feat(mail-admin): read-only account view for mail.produktor.io (#74)

- admin/: Go stdlib-only HTTP viewer, lists accounts from
  config/postfix-accounts.cf with per-mailbox message counts (INBOX and
  total, same numbers doveadm reports) and storage; quota from
  dovecot-quotas.cf; Basic Auth from .env; offline tests vs fixtures
  (go test -race ./...)
- compose: mail-admin service, build admin/Dockerfile, publishes
  127.0.0.1:19945 / 172.17.0.1:19945; config and mail-data mounted :ro,
  no docker socket
- NPM proxy host 66: location /admin/ -> 172.17.0.1:19945
- README: account admin section
This commit is contained in:
2026-09-01 15:07:55 +01:00
parent e00c6950ed
commit 5a46ba4b33
22 changed files with 790 additions and 0 deletions
+32
View File
@@ -7,6 +7,7 @@ Docker Compose mail stack for `mail.produktor.io` on arc-01, based on
|---------|-----------|-------|
| Mail server (DMS) | `mailserver` | 25 (SMTP), 465 (SMTPS), 587 (Submission STARTTLS), 143 (IMAP STARTTLS), 993 (IMAPS) |
| Webmail (Roundcube) | `webmail` | 127.0.0.1:19944 / 172.17.0.1:19944 (HTTP, behind NPM) |
| Account admin (read-only) | `mail-admin` | 127.0.0.1:19945 / 172.17.0.1:19945 (HTTP, behind NPM) |
## Accounts
@@ -56,6 +57,37 @@ The webmail stores its sqlite database (addressbook, settings) in
`data/roundcube/db/`. `ROUNDCUBEMAIL_DES_KEY` (session encryption) must be set
in `.env` — compose fails without it.
## Account admin (read-only view)
The `mail-admin` service is a small Go (stdlib-only) HTTP viewer for **all**
accounts at once: **https://mail.produktor.io/admin/** (HTTP Basic Auth, NPM
proxy host 66, location `/admin/` → `172.17.0.1:19945`).
It shows every account from `config/postfix-accounts.cf` with:
- INBOX message count (files in the Maildir `cur/` + `new/`, the same numbers
`doveadm mailbox status ... messages INBOX` reports),
- total messages across all mailboxes (incl. subfolders),
- storage used and the quota limit from `config/dovecot-quotas.cf`,
- timestamp of the newest message.
Read-only by design: `./config/` and `./data/mail-data/` are mounted `:ro`, no
docker socket, no host access. Management (add/del accounts) stays in
docker-mailserver (`setup email add`, edit `postfix-accounts.cf`).
Source: `admin/` (Go 1.25, `go test -race ./...` offline vs `admin/testdata/`).
### Manage
```bash
docker compose up -d # builds mail-admin from admin/Dockerfile
docker compose logs -f mail-admin
curl -u "$MAIL_ADMIN_USER:$MAIL_ADMIN_PASSWORD" https://mail.produktor.io/admin/api/accounts
```
Credentials `MAIL_ADMIN_USER` / `MAIL_ADMIN_PASSWORD` are required in `.env`
(compose fails without them). The JSON API is at `/admin/api/accounts`.
## Reverse proxy (NPM)
`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container,