12 Commits
Author SHA1 Message Date
eSlider 6e8a9dc963 feat(mail): share oleksandra.svitelska mailbox with info@ (read-only)
Add oleksandra.svitelska@produktor.io to PRODUCTION_OWNERS so info@
sees it under Shared/ (lookup read), same class as the other production
mailboxes. Applied live via user-patches.sh (idempotent); no container
recreation needed.
2026-09-23 19:37:56 +01:00
eSlider e1208be24e chore(mail): pinned-version update check off, Gmail postscreen whitelist, docs
- compose: ENABLE_UPDATE_CHECK=0 (image intentionally pinned to DMS v15.1.0).

- postscreen: permit Google SMTP outbound ranges (Gmail retries from rotating IPs,

  '450 PASS NEW' never completes) — keeps LinkedIn/Gmail mail out of the tarpit.

- README: DNS/ops notes; user-patches: whitelist copy path.
2026-09-16 14:59:45 +01:00
eSlider 4b3af3fad3 fix(mail): only $mydomain is a local virtual mailbox domain
gmail.com and the other historical/incubator domains (gmx.de, gridfactor.de,

rpf.de, viscreation.de, wheregroup.com) were in /etc/postfix/vhost, so mail to

those addresses short-circuited into the local incubator archive via dovecot

lmtp and never left the host — e.g. a campaign test from info@produktor.io to

eslider@gmail.com. DMS appends postfix-main.cf last, so this override wins.

Dovecot accounts stay for IMAP/doveadm import; only local delivery changes.

Verified: v19 EML relayed to gmail-smtp-in.l.google.com, status=sent, dkim=pass.
2026-09-16 14:51:36 +01:00
eSlider 8dbfba6be3 feat(dovecot): incubator owners defacto (gator #101) 2026-09-06 01:19:00 +01:00
eSlider 58a57e890e fix(mail): postscreen whitelist LinkedIn senders (450 reject of verification mail) 2026-09-04 09:37:18 +01:00
eSlider 717348db6c feat(dovecot): incubator owner eslider@gmail.com (G-10.3 #100) 2026-09-02 19:22:21 +01:00
eSlider d2724ec727 chore(dovecot): drop deleted wheregroup@produktor.io A1 pilot box from owner lists (#252) 2026-09-02 13:50:54 +01:00
eSlider 6cdd704aef feat(dovecot): historical-account andriy.oblivantsev@wheregroup.com for wheregroup incubator (#252) 2026-09-02 13:42:58 +01:00
eSlider a4ab96d025 feat(dovecot): incubator owner wheregroup@ + info@ delete access (#251) 2026-09-02 12:10:51 +01:00
eSlider 2bb6ed310e feat(dovecot): shared mailboxes — info@ reads all accounts (#79)
Dovecot ACL + shared namespace (shared/%%u/), acl_shared_dict in mail-state,
idempotent user-patches.sh grants info@ read-only (lookup read) on every
mailbox of ano@, andriy.oblivantsev@, postmaster@ and pre-subscribes the
shared folders so Roundcube's subscribed folder list shows them. Delivery and
passwords untouched; other accounts see no shared folders.
2026-09-01 16:02:52 +01:00
eSlider 05540c2a8d fix(fail2ban): ignoreip real docker subnet /20 (#113) 2026-08-25 19:58:57 +01:00
eSlider 7d874c5117 TLS: letsencrypt DNS-01 via Dynadot hook; fail2ban ignoreip guard (#114)
- scripts/dynadot-dns.sh: DNS-01 hook (snapshot -> append TXT -> restore);
  set_dns2 wants lowercase record types, ResponseCode checks on deploy/clean
- compose: SSL_TYPE=letsencrypt, mount tls/letsencrypt/<domain> ->
  /etc/letsencrypt/live/<domain>; drop-in jail.d/ignoreip.local so the
  postfix jail can't ban the docker bridge gateway (host self-DoS)
- cert issued for mail.produktor.io (Let's Encrypt, ECDSA); renewal via
  acme.sh cron + reloadcmd (postfix/dovecot reload)
2026-08-22 22:46:24 +01:00