-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathconfig.example.dhall
More file actions
77 lines (77 loc) · 4.68 KB
/
Copy pathconfig.example.dhall
File metadata and controls
77 lines (77 loc) · 4.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
let Auth = { enabled : Bool, username : Text, password : Text }
in let Config =
{ hostname : Text
, domains : List Text
, listen : { address : Text, port : Natural, proxy_from : List Text }
, tls_listen : { address : Text, port : Natural }
, limits : { message : Natural, line : Natural, rcpts : Natural
, cmd_timeout : Natural, data_timeout : Natural }
, relay : { host : Text, port : Natural, auth : Auth, retries : Natural
, tls : Text, tls_ca : Text, max_attempts : Natural }
-- Optional outbound relay for reverse-alias REPLIES only. Normal alias
-- forwards keep using `relay` (the local imapd ingest); replies from the
-- local mailbox back to the original external sender go out through
-- `reply_relay` — typically an authenticated STARTTLS submission server
-- (e.g. node-one's outbox on :587) that can deliver to external
-- recipients. Omit the field (older configs) to default to a copy of
-- `relay` (previous behaviour). Same schema as `relay`.
, reply_relay : { host : Text, port : Natural, auth : Auth, retries : Natural
, tls : Text, tls_ca : Text, max_attempts : Natural }
, storage : { path : Text, spool : Text, retention_days : Natural }
, reply : { prefix : Text, separator : Text }
, catch_all : Text
, aliases : List { alias : Text, destinations : List Text }
, http : { address : Text, port : Natural }
, admin : { token : Text }
, tls : { cert : Text, key : Text }
, dkim : List { domain : Text, selector : Text, private_key : Text }
}
in { hostname = "mx.example.com"
, domains = [ "example.com" ]
, listen = { address = "0.0.0.0", port = 2525, proxy_from = [] : List Text }
-- proxy_from lists the TRUSTED PROXY-protocol v1 peers (IP literals, e.g.
-- the fly edge / nginx stream proxy in front of this listener). A PROXY
-- header is honored only when the actual TCP peer is in this list; from
-- any other peer it is ignored, so an empty list means a directly
-- reachable listener cannot forge the client IP (SPF / conn caps).
-- Put the edge's address here when running behind a PROXY-protocol proxy.
-- Optional implicit-TLS (SMTPS) listener; the fly edge uses it to deliver
-- over TLS (nginx stream `proxy_ssl`). port 0 = disabled.
, tls_listen = { address = "0.0.0.0", port = 0 }
, limits = { message = 26214400, line = 1000, rcpts = 100
, cmd_timeout = 300, data_timeout = 600 }
, relay = { host = "127.0.0.1", port = 2526
, auth = { enabled = False, username = "", password = "" }
, retries = 3, tls = "starttls-verify"
-- tls_ca = "" uses the embedded Mozilla CA bundle; a non-empty path
-- points at an operator-provided PEM CA bundle (only consulted
-- when tls == "starttls-verify").
, tls_ca = "", max_attempts = 100 }
-- reply_relay carries reverse-alias replies to an EXTERNAL submission
-- server (AUTH + STARTTLS on :587). Replace host/username/password with
-- node-one's outbox credentials. AUTH is only ever sent over a
-- certificate-VERIFIED TLS leg, so auth.enabled=True requires
-- tls = "starttls-verify" (implicit/starttls are privacy-only: an active
-- MITM terminates them and would capture the password).
, reply_relay = { host = "outbox.node-one", port = 587
, auth = { enabled = True, username = "visage", password = "change-me" }
, retries = 3, tls = "starttls-verify"
, tls_ca = "", max_attempts = 100 }
, storage = { path = "./var/db", spool = "./var/spool", retention_days = 30 }
, reply = { prefix = "reply", separator = "+" }
, catch_all = ""
, aliases = [ { alias = "jane@example.com", destinations = [ "jane@realmail.example" ] }
, { alias = "shopping@example.com", destinations = [ "jane@realmail.example", "bob@realmail.example" ] }
]
, http = { address = "127.0.0.1", port = 8080 }
-- admin.token is the bearer token for the admin HTTP API. It is read into
-- a 512-byte Authorization buffer, so it must be at most ~505 chars (config
-- enforces a 500-char ceiling); the placeholder below is fine for config-check
-- but a real deployment must use a long random token.
, admin = { token = "change-me" }
-- tls enables inbound STARTTLS (RFC 3207) on the SMTP listener. Both
-- paths are required when the record is present; empty paths (below) or
-- an omitted tls record disable TLS entirely (plaintext default).
, tls = { cert = "", key = "" }
, dkim = [] : List { domain : Text, selector : Text, private_key : Text }
} : Config