stack.basicstack.de/apps/stalwart
CTO Agent ae3f164987 fix(stalwart): Add externalTrafficPolicy: Local to LoadBalancer services
Root cause: ArgoCD continuously reverts the LoadBalancer services to use
externalTrafficPolicy: Cluster (the k8s default), causing k3s to assign
internal flannel VXLAN IPs (10.42.1.x) instead of the node public IPs.

With externalTrafficPolicy: Cluster, traffic can be routed to any node,
and k3s's service controller assigns the flannel overlay IPs. This breaks
external connectivity because those IPs are not routable from outside.

With externalTrafficPolicy: Local, traffic is only routed to pods on the
same node, and k3s assigns the node's actual public IP to the LoadBalancer.

This was the missing piece from the reliability hardening in commit b0f2acf.
Without this in git, any manual kubectl patch is reverted by ArgoCD sync.

Evidence: stalwart-smtp and stalwart-imap both showing LoadBalancer IPs:
10.42.1.1, 10.42.1.2, 10.42.1.3, 10.42.1.5 (internal flannel IPs)

Related: DEV-230, DEV-231, DEV-233, DEV-235

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-13 20:03:49 +00:00
..
CERTIFICATE-RENEWAL.md Implement automatic TLS certificate renewal for Stalwart 2026-07-04 16:48:48 +00:00
ISSUE-2026-07-13-smtp-imap-external-access.md Document SMTP/IMAP external access issue and solution options 2026-07-13 20:00:19 +00:00
manual_config_steps.md apps/stalwart/manual_config_steps.md aktualisiert 2026-07-04 16:39:11 +00:00
README.md apps/stalwart/README.md aktualisiert 2026-07-04 17:19:55 +00:00
SETUP_COMPLETE.md Move Application manifests to apps root for proper self-management 2026-07-12 09:27:28 +00:00
STABILITY-CHECK.md Add comprehensive Stalwart stability check procedure 2026-07-13 19:56:35 +00:00
stalwart-admin-credentials-sealed.yaml Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
stalwart-fresh-deployment.yaml fix(stalwart): Add externalTrafficPolicy: Local to LoadBalancer services 2026-07-13 20:03:49 +00:00
stalwart-monitoring.yaml Stalwart reliability hardening: fix k3s service networking issues 2026-07-11 11:06:36 +00:00
stalwart-s3-backup-sealed.yaml Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00

Stalwart Mail Server v0.16.11

Clean deployment of Stalwart mail server with username/password authentication only.

Architecture

  • Version: v0.16.11
  • Authentication: Username/password only (NO OAuth/OIDC)
  • Configuration: API-based (stored in RocksDB)
  • Storage: Encrypted hcloud-volumes (20Gi)
  • Backup: Daily restic backup to S3 at 3 AM
  • Web UI: https://mail.basicstack.de

Files

  • stalwart-fresh-deployment.yaml - Main deployment manifest
  • stalwart-admin-credentials-sealed.yaml - Sealed secret for admin password
  • stalwart-s3-backup-sealed.yaml - Sealed secret for S3 backup credentials

Deployment

# Apply sealed secrets first
kubectl apply -f stalwart-admin-credentials-sealed.yaml
kubectl apply -f stalwart-s3-backup-sealed.yaml

# Create bootstrap config
kubectl create configmap stalwart-bootstrap-config \
  --from-literal=config.json='{"@type":"RocksDb","path":"/var/lib/stalwart"}' \
  -n stalwart

# Deploy Stalwart
kubectl apply -f stalwart-fresh-deployment.yaml

Initial Admin Login

After deployment, log in at https://mail.basicstack.de with:

  • Username: admin
  • Password: (from stalwart-admin-credentials secret)

Configuration

All configuration is done via the web UI or API. The bootstrap config only points to the RocksDB database location. NO config.toml files are used.

Check https://stalw.art/docs/ref/ for configuration possibilities. The API access via /jmap seems to be too complex for the agent and the configruation has been done manually.

Refer to manual configuration steps

Ports

  • SMTP: 25, 587, 465
  • IMAP: 143, 993
  • HTTP: 8080 (web UI)

Storage

Data is stored in /var/lib/stalwart using the RocksDB database format. This includes:

  • Email messages
  • User accounts
  • Server configuration
  • TLS certificates configuration

Certificate Renewal

Refer to Automatic Renewal TLS Certificate