Add Dovecot IMAP + Fetchmail, fix Gitea SSO, simplify credential management

- Add local Dovecot IMAP server exposed via Traefik IMAPS on port 993;
  Roundcube now connects to it internally instead of requiring manual server entry
- Add Fetchmail integration for pulling from external POP3 accounts with
  configurable per-account poll interval
- Fix Gitea SSO registration: DISABLE_REGISTRATION=false + ALLOW_ONLY_EXTERNAL_REGISTRATION
  allows Keycloak-authenticated users to get accounts while blocking public sign-up;
  disable legacy OpenID 2.0 sign-in
- Fix Keycloak post-logout redirect for Nextcloud (valid post logout redirect URI)
- Replace all pre-hashed credentials (Traefik dashboard, registry, Dovecot) with
  plaintext passwords in vault; Ansible generates deterministic bcrypt/SHA-512 hashes
  at deploy time — no more manual htpasswd commands
- Rewrite check-vault.sh with Python/PyYAML to properly validate both scalar and
  list-type secrets
- Update provisioning and configuration runbooks throughout
This commit is contained in:
ml
2026-06-28 14:13:53 +02:00
parent fdcc0079cb
commit 187c6bdea4
15 changed files with 436 additions and 116 deletions
+2 -3
View File
@@ -12,10 +12,9 @@
- "{{ registry_data_dir }}/auth"
tags: registry
# htpasswd content is stored in vault and deployed as a file
- name: Deploy htpasswd file
ansible.builtin.copy:
content: "{{ registry_htpasswd }}\n"
ansible.builtin.template:
src: htpasswd.j2
dest: "{{ registry_data_dir }}/auth/htpasswd"
owner: root
group: root
@@ -0,0 +1,4 @@
# Managed by Ansible — do not edit manually
{% for user in registry_users | default([]) %}
{{ user.username }}:{{ user.password | password_hash('bcrypt', (user.username | hash('md5'))[:22]) }}
{% endfor %}