Add Dovecot IMAP + Fetchmail, fix Gitea SSO, simplify credential management
- Add local Dovecot IMAP server exposed via Traefik IMAPS on port 993; Roundcube now connects to it internally instead of requiring manual server entry - Add Fetchmail integration for pulling from external POP3 accounts with configurable per-account poll interval - Fix Gitea SSO registration: DISABLE_REGISTRATION=false + ALLOW_ONLY_EXTERNAL_REGISTRATION allows Keycloak-authenticated users to get accounts while blocking public sign-up; disable legacy OpenID 2.0 sign-in - Fix Keycloak post-logout redirect for Nextcloud (valid post logout redirect URI) - Replace all pre-hashed credentials (Traefik dashboard, registry, Dovecot) with plaintext passwords in vault; Ansible generates deterministic bcrypt/SHA-512 hashes at deploy time — no more manual htpasswd commands - Rewrite check-vault.sh with Python/PyYAML to properly validate both scalar and list-type secrets - Update provisioning and configuration runbooks throughout
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
# Managed by Ansible — do not edit manually
|
||||
set postmaster "postmaster"
|
||||
set bouncemail
|
||||
set logfile /dev/stdout
|
||||
# Wake up every 60 seconds; each server's 'interval' is a multiplier of this
|
||||
set daemon 60
|
||||
|
||||
{% for account in fetchmail_accounts | default([]) %}
|
||||
poll {{ account.server }} proto {{ account.protocol | default('pop3') }}{% if account.ssl | default(true) %} ssl{% endif %}
|
||||
|
||||
user "{{ account.username }}" password "{{ account.password }}"
|
||||
is {{ account.local_user }} here
|
||||
smtphost dovecot
|
||||
smtpport 24
|
||||
lmtp
|
||||
fetchall
|
||||
{{ 'keep' if account.keep | default(true) else 'no keep' }}
|
||||
interval {{ account.poll_minutes | default(10) }}
|
||||
|
||||
{% endfor %}
|
||||
Reference in New Issue
Block a user