From 914f1ae0e4113a0ab6d636b368c1c08410a9c1ba Mon Sep 17 00:00:00 2001 From: Ruben Hensen Date: Sun, 25 Jan 2026 22:54:09 +0100 Subject: [PATCH] stalwart: Add x-forwarded configmap --- stalwart/templates/configmap.yaml | 94 ++++++++++++++++++++++++++++++ stalwart/templates/deployment.yaml | 10 +++- stalwart/values.yaml | 12 ++++ 3 files changed, 115 insertions(+), 1 deletion(-) create mode 100644 stalwart/templates/configmap.yaml diff --git a/stalwart/templates/configmap.yaml b/stalwart/templates/configmap.yaml new file mode 100644 index 0000000..a824f65 --- /dev/null +++ b/stalwart/templates/configmap.yaml @@ -0,0 +1,94 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ include "stalwart.fullname" . }}-config + labels: + {{- include "stalwart.labels" . | nindent 4 }} +data: + config.toml: | + [server] + hostname = "{{ .Values.config.hostname }}" + max-connections = 8192 + allowed-ip = {{ .Values.config.allowedIPs | toJson }} + + [server.socket] + backlog = 1024 + nodelay = true + reuse-addr = true + reuse-port = true + + [server.listener.http] + bind = "[::]:8080" + protocol = "http" + + [server.listener.https] + bind = "[::]:443" + protocol = "http" + tls.implicit = true + + [server.listener.smtp] + bind = "[::]:25" + protocol = "smtp" + + [server.listener.submission] + bind = "[::]:587" + protocol = "smtp" + + [server.listener.submissions] + bind = "[::]:465" + protocol = "smtp" + tls.implicit = true + + [server.listener.imap] + bind = "[::]:143" + protocol = "imap" + + [server.listener.imaptls] + bind = "[::]:993" + protocol = "imap" + tls.implicit = true + + [server.listener.pop3] + bind = "[::]:110" + protocol = "pop3" + + [server.listener.pop3s] + bind = "[::]:995" + protocol = "pop3" + tls.implicit = true + + [server.listener.sieve] + bind = "[::]:4190" + protocol = "managesieve" + + [http] + use-x-forwarded = {{ .Values.config.useXForwarded }} + + [storage] + data = "rocksdb" + blob = "rocksdb" + fts = "rocksdb" + lookup = "rocksdb" + directory = "internal" + + [store.rocksdb] + type = "rocksdb" + path = "/opt/stalwart/data" + compression = "lz4" + + [directory.internal] + type = "internal" + store = "rocksdb" + + [authentication.fallback-admin] + user = "admin" + secret = "{{ .Values.config.adminPasswordHash }}" + + [tracer.log] + type = "log" + enable = true + level = "info" + path = "/opt/stalwart/logs" + prefix = "stalwart.log" + rotate = "daily" + ansi = false diff --git a/stalwart/templates/deployment.yaml b/stalwart/templates/deployment.yaml index 7bbc165..6b3a07e 100644 --- a/stalwart/templates/deployment.yaml +++ b/stalwart/templates/deployment.yaml @@ -11,6 +11,8 @@ spec: {{- include "stalwart.selectorLabels" . | nindent 6 }} template: metadata: + annotations: + checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} labels: {{- include "stalwart.selectorLabels" . | nindent 8 }} spec: @@ -31,7 +33,7 @@ spec: path: /healthz/ready port: 8080 initialDelaySeconds: 5 - periodSeconds: 10 + periodSeconds: 10 ports: - containerPort: 8080 - containerPort: 443 @@ -50,7 +52,13 @@ spec: volumeMounts: - name: stalwart-volume mountPath: {{ .Values.persistence.mountPath }} + - name: config + mountPath: /opt/stalwart/etc/config.toml + subPath: config.toml volumes: - name: stalwart-volume persistentVolumeClaim: claimName: {{ include "stalwart.fullname" . }} + - name: config + configMap: + name: {{ include "stalwart.fullname" . }}-config diff --git a/stalwart/values.yaml b/stalwart/values.yaml index 91d0d17..df033d2 100644 --- a/stalwart/values.yaml +++ b/stalwart/values.yaml @@ -23,3 +23,15 @@ persistence: mountPath: /opt/stalwart replicaCount: 1 + +config: + hostname: "mail.hensen.io" + # Whitelist cluster IPs to prevent ingress from being banned + allowedIPs: + - "127.0.0.1" + - "::1" + - "10.0.0.0/8" + # Trust X-Forwarded-For header from reverse proxy for real client IP + useXForwarded: true + # Admin password hash (generate with: echo -n 'password' | openssl passwd -6 -stdin) + adminPasswordHash: "$6$nUKyIdu3tyREoEza$lfXMSXAmDzokPlsXasZw6gvSKkLE/2xxC4Jp5Wq2cFA0wi1udS.lt5Kvp2EuUA7ZWNbkP7foG4BseXkIR24e40"