stack.basicstack.de/apps/stalwart/stalwart-bootstrap-completion-guide.md
CTO Agent f981b3e269 Initialize CD/CI repository structure with Stalwart example
Set up the repository structure following GitOps principles:
- apps/ for application deployments (Stalwart as example)
- infrastructure/ for cluster-wide configs (networking, monitoring)
- docs/ for general documentation

Migrated complete Stalwart deployment configuration including:
- Multiple deployment variants (basic, OIDC-enabled)
- Helm values files
- Monitoring and dashboard configurations
- Operational documentation (backup/restore, bootstrap)
- Configuration patches and fixes

Added comprehensive README files at each level to guide future use.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-01 18:08:31 +00:00

5.4 KiB

Stalwart 0.16 Bootstrap Wizard Completion Guide

Current Status

  • Pod running: stalwart-0 in namespace stalwart
  • JMAP API accessible (tested)
  • OIDC credentials prepared in Kubernetes secret
  • Bootstrap wizard awaiting completion

Bootstrap Access Credentials

URL: https://mail.basicstack.de/admin
Username: admin
Password: YFMySjQYfMB3tYZa

Note

: These credentials are valid only until the bootstrap wizard is completed, then they will be automatically disabled.

OIDC Configuration Details

Retrieved from Kubernetes secret stalwart-oidc in namespace stalwart:

Client ID: 0f37a0e3-8d3b-4413-a394-36226f42a980
Client Secret: LPo8VejJXznisTQ87TGAs4Ad0Typ1MJw
Issuer URL: https://auth.basicstack.de
Redirect URI: https://mail.basicstack.de/admin/oauth/callback
Scopes: openid profile email

Step-by-Step Bootstrap Wizard Completion

Step 1: Access Bootstrap Interface

  1. Open browser to: https://mail.basicstack.de/admin
  2. Login with bootstrap credentials:
    • Username: admin
    • Password: YFMySjQYfMB3tYZa

Step 2: Configure Data Store

The wizard should show the data store configuration. This is likely auto-configured:

  • Type: RocksDB
  • Path: /opt/stalwart-mail/data

Verify the settings and proceed.

Step 3: Set Up OIDC Authentication

Configure OAuth/OIDC provider with these exact settings:

Field Value
Provider Name Pocket ID
Issuer URL https://auth.basicstack.de
Client ID 0f37a0e3-8d3b-4413-a394-36226f42a980
Client Secret LPo8VejJXznisTQ87TGAs4Ad0Typ1MJw
Redirect URI https://mail.basicstack.de/admin/oauth/callback
Scopes openid profile email

Authorization Endpoint (auto-discovered): https://auth.basicstack.de/api/oidc/authorize
Token Endpoint (auto-discovered): https://auth.basicstack.de/api/oidc/token
UserInfo Endpoint (auto-discovered): https://auth.basicstack.de/api/oidc/userinfo

Choose Option A (recommended): Link to Pocket ID user

  • When prompted, link the admin account to a Pocket ID user
  • The Pocket ID OIDC client is already configured with group restrictions
  • Only users in the Stalwart-admin group can access

If the wizard requires creating an internal admin first:

  • Create a temporary internal admin
  • Link it to OIDC
  • The bootstrap password login will be automatically disabled after setup

Step 5: Disable Password Authentication (if prompted)

  • Web UI Authentication: OIDC only
  • Mail Client Authentication: Uses internal directory (separate from web UI auth)

This ensures the web admin interface only accepts OIDC login while mail clients continue to work normally.

Step 6: Complete Setup

  1. Review all configuration
  2. Click "Complete Setup" or equivalent final button
  3. The system will:
    • Save configuration to RocksDB
    • Exit bootstrap mode
    • Disable the bootstrap credentials
    • Enable OIDC authentication

Step 7: Verify OIDC Login

  1. Log out from the bootstrap session
  2. Access https://mail.basicstack.de/admin again
  3. Click "Login with Pocket ID" or the OAuth login button
  4. Should redirect to https://auth.basicstack.de for authentication
  5. After successful Pocket ID login, should return to Stalwart admin interface

Post-Bootstrap Verification

Run these commands to verify the configuration:

# Check pod is still running
export KUBECONFIG=/paperclip/instances/default/workspaces/b4536334-39f2-4e05-b2f1-bb0e4670fba8/k3s.kubeconfig
/paperclip/instances/default/workspaces/b4536334-39f2-4e05-b2f1-bb0e4670fba8/bin/kubectl get pods -n stalwart

# Test JMAP API (should still work with OIDC credentials now)
curl -s -X POST https://mail.basicstack.de/jmap \
  -H "Content-Type: application/json" \
  -d '{"using":["urn:ietf:params:jmap:core"],"methodCalls":[["Core/echo",{"test":"post-bootstrap"},"0"]]}'

# Verify management API is now accessible
curl -s https://mail.basicstack.de/api/session

Troubleshooting

Issue: Cannot access bootstrap UI

  • Verify pod is running: kubectl get pods -n stalwart
  • Check pod logs: kubectl logs stalwart-0 -n stalwart
  • Verify ingress: kubectl get ingress -n stalwart

Issue: OIDC login not working after setup

  • Check Stalwart logs for OAuth errors
  • Verify redirect URI matches exactly
  • Confirm user is in Stalwart-admin group in Pocket ID
  • Test Pocket ID OIDC client directly

Issue: Bootstrap credentials don't work

  • Pod may have been restarted and new credentials generated
  • Check parent issue DEV-155 for any updates
  • May need to restart the pod or check the deployment

Security Notes

  • Bootstrap credentials automatically expire after setup completion
  • OIDC client secret is stored in Kubernetes secret stalwart-oidc
  • Access restricted to Stalwart-admin group members only
  • All communication over HTTPS/TLS

References

  • Parent Issue: DEV-155
  • OIDC Client configured in Pocket ID (client ID: 0f37a0e3-8d3b-4413-a394-36226f42a980)
  • User Group: Stalwart-admin (group ID: 99ffc3ae-0112-4fa0-bec9-90da19bdaddd)
  • Pocket ID: https://auth.basicstack.de
  • Stalwart: https://mail.basicstack.de

Acceptance Criteria Checklist

  • Bootstrap setup wizard completed
  • OIDC authentication configured with Pocket ID
  • Can login to web UI via Pocket ID
  • Password login disabled for web UI
  • Bootstrap mode exited
  • Configuration saved to RocksDB
  • Management API responding (not "no available server")