Add Dovecot IMAP + Fetchmail, fix Gitea SSO, simplify credential management

- Add local Dovecot IMAP server exposed via Traefik IMAPS on port 993;
  Roundcube now connects to it internally instead of requiring manual server entry
- Add Fetchmail integration for pulling from external POP3 accounts with
  configurable per-account poll interval
- Fix Gitea SSO registration: DISABLE_REGISTRATION=false + ALLOW_ONLY_EXTERNAL_REGISTRATION
  allows Keycloak-authenticated users to get accounts while blocking public sign-up;
  disable legacy OpenID 2.0 sign-in
- Fix Keycloak post-logout redirect for Nextcloud (valid post logout redirect URI)
- Replace all pre-hashed credentials (Traefik dashboard, registry, Dovecot) with
  plaintext passwords in vault; Ansible generates deterministic bcrypt/SHA-512 hashes
  at deploy time — no more manual htpasswd commands
- Rewrite check-vault.sh with Python/PyYAML to properly validate both scalar and
  list-type secrets
- Update provisioning and configuration runbooks throughout
This commit is contained in:
ml
2026-06-28 14:13:53 +02:00
parent fdcc0079cb
commit 187c6bdea4
15 changed files with 436 additions and 116 deletions
@@ -20,8 +20,14 @@ services:
# Security
- GITEA__security__SECRET_KEY={{ gitea_secret_key }}
- GITEA__security__INTERNAL_TOKEN={{ gitea_internal_token }}
# Disable public registration — set to false only for initial admin setup
- GITEA__service__DISABLE_REGISTRATION={{ gitea_disable_registration | lower }}
# Allow account creation only via external auth (OAuth2/SSO).
# DISABLE_REGISTRATION=false is explicit because the setup wizard writes true to app.ini;
# ALLOW_ONLY_EXTERNAL_REGISTRATION then hides the sign-up form so only SSO accounts work.
- GITEA__service__DISABLE_REGISTRATION=false
- GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION=true
# Disable legacy OpenID 2.0 sign-in (distinct from the Keycloak OAuth2 integration)
- GITEA__openid__ENABLE_OPENID_SIGNIN=false
- GITEA__openid__ENABLE_OPENID_SIGNUP=false
volumes:
- {{ gitea_data_dir }}/data:/data
ports: