Add Dovecot IMAP + Fetchmail, fix Gitea SSO, simplify credential management
- Add local Dovecot IMAP server exposed via Traefik IMAPS on port 993; Roundcube now connects to it internally instead of requiring manual server entry - Add Fetchmail integration for pulling from external POP3 accounts with configurable per-account poll interval - Fix Gitea SSO registration: DISABLE_REGISTRATION=false + ALLOW_ONLY_EXTERNAL_REGISTRATION allows Keycloak-authenticated users to get accounts while blocking public sign-up; disable legacy OpenID 2.0 sign-in - Fix Keycloak post-logout redirect for Nextcloud (valid post logout redirect URI) - Replace all pre-hashed credentials (Traefik dashboard, registry, Dovecot) with plaintext passwords in vault; Ansible generates deterministic bcrypt/SHA-512 hashes at deploy time — no more manual htpasswd commands - Rewrite check-vault.sh with Python/PyYAML to properly validate both scalar and list-type secrets - Update provisioning and configuration runbooks throughout
This commit is contained in:
@@ -12,10 +12,9 @@
|
||||
- "{{ registry_data_dir }}/auth"
|
||||
tags: registry
|
||||
|
||||
# htpasswd content is stored in vault and deployed as a file
|
||||
- name: Deploy htpasswd file
|
||||
ansible.builtin.copy:
|
||||
content: "{{ registry_htpasswd }}\n"
|
||||
ansible.builtin.template:
|
||||
src: htpasswd.j2
|
||||
dest: "{{ registry_data_dir }}/auth/htpasswd"
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
# Managed by Ansible — do not edit manually
|
||||
{% for user in registry_users | default([]) %}
|
||||
{{ user.username }}:{{ user.password | password_hash('bcrypt', (user.username | hash('md5'))[:22]) }}
|
||||
{% endfor %}
|
||||
Reference in New Issue
Block a user