mail relay configured
This commit is contained in:
+53
-26
@@ -4,7 +4,7 @@ Live state of the Mechanical Compiler staging instance on `srv-b`.
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| Updated | 2026-08-16, formal infrastructure acceptance |
|
||||
| Updated | 2026-08-17, after work order 002 (mail) |
|
||||
| Instance | Staging / development |
|
||||
| Specification | `ENVIRONMENT.md` revision 5 |
|
||||
| Failure log | `FAILURES.md` |
|
||||
@@ -36,8 +36,8 @@ and must not be represented as either hidden failures or completed work:
|
||||
|
||||
| Subsystem | Status |
|
||||
|---|---|
|
||||
| Mail alert delivery | Partially configured, characterised, **not accepted end to end** |
|
||||
| `smartd` monitoring | Deferred with mail alerting |
|
||||
| Mail alert delivery | **Accepted 2026-08-17.** Delivered end to end, twice, headers captured. |
|
||||
| `smartd` monitoring | Deferred. Now unblocked — mail works. |
|
||||
| Backup infrastructure | **Postponed by operator decision** — strategy may change |
|
||||
|
||||
---
|
||||
@@ -148,24 +148,43 @@ MECHCOMP_ARTIFACT_RETENTION_DAYS=30
|
||||
MECHCOMP_SECRET_KEY=<generated, not recorded>
|
||||
```
|
||||
|
||||
### Mail, as currently configured
|
||||
### Mail — accepted 2026-08-17
|
||||
|
||||
```
|
||||
relay endpoint 10.110.0.1:25 over wg0
|
||||
banner wg-pk.diagnostics.kane-il.us, STARTTLS offered
|
||||
STARTTLS cert self-signed, CN = wg-pk
|
||||
authentication unauthenticated accepted from 10.110.0.12
|
||||
ports 465 / 587 unavailable; public 198.58.111.109 exposes no SMTP on this path
|
||||
srv-b relayhost [10.110.0.1]:25
|
||||
smtp_tls_security_level may
|
||||
smtp_sasl_auth_enable no
|
||||
srv-b relayhost [10.110.0.1]:25 over wg0
|
||||
root alias sandor@kane-il.us (postalias verified)
|
||||
inet_interfaces loopback-only
|
||||
root alias sandor@kane-il.us
|
||||
local handoff succeeds, relay returns SMTP 250, queue empties
|
||||
FINAL DELIVERY NOT ACCEPTED — operator received a delivery-failure message
|
||||
status deferred, cause unproven downstream (F-023)
|
||||
delivery path srv-b -> wg-pk -> mx1 -> kane-il.us
|
||||
status DELIVERED end to end, twice, full headers captured
|
||||
queue empty, no bounced or deferred entries
|
||||
```
|
||||
|
||||
F-023 was proven to be a relay-trust mismatch three hops downstream: `mx1`
|
||||
rejected `RCPT TO` with `554 5.7.1 Access denied` because `wg-pk`'s public
|
||||
addresses were absent from its `mynetworks`. Corrected by adding only those two
|
||||
addresses.
|
||||
|
||||
**Standing constraints on this path — do not violate:**
|
||||
|
||||
| Host | Constraint |
|
||||
|---|---|
|
||||
| `kane-il.us` | Runs YunoHost. **Its mail configuration must not be altered.** This is why `mx1` exists. |
|
||||
| `mx1.diagnostics.kane-il.us` | Uses DANE. **Its TLS and certificate configuration must not be broken.** The `mynetworks` change is inbound client trust and does not interact with DANE. |
|
||||
| `wg-pk` | Must continue relaying to arbitrary external destinations. Hubzilla registration and notification mail depends on it, and the ISP blocks port 25. Do not restrict it by recipient. |
|
||||
|
||||
**Fragility to know about:** delivery now depends on Linode not reassigning
|
||||
`198.58.111.109` or `2600:3c00::f03c:92ff:fe42:43d7`. If either changes, mail
|
||||
stops silently and the cause is in `mx1`'s `mynetworks`.
|
||||
|
||||
**Open exposure — see F-025.** The correction authorises `wg-pk` under
|
||||
`permit_mynetworks`, which grants relay to any destination. Combined with
|
||||
`wg-pk`'s own `mynetworks = 10.110.0.0/22`, every tunnel peer — including both
|
||||
containers, which arrive as `10.110.0.12` through the host masquerade — can
|
||||
originate mail as `kane-il.us` infrastructure. Correction pending decision.
|
||||
|
||||
**Logging note (F-024):** `/var/log/mail.log` does not exist. Proxmox ships
|
||||
without `rsyslog`; Postfix logs to journald. Use `journalctl -u postfix@-`.
|
||||
|
||||
### Placeholder backend — staging scaffold, not application code
|
||||
|
||||
```
|
||||
@@ -212,6 +231,7 @@ Each line was demonstrated by command output, not inferred.
|
||||
- [x] LAN to Proxmox console `10.0.0.12:8006` returns 200, unaffected
|
||||
- [x] NAT and FORWARD rules present live **and** persisted, in correct order
|
||||
- [x] Host: `running`, zero failed units
|
||||
- [x] **Mail delivered end to end from `root` on `srv-b`, twice, headers captured**
|
||||
|
||||
### CT 100
|
||||
|
||||
@@ -258,15 +278,19 @@ Nothing. The infrastructure boundary is accepted.
|
||||
Recorded here so they are visually distinct from failures and from forgotten
|
||||
work. None is a defect.
|
||||
|
||||
- [ ] **Mail end-to-end delivery** (F-023). Handoff to `wg-pk` works; final
|
||||
delivery does not. Leading untested hypothesis: envelope sender
|
||||
`root@srv-b.dev.infra` rejected on sender-domain verification, since
|
||||
`dev.infra` does not resolve publicly. Candidate remedies `myorigin` or
|
||||
`smtp_generic_maps`. Check the `postfix check` chroot divergence first.
|
||||
- [ ] **SMTP egress block for the container network** (F-025). The containers
|
||||
have no reason to originate mail. A `FORWARD` DROP on ports 25/465/587
|
||||
from the service network to `10.110.0.0/22` is local, precise, and touches
|
||||
no estate policy. `srv-b`'s own alerts are unaffected — they originate
|
||||
locally and take OUTPUT, never FORWARD.
|
||||
- [ ] **`wg-pk` `mynetworks` scope** (F-025). Estate decision: whether every
|
||||
tunnel peer should originate mail as `kane-il.us` infrastructure, or only
|
||||
the hosts that legitimately do. Not this project's to change unilaterally.
|
||||
- [ ] **`smartd` explicit four-member configuration.** The package is installed
|
||||
and the service is active, but `DEVICESCAN` currently monitors **zero
|
||||
devices**; the P410i members are visible only through explicit
|
||||
`-d cciss,N`. Active is not the same as monitoring. Deferred with mail.
|
||||
`-d cciss,N`. Active is not the same as monitoring. **Now unblocked** —
|
||||
mail is accepted, so `-M test` gives a real end-to-end acceptance.
|
||||
- [ ] **Backup infrastructure, entirely.** Postponed 2026-08-16 because the
|
||||
strategy may change: `vzdump` job, archive sizing, retention, free-space
|
||||
guard, host-side pull, `mechcomp-backup`, backup alerting, gold media,
|
||||
@@ -341,11 +365,12 @@ The Shapely port gates all of the above.
|
||||
|
||||
| # | Question | Blocks |
|
||||
|---|---|---|
|
||||
| 1 | Why does delivery fail downstream of `wg-pk`? | mail, `smartd`, backup alerting |
|
||||
| 2 | What is the backup strategy? | all backup work |
|
||||
| 3 | Where is the 3+ TB USB disk attached? | gold redundancy step |
|
||||
| 1 | Should container SMTP egress be blocked at `srv-b`? | F-025, ours to fix |
|
||||
| 2 | Should `wg-pk` `mynetworks` narrow to explicit hosts? | F-025, estate decision |
|
||||
| 3 | What is the backup strategy? | all backup work |
|
||||
| 4 | Where is the 3+ TB USB disk attached? | gold redundancy step |
|
||||
|
||||
Question 1 is answered by diagnosis. Questions 2 and 3 need CIVICVS.
|
||||
All four need CIVICVS.
|
||||
|
||||
---
|
||||
|
||||
@@ -361,3 +386,5 @@ Question 1 is answered by diagnosis. Questions 2 and 3 need CIVICVS.
|
||||
| Docker storage driver | `overlay2` / `systemd`. No fallback needed. |
|
||||
| LAN workstation access | Not required. WireGuard through `srv-b`. |
|
||||
| `MECHCOMP_BIND` semantics | Scalar, service address only. Loopback not bound. |
|
||||
| Why did delivery fail downstream? | `mx1` relay trust. Proven and corrected (F-023). |
|
||||
| Where does Postfix log on this host? | journald. No `rsyslog`, no `/var/log/mail.log` (F-024). |
|
||||
|
||||
Reference in New Issue
Block a user