app-email: smtp_mapping for vaultwarden + mealie
Vaultwarden via STARTTLS (accepts self-signed shim cert); Mealie via plaintext
(NONE) — no accept-invalid-cert option, spike-validated mode. Compose files
reference injected ${SMTP_*}. README documents the pattern.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -62,3 +62,18 @@ healthcheck:
|
||||
checks:
|
||||
- type: tcp
|
||||
port: 9000
|
||||
|
||||
# --- App-email mapping (apps → in-controller shim → hub → Resend) ---
|
||||
# When app-email is on (global toggle + this app's per-app toggle), the controller injects
|
||||
# host = the on-box shim, port = 2525, From = mealie@felhom.eu. Mealie has NO accept-invalid-
|
||||
# cert option, so it talks PLAINTEXT (SMTP_AUTH_STRATEGY=NONE) to the shim on 2525 — the
|
||||
# spike-validated mode (SPIKE-smtp-app-relay-2026-06-28 §7). SMTP_USER/SMTP_PASSWORD stay
|
||||
# unset (no auth needed; the shim holds no Resend key).
|
||||
smtp_mapping:
|
||||
host_var: SMTP_HOST
|
||||
port_var: SMTP_PORT
|
||||
security_var: SMTP_AUTH_STRATEGY
|
||||
security_value: "NONE"
|
||||
from_var: SMTP_FROM_EMAIL
|
||||
from_name_var: SMTP_FROM_NAME
|
||||
from_local: mealie
|
||||
|
||||
@@ -26,6 +26,15 @@ services:
|
||||
- MAX_WORKERS=1
|
||||
- WEB_CONCURRENCY=1
|
||||
- BASE_URL=https://${SUBDOMAIN}.${DOMAIN}
|
||||
# App-email (managed relay). Injected by the controller only when app-email is on
|
||||
# (global + per-app); empty SMTP_HOST = Mealie mail stays disabled. Mealie has no
|
||||
# accept-invalid-cert option, so the relay uses plaintext (NONE) to the on-box shim —
|
||||
# the spike-validated mode. See .felhom.yml smtp_mapping.
|
||||
- SMTP_HOST=${SMTP_HOST:-}
|
||||
- SMTP_PORT=${SMTP_PORT:-25}
|
||||
- SMTP_AUTH_STRATEGY=${SMTP_AUTH_STRATEGY:-NONE}
|
||||
- SMTP_FROM_NAME=${SMTP_FROM_NAME:-}
|
||||
- SMTP_FROM_EMAIL=${SMTP_FROM_EMAIL:-}
|
||||
volumes:
|
||||
- mealie_data:/app/data/
|
||||
networks:
|
||||
|
||||
Reference in New Issue
Block a user