Add Dovecot IMAP + Fetchmail, fix Gitea SSO, simplify credential management
- Add local Dovecot IMAP server exposed via Traefik IMAPS on port 993; Roundcube now connects to it internally instead of requiring manual server entry - Add Fetchmail integration for pulling from external POP3 accounts with configurable per-account poll interval - Fix Gitea SSO registration: DISABLE_REGISTRATION=false + ALLOW_ONLY_EXTERNAL_REGISTRATION allows Keycloak-authenticated users to get accounts while blocking public sign-up; disable legacy OpenID 2.0 sign-in - Fix Keycloak post-logout redirect for Nextcloud (valid post logout redirect URI) - Replace all pre-hashed credentials (Traefik dashboard, registry, Dovecot) with plaintext passwords in vault; Ansible generates deterministic bcrypt/SHA-512 hashes at deploy time — no more manual htpasswd commands - Rewrite check-vault.sh with Python/PyYAML to properly validate both scalar and list-type secrets - Update provisioning and configuration runbooks throughout
This commit is contained in:
@@ -47,7 +47,7 @@ services:
|
||||
- "traefik.http.routers.sso.entrypoints=websecure"
|
||||
- "traefik.http.routers.sso.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.services.sso.loadbalancer.server.port=8080"
|
||||
- "traefik.http.routers.sso.middlewares=rate-limit@docker"
|
||||
- "traefik.http.routers.sso.middlewares=rate-limit-lax@docker"
|
||||
healthcheck:
|
||||
test: ["CMD", "bash", "-c", "exec 3<>/dev/tcp/localhost/9000"]
|
||||
interval: 30s
|
||||
|
||||
Reference in New Issue
Block a user