|
|
echo -e ${SQL_CMD}
|
|
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite
|