Registration has been dead since 2026-09-13. `ssh join@bbs.profullstack.com`
creates the account, then fails at the confirmation step with "couldn't email
the code" and disconnects, so nobody can finish signing up.
Cause: Caddy owns ACME for mail.profullstack.com and renewed on 2026-08-14
(valid to Nov 12), but Mailu went on serving the certificate it loaded at
container start (Jun 15 -> Sep 13). When that lapsed, the STARTTLS handshake
from internal/mail started failing verification and every transactional send
died with it -- confirmation codes, signup notifications, credential mail.
Reproduced against production; 25/465/993 all still present the expired cert
while :443 serves the renewed one.
Three things let a single stale certificate take registration down:
- setup.sh installed the refresher and enabled its *timer*, but never ran it.
`systemctl enable --now <timer>` starts the timer, not the service, so a
redeploy left a stale cert in place (and did nothing at all if the timer was
never scheduled). The news and IRC sections already run theirs at provision
time; the Mailu section now does too, which is what repairs the live host.
- refresh-certs.sh only compared files, so a copy whose reload silently failed
left a fresh cert on disk and an expiring one on the wire -- invisible. It now
reads back what the relay actually serves, forces a reload when that disagrees
with /certs, refuses to copy a source cert that is itself expired, and no
longer swallows the `docker compose restart` failure. It restarts `front`
alone, the only container that mounts ./certs.
- internal/mail verified the relay's certificate even on loopback, where there
is nothing to intercept. It now skips verification for a loopback relay (the
reasoning docs/mail.md already applies to the plaintext Dovecot hand-off) and
gains AGENTBBS_SMTP_SERVERNAME, mirroring AGENTBBS_MAIL_SMTP_SERVERNAME, so
the documented 127.0.0.1:25 config can verify against the mail host instead of
an IP literal. A non-loopback relay is still verified. Errors are wrapped with
the address and the failing stage so the next failure is one journal line to
diagnose rather than nine days of silence.
Tests cover the envelope, the unreachable-relay message, and both halves of the
TLS decision: a loopback relay with an expired cert delivers, a non-loopback one
with the same cert is refused.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Members get a real <name>@mail.profullstack.com mailbox, served by a
co-located Mailu (Postfix+Dovecot+Roundcube+rspamd) Docker stack. Coexists
with the host Caddy: Mailu owns the mail ports; Caddy fronts the loopback
webmail and supplies the TLS cert (TLS_FLAVOR=mail), the same cert-copy
pattern as the Ergo/IRC and NNTP services.
- deploy/mailu/: docker-compose.yml, mailu.env.example, refresh-certs.sh
(copy Caddy's mail cert into Mailu on renewal), provision-mailbox.sh
(member mailbox + Dovecot gateway master user), README.
- setup.sh: MAIL flag + mail.${DOMAIN#*.} Caddy site + §9e (cert timer,
mail-port firewall, conditional compose bring-up, AGENTBBS_MAIL_* env).
- docs/mail.md: architecture, DNS (MX/SPF/DKIM/DMARC/PTR), gateway
master-user setup, env, provisioning, webmail-only policy.
Apex profullstack.com stays corporate; member mail is only on mail.*.
Infra is inspection-verified (bash -n, YAML lint); deploy pending.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>