stack.basicstack.de/apps/stalwart
CTO Agent c755bc1a45 Document SMTP/IMAP external access issue and solution options
Root cause: k3s ServiceLB assigns internal VIPs (10.42.1.x) that are not
publicly routable. External traffic to mail.basicstack.de cannot reach the
SMTP/IMAP services.

Investigation shows:
- Web-UI works (goes through Traefik IngressRoute)
- SMTP/IMAP ports have correct firewall rules
- iptables DNAT rules exist but don't help external traffic
- Internal connectivity works correctly
- LoadBalancer 'external IPs' are actually pod network IPs

Three solution options documented:
A. NodePort + iptables REDIRECT (recommended)
B. Deploy MetalLB for true LoadBalancer IPs
C. Hetzner Cloud LoadBalancers (not recommended, cost)

Awaiting approval on approach before implementing fix.

Related: DEV-235

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-13 20:00:19 +00:00
..
CERTIFICATE-RENEWAL.md Implement automatic TLS certificate renewal for Stalwart 2026-07-04 16:48:48 +00:00
ISSUE-2026-07-13-smtp-imap-external-access.md Document SMTP/IMAP external access issue and solution options 2026-07-13 20:00:19 +00:00
manual_config_steps.md apps/stalwart/manual_config_steps.md aktualisiert 2026-07-04 16:39:11 +00:00
README.md apps/stalwart/README.md aktualisiert 2026-07-04 17:19:55 +00:00
SETUP_COMPLETE.md Move Application manifests to apps root for proper self-management 2026-07-12 09:27:28 +00:00
STABILITY-CHECK.md Add comprehensive Stalwart stability check procedure 2026-07-13 19:56:35 +00:00
stalwart-admin-credentials-sealed.yaml Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
stalwart-fresh-deployment.yaml Fix Stalwart backup CronJob to handle ReadWriteOnce PVC 2026-07-11 11:21:39 +00:00
stalwart-monitoring.yaml Stalwart reliability hardening: fix k3s service networking issues 2026-07-11 11:06:36 +00:00
stalwart-s3-backup-sealed.yaml Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00

Stalwart Mail Server v0.16.11

Clean deployment of Stalwart mail server with username/password authentication only.

Architecture

  • Version: v0.16.11
  • Authentication: Username/password only (NO OAuth/OIDC)
  • Configuration: API-based (stored in RocksDB)
  • Storage: Encrypted hcloud-volumes (20Gi)
  • Backup: Daily restic backup to S3 at 3 AM
  • Web UI: https://mail.basicstack.de

Files

  • stalwart-fresh-deployment.yaml - Main deployment manifest
  • stalwart-admin-credentials-sealed.yaml - Sealed secret for admin password
  • stalwart-s3-backup-sealed.yaml - Sealed secret for S3 backup credentials

Deployment

# Apply sealed secrets first
kubectl apply -f stalwart-admin-credentials-sealed.yaml
kubectl apply -f stalwart-s3-backup-sealed.yaml

# Create bootstrap config
kubectl create configmap stalwart-bootstrap-config \
  --from-literal=config.json='{"@type":"RocksDb","path":"/var/lib/stalwart"}' \
  -n stalwart

# Deploy Stalwart
kubectl apply -f stalwart-fresh-deployment.yaml

Initial Admin Login

After deployment, log in at https://mail.basicstack.de with:

  • Username: admin
  • Password: (from stalwart-admin-credentials secret)

Configuration

All configuration is done via the web UI or API. The bootstrap config only points to the RocksDB database location. NO config.toml files are used.

Check https://stalw.art/docs/ref/ for configuration possibilities. The API access via /jmap seems to be too complex for the agent and the configruation has been done manually.

Refer to manual configuration steps

Ports

  • SMTP: 25, 587, 465
  • IMAP: 143, 993
  • HTTP: 8080 (web UI)

Storage

Data is stored in /var/lib/stalwart using the RocksDB database format. This includes:

  • Email messages
  • User accounts
  • Server configuration
  • TLS certificates configuration

Certificate Renewal

Refer to Automatic Renewal TLS Certificate