Ansible playbook for the mail server (lysithea)
Find a file
2026-09-22 18:03:10 +00:00
tests Mail server playbook 2026-09-09 18:59:22 +00:00
.ansible-lint Mail server playbook 2026-09-09 18:59:22 +00:00
.gitignore Mail server playbook 2026-09-09 18:59:22 +00:00
.yamllint Mail server playbook 2026-09-09 18:59:22 +00:00
ansible.cfg Mail server playbook 2026-09-09 18:59:22 +00:00
mailserver.yml Mail server playbook 2026-09-09 18:59:22 +00:00
mise.toml Stop the pipx virtualenvs depending on the system Python 2026-09-21 17:04:22 +00:00
README.md Mail server playbook 2026-09-09 18:59:22 +00:00
requirements.yml Bump courier_imap to v0.2.0 2026-09-09 19:11:15 +00:00

ansible_playbook_mailserver

Configuration for the mail server, separate from the fleet baseline.

mise install
mise run setup
mise run check          # dry run, changes nothing
ansible-playbook mailserver.yml --ask-become-pass

Why a separate playbook

Applying this restarts imapd-ssl. The baseline runs across ten hosts and should not carry a change that interrupts mail, so the mail server gets its own playbook and its own inventory group (dwaler/fennec#665, #670).

What it owns

courier_imap sets named keys in /usr/local/etc/courier-imap/imapd-ssl and leaves the rest of that file alone. A package upgrade that rewrites the file is corrected on the next run.

The settings exist because both have already failed in production. The 5.3.2 to 6.0.5 upgrade dropped SSLPIDFILE, which the startup script dereferences, and IMAPS was down for 33 minutes. The same file carried a TLS_PROTOCOL value in a syntax that version does not accept, which silently fell back to a TLS 1.0 floor.

Not owned

exim, fetchmail, and the certificate lifecycle.