app-email: smtp_mapping for vaultwarden + mealie

Vaultwarden via STARTTLS (accepts self-signed shim cert); Mealie via plaintext
(NONE) — no accept-invalid-cert option, spike-validated mode. Compose files
reference injected ${SMTP_*}. README documents the pattern.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-29 08:45:23 +02:00
parent 5d42ca18bf
commit 4581a92781
7 changed files with 153 additions and 105 deletions
+15
View File
@@ -62,3 +62,18 @@ healthcheck:
checks:
- type: tcp
port: 9000
# --- App-email mapping (apps → in-controller shim → hub → Resend) ---
# When app-email is on (global toggle + this app's per-app toggle), the controller injects
# host = the on-box shim, port = 2525, From = mealie@felhom.eu. Mealie has NO accept-invalid-
# cert option, so it talks PLAINTEXT (SMTP_AUTH_STRATEGY=NONE) to the shim on 2525 — the
# spike-validated mode (SPIKE-smtp-app-relay-2026-06-28 §7). SMTP_USER/SMTP_PASSWORD stay
# unset (no auth needed; the shim holds no Resend key).
smtp_mapping:
host_var: SMTP_HOST
port_var: SMTP_PORT
security_var: SMTP_AUTH_STRATEGY
security_value: "NONE"
from_var: SMTP_FROM_EMAIL
from_name_var: SMTP_FROM_NAME
from_local: mealie