mail relay configured

This commit is contained in:
2026-08-17 08:25:14 -04:00
parent e67988eef5
commit 673d5f26ac
4 changed files with 187 additions and 41 deletions
+53 -26
View File
@@ -4,7 +4,7 @@ Live state of the Mechanical Compiler staging instance on `srv-b`.
| | |
|---|---|
| Updated | 2026-08-16, formal infrastructure acceptance |
| Updated | 2026-08-17, after work order 002 (mail) |
| Instance | Staging / development |
| Specification | `ENVIRONMENT.md` revision 5 |
| Failure log | `FAILURES.md` |
@@ -36,8 +36,8 @@ and must not be represented as either hidden failures or completed work:
| Subsystem | Status |
|---|---|
| Mail alert delivery | Partially configured, characterised, **not accepted end to end** |
| `smartd` monitoring | Deferred with mail alerting |
| Mail alert delivery | **Accepted 2026-08-17.** Delivered end to end, twice, headers captured. |
| `smartd` monitoring | Deferred. Now unblocked — mail works. |
| Backup infrastructure | **Postponed by operator decision** — strategy may change |
---
@@ -148,24 +148,43 @@ MECHCOMP_ARTIFACT_RETENTION_DAYS=30
MECHCOMP_SECRET_KEY=<generated, not recorded>
```
### Mail, as currently configured
### Mail — accepted 2026-08-17
```
relay endpoint 10.110.0.1:25 over wg0
banner wg-pk.diagnostics.kane-il.us, STARTTLS offered
STARTTLS cert self-signed, CN = wg-pk
authentication unauthenticated accepted from 10.110.0.12
ports 465 / 587 unavailable; public 198.58.111.109 exposes no SMTP on this path
srv-b relayhost [10.110.0.1]:25
smtp_tls_security_level may
smtp_sasl_auth_enable no
srv-b relayhost [10.110.0.1]:25 over wg0
root alias sandor@kane-il.us (postalias verified)
inet_interfaces loopback-only
root alias sandor@kane-il.us
local handoff succeeds, relay returns SMTP 250, queue empties
FINAL DELIVERY NOT ACCEPTED — operator received a delivery-failure message
status deferred, cause unproven downstream (F-023)
delivery path srv-b -> wg-pk -> mx1 -> kane-il.us
status DELIVERED end to end, twice, full headers captured
queue empty, no bounced or deferred entries
```
F-023 was proven to be a relay-trust mismatch three hops downstream: `mx1`
rejected `RCPT TO` with `554 5.7.1 Access denied` because `wg-pk`'s public
addresses were absent from its `mynetworks`. Corrected by adding only those two
addresses.
**Standing constraints on this path — do not violate:**
| Host | Constraint |
|---|---|
| `kane-il.us` | Runs YunoHost. **Its mail configuration must not be altered.** This is why `mx1` exists. |
| `mx1.diagnostics.kane-il.us` | Uses DANE. **Its TLS and certificate configuration must not be broken.** The `mynetworks` change is inbound client trust and does not interact with DANE. |
| `wg-pk` | Must continue relaying to arbitrary external destinations. Hubzilla registration and notification mail depends on it, and the ISP blocks port 25. Do not restrict it by recipient. |
**Fragility to know about:** delivery now depends on Linode not reassigning
`198.58.111.109` or `2600:3c00::f03c:92ff:fe42:43d7`. If either changes, mail
stops silently and the cause is in `mx1`'s `mynetworks`.
**Open exposure — see F-025.** The correction authorises `wg-pk` under
`permit_mynetworks`, which grants relay to any destination. Combined with
`wg-pk`'s own `mynetworks = 10.110.0.0/22`, every tunnel peer — including both
containers, which arrive as `10.110.0.12` through the host masquerade — can
originate mail as `kane-il.us` infrastructure. Correction pending decision.
**Logging note (F-024):** `/var/log/mail.log` does not exist. Proxmox ships
without `rsyslog`; Postfix logs to journald. Use `journalctl -u postfix@-`.
### Placeholder backend — staging scaffold, not application code
```
@@ -212,6 +231,7 @@ Each line was demonstrated by command output, not inferred.
- [x] LAN to Proxmox console `10.0.0.12:8006` returns 200, unaffected
- [x] NAT and FORWARD rules present live **and** persisted, in correct order
- [x] Host: `running`, zero failed units
- [x] **Mail delivered end to end from `root` on `srv-b`, twice, headers captured**
### CT 100
@@ -258,15 +278,19 @@ Nothing. The infrastructure boundary is accepted.
Recorded here so they are visually distinct from failures and from forgotten
work. None is a defect.
- [ ] **Mail end-to-end delivery** (F-023). Handoff to `wg-pk` works; final
delivery does not. Leading untested hypothesis: envelope sender
`root@srv-b.dev.infra` rejected on sender-domain verification, since
`dev.infra` does not resolve publicly. Candidate remedies `myorigin` or
`smtp_generic_maps`. Check the `postfix check` chroot divergence first.
- [ ] **SMTP egress block for the container network** (F-025). The containers
have no reason to originate mail. A `FORWARD` DROP on ports 25/465/587
from the service network to `10.110.0.0/22` is local, precise, and touches
no estate policy. `srv-b`'s own alerts are unaffected — they originate
locally and take OUTPUT, never FORWARD.
- [ ] **`wg-pk` `mynetworks` scope** (F-025). Estate decision: whether every
tunnel peer should originate mail as `kane-il.us` infrastructure, or only
the hosts that legitimately do. Not this project's to change unilaterally.
- [ ] **`smartd` explicit four-member configuration.** The package is installed
and the service is active, but `DEVICESCAN` currently monitors **zero
devices**; the P410i members are visible only through explicit
`-d cciss,N`. Active is not the same as monitoring. Deferred with mail.
`-d cciss,N`. Active is not the same as monitoring. **Now unblocked** —
mail is accepted, so `-M test` gives a real end-to-end acceptance.
- [ ] **Backup infrastructure, entirely.** Postponed 2026-08-16 because the
strategy may change: `vzdump` job, archive sizing, retention, free-space
guard, host-side pull, `mechcomp-backup`, backup alerting, gold media,
@@ -341,11 +365,12 @@ The Shapely port gates all of the above.
| # | Question | Blocks |
|---|---|---|
| 1 | Why does delivery fail downstream of `wg-pk`? | mail, `smartd`, backup alerting |
| 2 | What is the backup strategy? | all backup work |
| 3 | Where is the 3+ TB USB disk attached? | gold redundancy step |
| 1 | Should container SMTP egress be blocked at `srv-b`? | F-025, ours to fix |
| 2 | Should `wg-pk` `mynetworks` narrow to explicit hosts? | F-025, estate decision |
| 3 | What is the backup strategy? | all backup work |
| 4 | Where is the 3+ TB USB disk attached? | gold redundancy step |
Question 1 is answered by diagnosis. Questions 2 and 3 need CIVICVS.
All four need CIVICVS.
---
@@ -361,3 +386,5 @@ Question 1 is answered by diagnosis. Questions 2 and 3 need CIVICVS.
| Docker storage driver | `overlay2` / `systemd`. No fallback needed. |
| LAN workstation access | Not required. WireGuard through `srv-b`. |
| `MECHCOMP_BIND` semantics | Scalar, service address only. Loopback not bound. |
| Why did delivery fail downstream? | `mx1` relay trust. Proven and corrected (F-023). |
| Where does Postfix log on this host? | journald. No `rsyslog`, no `/var/log/mail.log` (F-024). |