mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-07-21 12:57:07 +00:00
139 lines
5.6 KiB
YAML
139 lines
5.6 KiB
YAML
# Stalwart Mail Server - Helm values
|
|
#
|
|
# TLS for the mail listeners is sourced from cert-manager: the
|
|
# mail-vhaudiquet-fr-tls Secret (see certificate.yaml) is mounted into the pod
|
|
# and pushed to Stalwart by the chart's tls-sync sidecar over JMAP, which also
|
|
# calls ReloadTlsCertificates on every cert-manager renewal.
|
|
# Container image
|
|
image:
|
|
repository: stalwartlabs/stalwart
|
|
tag: v0.16.11
|
|
pullPolicy: IfNotPresent
|
|
# Single-node RocksDB deployment.
|
|
replicaCount: 1
|
|
role: ""
|
|
pushShard: ""
|
|
# Recovery / bootstrap administrator.
|
|
# The Secret (stalwart-recovery-admin) is required for the lifetime of the
|
|
# deployment because the tls-sync sidecar authenticates to Stalwart's JMAP API
|
|
# with these credentials on every cert-manager renewal.
|
|
recoveryAdmin:
|
|
enabled: true
|
|
username: ENC[AES256_GCM,data:pt9Orrg=,iv:eA8wDN4PenpCsEkYtWmPAHcpqrJsUTMxwhl3hllUIuw=,tag:EsOMXJc1efrXdFQaeFgaWw==,type:str]
|
|
password: ""
|
|
existingSecret: ENC[AES256_GCM,data:1Pc+vo6aRRMkpr9KpHxVF6OJhZP82ec=,iv:mZ56xZhvyNkHDXtYEPZBHG3D+krUstM6dDylxgFF9x8=,tag:LFHlvXUcvzbjBqsj6LT8AA==,type:str]
|
|
usernameKey: username
|
|
passwordKey: password
|
|
# Recovery mode suspends mail services and exposes only the management listener.
|
|
# Ship production values with this OFF.
|
|
recoveryMode:
|
|
enabled: false
|
|
port: 8080
|
|
logLevel: info
|
|
extraEnv: {}
|
|
extraSecretEnv: {}
|
|
# The bootstrap hook Job provisions a *fresh* domain/accounts/OIDC directory.
|
|
bootstrap:
|
|
enabled: false
|
|
# cert-manager TLS integration for the mail (SMTP/IMAP/POP3 STARTTLS + implicit
|
|
# TLS) listeners. The Secret below is produced by the Certificate in
|
|
# certificate.yaml (letsencrypt-production, Cloudflare DNS-01).
|
|
mailTls:
|
|
enabled: true
|
|
existingSecret: ENC[AES256_GCM,data:H/X/h6GSm/ji5pCyQFyCBlnwAtEKbQ==,iv:MWKRgmsGVK5UjV8rqVF/WarLICSgKlT/vXXuU76mQ6U=,tag:aUZ5tERNYVqsGPepAL6UkA==,type:str]
|
|
certKey: tls.crt
|
|
privateKeyKey: tls.key
|
|
mountPath: /etc/stalwart/tls/ingress
|
|
hostname: mail.vhaudiquet.fr
|
|
domain: vhaudiquet.fr
|
|
# How often the sidecar re-checks the mounted cert for changes.
|
|
reloadIntervalSeconds: 300
|
|
# config.json contents - ONLY the DataStore object. All other settings
|
|
# (listeners, storage backends, domains, accounts, certs) live in the database
|
|
# and are managed via JMAP/WebUI.
|
|
config:
|
|
'@type': RocksDb
|
|
path: /var/lib/stalwart
|
|
# Main Service: ClusterIP. Used by the Ingress for the management WebUI (mgmt)
|
|
# and for in-cluster access. Mail L4 ports are exposed separately via mailService.
|
|
service:
|
|
type: ClusterIP
|
|
ports:
|
|
smtp: 25
|
|
smtps: 465
|
|
submission: 587
|
|
imap: 143
|
|
imaps: 993
|
|
pop3: 110
|
|
pop3s: 995
|
|
sieve: 4190
|
|
http: 80
|
|
https: 443
|
|
mgmt: 8080
|
|
# Dedicated LoadBalancer for SMTP/IMAP/POP3/Sieve (L4). HTTP/HTTPS/mgmt are NOT
|
|
# exposed here - the WebUI is reached via the Ingress (Traefik) below.
|
|
# The WAN router NAT for 25/465/587/993/995/4190 must be repointed to this IP.
|
|
mailService:
|
|
enabled: true
|
|
name: stalwart-mail
|
|
type: LoadBalancer
|
|
loadBalancerIP: 10.1.2.143
|
|
annotations: {}
|
|
# WebUI ingress. TLS is terminated by Caddy at the edge (wildcard cert), so the
|
|
# path is: public -> Caddy (TLS) -> Traefik (HTTP) -> this Ingress -> mgmt:8080.
|
|
# No TLS block here.
|
|
ingress:
|
|
enabled: true
|
|
className: traefik
|
|
annotations: {}
|
|
hosts:
|
|
- host: mail.vhaudiquet.fr
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
portName: mgmt
|
|
tls: []
|
|
# Persistent volume for the RocksDB data directory.
|
|
persistence:
|
|
enabled: true
|
|
accessMode: ReadWriteOnce
|
|
storageClass: ""
|
|
size: 50Gi
|
|
resources:
|
|
requests:
|
|
cpu: 250m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 1Gi
|
|
# Inherit the chart's secure defaults (UID/GID 2000, non-root, RuntimeDefault
|
|
# seccomp, drop ALL caps + add NET_BIND_SERVICE for privileged mail ports).
|
|
podSecurityContext: {}
|
|
containerSecurityContext: {}
|
|
sops:
|
|
lastmodified: "2026-07-02T22:38:44Z"
|
|
mac: ENC[AES256_GCM,data:sARZquoUODSo3t9sMkONz5WX/Pzq87Nv9NQHhAsOseAgEHnBE9ZN4OvCyNGQazM5I7Qqf7DBgOjHN1/Sh4KOWMWof4NzRmMzhHFnb1Lodg42Y+p29Xvx7K233GMUWD/+FeUNlIaNzmKn/ryEweCpmijCmRqqgEf750QFX9uCAeY=,iv:AYif9HwQN7d7w90XCjWCGkRsMEXwIavkRlw8bI4jMxY=,tag:+jBKnuzWTsUZc0j7J6isoA==,type:str]
|
|
pgp:
|
|
- created_at: "2026-07-02T22:38:44Z"
|
|
enc: |-
|
|
-----BEGIN PGP MESSAGE-----
|
|
|
|
hQIMA7uy4qQr71wiAQ//WT28d0Sf2Kq1CPgXVC4XEChZe7tjXYwJTDJghj8bMfSa
|
|
xmS+5k+lEle1ZK5rbJWxuUHXbm7QXl3O76nkMNhPHa6AB/Z+wk+8+GwybN51G71r
|
|
9Lau13PmGRtX1gwLPqzbmrumfwa8U21+xo5BEKqvhz2D1hH88p66kEgoeaHjOKm5
|
|
9SFKeVpMDNPkaiiv2adX3BithXWtTCVQOJ2Fnq/f2P8ptPfv7HWk4sP3ldWk08M9
|
|
tElgt5RYSHEYnM/E3fc7Ionf27b71x/cdD4wc0YfGvY0lj4zWUSxd5KSbW5AG91K
|
|
1e7VrmnE20xRl3Dcs+/PhPJenyOaYWXm8fNIljsBcXCgLfNM/2kfta+ppr1ZE7lX
|
|
uUyYY0zyuz2/ZA9BpkGIeUIf+flmIhSON6HqurlTFCGV19+Qu2sRYFp7UOFM9Zwq
|
|
8f92eyovDPVd1NXtdkuL+HrbbQpFXFTIm1fp8bnFRD0nxZNjRT9Xd8N+Iz4U5oDv
|
|
0hgrrcUMX7FBtujMHVM8VM901Y5DZsnL6IM4cTmB2hgcaE3MvSydk7XCqtTydlX6
|
|
a/HkO03otKKRdXd0SwpJVKU5QhHU7dTs7zD7r5tUpjcaQTJd7xnsB5DIk5gZXYVg
|
|
59aEp/QlJo4UJ1ULA9AgcfwP1/NTySXiUMf9FsV4l0fwpXGQsXgc77MaOlH9/EPS
|
|
XgH0umvQpW4+eCqyOgQBfQV/Zj1JXb7AgoYy6ukhLTfBrMkJVlpxJNFHylCcQ/cI
|
|
yJHs91R1fwGjroluQhRyl94mI1HE5r4VhPIr/BYY9SslnqLsr05Nh2YhZpmBZIE=
|
|
=qjwv
|
|
-----END PGP MESSAGE-----
|
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
|
version: 3.10.2
|