app-email rollout: gitea + rallly mappings; calcom/nextcloud/immich = findings

gitea (STARTTLS + FORCE_TRUST_SERVER_CERT) and rallly (Nodemailer STARTTLS +
SMTP_REJECT_UNAUTHORIZED=false) wired. Fixed rallly's non-existent 3.12.1 pin → 3.11.2.
calcom/nextcloud/immich don't fit the mechanism (self-signed opportunistic-STARTTLS,
split From, no-SMTP-env) — see FINDING doc in felhom.eu.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-29 10:32:55 +02:00
parent f0529bc9a0
commit 3b5d102d21
5 changed files with 65 additions and 1 deletions
+9
View File
@@ -16,6 +16,15 @@ services:
- GITEA__server__ROOT_URL=https://${SUBDOMAIN}.${DOMAIN}
- GITEA__server__SSH_DOMAIN=${SUBDOMAIN}.${DOMAIN}
- GITEA__database__DB_TYPE=sqlite3
# App-email (managed relay). Injected by the controller only when app-email is on (global +
# per-app); empty ENABLED/ADDR keeps Gitea mail disabled. Gitea applies GITEA__* env on every
# boot (environment-to-ini), so the toggle takes effect on redeploy. See .felhom.yml smtp_mapping.
- GITEA__mailer__ENABLED=${GITEA__mailer__ENABLED:-false}
- GITEA__mailer__PROTOCOL=${GITEA__mailer__PROTOCOL:-smtp+starttls}
- GITEA__mailer__SMTP_ADDR=${GITEA__mailer__SMTP_ADDR:-}
- GITEA__mailer__SMTP_PORT=${GITEA__mailer__SMTP_PORT:-2525}
- GITEA__mailer__FROM=${GITEA__mailer__FROM:-}
- GITEA__mailer__FORCE_TRUST_SERVER_CERT=${GITEA__mailer__FORCE_TRUST_SERVER_CERT:-false}
volumes:
- gitea_data:/data
networks: