diff --git a/apps/stalwart/stalwart-config.yaml b/apps/stalwart/stalwart-config.yaml new file mode 100644 index 0000000..d3ff5ed --- /dev/null +++ b/apps/stalwart/stalwart-config.yaml @@ -0,0 +1,66 @@ +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: stalwart-config + namespace: stalwart +data: + stalwart.toml: | + # + # Stalwart Mail Server Configuration + # + + [store] + data = "rocksdb" + + [store.rocksdb] + type = "rocksdb" + path = "/var/lib/stalwart" + + # + # Server Configuration + # + + [server] + hostname = "mail.basicstack.de" + + # HTTP Listener (Web UI and API) + [server.listener.http] + bind = ["0.0.0.0:8080"] + protocol = "http" + + # Security: Allow internal cluster IPs for Traefik ingress + # Pod network CIDR: 10.244.0.0/16 + [server.listener.http.security] + allowed-ips = ["10.244.0.0/16", "127.0.0.1/32"] + + # SMTP Listener (Port 25) + [server.listener.smtp] + bind = ["0.0.0.0:25"] + protocol = "smtp" + + # Submission Listener (Port 587 with STARTTLS) + [server.listener.submission] + bind = ["0.0.0.0:587"] + protocol = "smtp" + + # IMAPS Listener (Port 993 with TLS) + [server.listener.imaps] + bind = ["0.0.0.0:993"] + protocol = "imap" + tls.implicit = true + + # + # TLS Configuration + # + + [server.tls] + certificate = "file:///etc/stalwart/certs/tls.crt" + private-key = "file:///etc/stalwart/certs/tls.key" + + # + # Logging + # + + [tracing.level] + default = "info" diff --git a/apps/stalwart/stalwart-fresh-deployment.yaml b/apps/stalwart/stalwart-fresh-deployment.yaml index 85326f8..8936623 100644 --- a/apps/stalwart/stalwart-fresh-deployment.yaml +++ b/apps/stalwart/stalwart-fresh-deployment.yaml @@ -128,6 +128,9 @@ spec: - name: bootstrap-config mountPath: /etc/stalwart/config.json subPath: config.json + - name: stalwart-config + mountPath: /etc/stalwart/stalwart.toml + subPath: stalwart.toml - name: tls-certs mountPath: /etc/stalwart/certs readOnly: true @@ -181,6 +184,9 @@ spec: - name: bootstrap-config configMap: name: stalwart-bootstrap-config + - name: stalwart-config + configMap: + name: stalwart-config - name: tls-certs secret: secretName: stalwart-tls