Add Dovecot IMAP + Fetchmail, fix Gitea SSO, simplify credential management
- Add local Dovecot IMAP server exposed via Traefik IMAPS on port 993; Roundcube now connects to it internally instead of requiring manual server entry - Add Fetchmail integration for pulling from external POP3 accounts with configurable per-account poll interval - Fix Gitea SSO registration: DISABLE_REGISTRATION=false + ALLOW_ONLY_EXTERNAL_REGISTRATION allows Keycloak-authenticated users to get accounts while blocking public sign-up; disable legacy OpenID 2.0 sign-in - Fix Keycloak post-logout redirect for Nextcloud (valid post logout redirect URI) - Replace all pre-hashed credentials (Traefik dashboard, registry, Dovecot) with plaintext passwords in vault; Ansible generates deterministic bcrypt/SHA-512 hashes at deploy time — no more manual htpasswd commands - Rewrite check-vault.sh with Python/PyYAML to properly validate both scalar and list-type secrets - Update provisioning and configuration runbooks throughout
This commit is contained in:
@@ -12,10 +12,9 @@
|
||||
- "{{ registry_data_dir }}/auth"
|
||||
tags: registry
|
||||
|
||||
# htpasswd content is stored in vault and deployed as a file
|
||||
- name: Deploy htpasswd file
|
||||
ansible.builtin.copy:
|
||||
content: "{{ registry_htpasswd }}\n"
|
||||
ansible.builtin.template:
|
||||
src: htpasswd.j2
|
||||
dest: "{{ registry_data_dir }}/auth/htpasswd"
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
Reference in New Issue
Block a user