|
|
||
|---|---|---|
| tests | ||
| .ansible-lint | ||
| .gitignore | ||
| .yamllint | ||
| ansible.cfg | ||
| mailserver.yml | ||
| mise.toml | ||
| README.md | ||
| requirements.yml | ||
ansible_playbook_mailserver
Configuration for the mail server, separate from the fleet baseline.
mise install
mise run setup
mise run check # dry run, changes nothing
ansible-playbook mailserver.yml --ask-become-pass
Why a separate playbook
Applying this restarts imapd-ssl. The baseline runs across ten hosts and
should not carry a change that interrupts mail, so the mail server gets its own
playbook and its own inventory group (dwaler/fennec#665, #670).
What it owns
courier_imap sets named keys in /usr/local/etc/courier-imap/imapd-ssl and
leaves the rest of that file alone. A package upgrade that rewrites the file is
corrected on the next run.
The settings exist because both have already failed in production. The 5.3.2 to
6.0.5 upgrade dropped SSLPIDFILE, which the startup script dereferences, and
IMAPS was down for 33 minutes. The same file carried a TLS_PROTOCOL value in a
syntax that version does not accept, which silently fell back to a TLS 1.0 floor.
Not owned
exim, fetchmail, and the certificate lifecycle.