mirror of
https://github.com/profullstack/agentbbs.git
synced 2026-08-13 14:27:27 +00:00
* ci: add mailu-update workflow to keep the mail stack current The deploy/mailu compose stack pins the floating series tags (ghcr.io/mailu/*:2024.06); patch releases within the series only land when someone runs `docker compose pull`, so the box drifts behind on security fixes. Add a scheduled (weekly) + on-demand workflow that SSHes to the droplet (reusing deploy.yml's DEPLOY_* secrets), backs up DKIM keys + the admin DB, pulls the latest images for the pinned series, recreates the containers, and health-checks the Mailu front on 127.0.0.1:8080. Shares deploy.yml's concurrency group so it never races a code deploy. Stays within the pinned series on purpose — crossing to a future series stays a deliberate PR. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: bump Forgejo to 11.0.15 + add Dependabot to keep deps current Audit of every version pin in the repo: Ergo (2.18.0), Go (1.26 → latest patch via setup-go), the Ubuntu pod base (24.04 LTS), and the GitHub Action majors are all already current. Only Forgejo was stale — bump 11.0.1 → 11.0.15 (latest patch of the 11.x LTS line; a 15.x major stays a deliberate, tested upgrade because of DB migrations). Add .github/dependabot.yml so github-actions, Go modules, and the Docker image tags (Mailu compose + pod Containerfile) get review-gated update PRs weekly. Shell-string pins (FORGEJO_VERSION/ERGO_VERSION in setup.sh) can't be watched by Dependabot; noted inline. Mailu runtime patch level is handled by the mailu-update workflow. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * mailu: document RECIPIENT_DELIMITER=+ in mailu.env.example Plus-addressing (chovy+tag@ -> chovy@) is a hard prerequisite for qaaas.dev's packages/mail but was missing from the example, so tagged mail bounces as an unknown recipient until an operator sets it by hand. Add it with a note that it governs DELIVERY only, not login (Mailu auths the exact address; base <name>@ is the single login and already receives all +tagged mail). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
66 lines
3.4 KiB
Text
66 lines
3.4 KiB
Text
# Mailu configuration — copy to deploy/mailu/mailu.env and fill the secrets.
|
|
# See docs/mail.md for the full setup (DNS, certs, gateway).
|
|
#
|
|
# Generate secrets with: openssl rand -hex 16
|
|
#
|
|
# NOTE: DOMAIN is the member ADDRESS domain (the @-part); HOSTNAMES is the mail
|
|
# SERVER host (TLS/HELO + webmail/admin/API). These deliberately differ:
|
|
# members get <name>@bbs.profullstack.com, served from mail.profullstack.com.
|
|
|
|
# --- General -----------------------------------------------------------------
|
|
SECRET_KEY=CHANGEME_16_HEX # openssl rand -hex 16
|
|
DOMAIN=bbs.profullstack.com # member addresses are <name>@bbs.profullstack.com
|
|
HOSTNAMES=mail.profullstack.com,smtp.profullstack.com
|
|
POSTMASTER=postmaster
|
|
# Apex profullstack.com is reserved for corporate mail and is NOT served here.
|
|
|
|
# Admin REST API: agentbbs auto-provisions member mailboxes through it. Mirror
|
|
# this value into the agentbbs service as AGENTBBS_MAIL_API_TOKEN.
|
|
API=true
|
|
API_TOKEN=CHANGEME_api_token # openssl rand -hex 24
|
|
|
|
# TLS_FLAVOR=mail: Mailu does NOT run its own ACME (Caddy owns :80/:443). We feed
|
|
# it certs copied from Caddy's mail.profullstack.com cert (deploy/mailu/refresh-certs.sh).
|
|
TLS_FLAVOR=mail
|
|
|
|
# --- Features ----------------------------------------------------------------
|
|
ADMIN=true # the admin UI (fronted at /admin via Caddy, internal only)
|
|
WEBMAIL=roundcube # the only member-facing surface (https://mail.profullstack.com)
|
|
WEBDAV=none
|
|
ANTIVIRUS=none # set to clamav on a 4GB+ host
|
|
ANTISPAM=true
|
|
|
|
# --- Networking --------------------------------------------------------------
|
|
# Mailu's front binds the mail ports on the host and HTTP on loopback only;
|
|
# Caddy reverse-proxies https://mail.profullstack.com to BIND_ADDRESS4:80.
|
|
BIND_ADDRESS4=127.0.0.1
|
|
SUBNET=192.168.203.0/24
|
|
MESSAGE_SIZE_LIMIT=52428800 # 50 MB
|
|
|
|
# --- Addressing --------------------------------------------------------------
|
|
# Plus-addressing (subaddressing): deliver mail sent to <name>+<tag>@ into the
|
|
# <name>@ mailbox (keeping the +tag in the To: header for filtering) instead of
|
|
# bouncing it as an unknown recipient. Required by qaaas.dev's packages/mail,
|
|
# which mints throwaway addresses like chovy+run-42@bbs.profullstack.com off the
|
|
# single chovy@ mailbox. NOTE: this affects DELIVERY only — it does NOT let
|
|
# <name>+<tag>@ be used as a LOGIN (Mailu authenticates the exact address; log
|
|
# into webmail as the base <name>@ and all +tagged mail is already there).
|
|
RECIPIENT_DELIMITER=+
|
|
|
|
# --- Gateway (the BBS reads/sends on behalf of members) ----------------------
|
|
# A Dovecot master user lets the agentbbs gateway open any member's mailbox with
|
|
# one secret (login "<name>*<master>"). Created by deploy/mailu/provision-mailbox.sh.
|
|
# Mirror these into the agentbbs service env:
|
|
# AGENTBBS_MAIL_ADDR_DOMAIN=bbs.profullstack.com
|
|
# AGENTBBS_MAIL_DOMAIN=mail.profullstack.com
|
|
# AGENTBBS_MAIL_IMAP_ADDR=mail.profullstack.com:993
|
|
# AGENTBBS_MAIL_SMTP_ADDR=127.0.0.1:25
|
|
# AGENTBBS_MAIL_ADMIN_URL=http://127.0.0.1:8080
|
|
# AGENTBBS_MAIL_API_TOKEN=<the API_TOKEN above>
|
|
# AGENTBBS_MAIL_MASTER_USER=gateway
|
|
# AGENTBBS_MAIL_MASTER_PASS=<the master password you set>
|
|
|
|
# --- Admin bootstrap ---------------------------------------------------------
|
|
INITIAL_ADMIN_ACCOUNT=admin
|
|
INITIAL_ADMIN_DOMAIN=bbs.profullstack.com
|
|
INITIAL_ADMIN_PW=CHANGEME_admin_password
|