Drop stalwart mail proxying from the haproxy edge (#491)

Stalwart was only ever a test deployment. The daemon is dead on all three
backend VMs and nothing public depends on it — `unkin.net` MX points at Google —
so the edge is proxying mail to nowhere and the tcp frontends make `defaults`
emit 20 spurious HTTP-mode warnings.

- Drop the `fe_smtp`, `fe_submission`, `fe_imap` and `fe_imaps` frontends.
- Drop the five `be_stalwart_*` backends and their map entries in `fe_http.map`/`fe_https.map`.
- Drop the now-unused 25/143/587/993 Service and container ports.

`haproxy -c` on the rendered config: exit 0, 0 warnings (was 20), 0 alerts.

Reviewed-on: #491
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #491.
This commit is contained in:
2026-09-26 21:25:49 +10:00
committed by BenVincent
parent 5341253573
commit 426a399f31
3 changed files with 2 additions and 152 deletions
+1 -13
View File
@@ -50,7 +50,7 @@ spec:
readOnlyRootFilesystem: true
capabilities:
drop: [ALL]
# Frontends bind 25/80/143/443/587; the dst_port ACLs need the real ports.
# Frontends bind 80 and 443; the dst_port ACLs need the real ports.
add: [NET_BIND_SERVICE]
ports:
- name: http
@@ -59,18 +59,6 @@ spec:
- name: https
containerPort: 443
protocol: TCP
- name: smtp
containerPort: 25
protocol: TCP
- name: imap
containerPort: 143
protocol: TCP
- name: submission
containerPort: 587
protocol: TCP
- name: imaps
containerPort: 993
protocol: TCP
- name: health
containerPort: 8404
protocol: TCP