TLS: letsencrypt DNS-01 via Dynadot hook; fail2ban ignoreip guard (#114)

- scripts/dynadot-dns.sh: DNS-01 hook (snapshot -> append TXT -> restore);
  set_dns2 wants lowercase record types, ResponseCode checks on deploy/clean
- compose: SSL_TYPE=letsencrypt, mount tls/letsencrypt/<domain> ->
  /etc/letsencrypt/live/<domain>; drop-in jail.d/ignoreip.local so the
  postfix jail can't ban the docker bridge gateway (host self-DoS)
- cert issued for mail.produktor.io (Let's Encrypt, ECDSA); renewal via
  acme.sh cron + reloadcmd (postfix/dovecot reload)
This commit is contained in:
2026-08-22 22:46:24 +01:00
parent 8baa303760
commit 7d874c5117
3 changed files with 201 additions and 4 deletions
+6
View File
@@ -0,0 +1,6 @@
# Host-originated connections reach postfix/dovecot via the docker bridge
# gateway. Without ignoring it, the postfix jail bans our own host as
# collateral of port-25 scanner noise + local TLS probes (self-DoS: host
# submission times out). Keep in sync with the compose network subnet.
[DEFAULT]
ignoreip = 127.0.0.1/8 192.168.32.0/24 192.168.1.0/24