Drop stalwart mail proxying from the haproxy edge (#491)
Stalwart was only ever a test deployment. The daemon is dead on all three backend VMs and nothing public depends on it — `unkin.net` MX points at Google — so the edge is proxying mail to nowhere and the tcp frontends make `defaults` emit 20 spurious HTTP-mode warnings. - Drop the `fe_smtp`, `fe_submission`, `fe_imap` and `fe_imaps` frontends. - Drop the five `be_stalwart_*` backends and their map entries in `fe_http.map`/`fe_https.map`. - Drop the now-unused 25/143/587/993 Service and container ports. `haproxy -c` on the rendered config: exit 0, 0 warnings (was 20), 0 alerts. Reviewed-on: #491 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #491.
This commit is contained in:
@@ -23,9 +23,6 @@ data:
|
|||||||
git.unkin.net be_gitea
|
git.unkin.net be_gitea
|
||||||
grafana.unkin.net be_grafana
|
grafana.unkin.net be_grafana
|
||||||
dashboard.ceph.unkin.net be_ceph_dashboard
|
dashboard.ceph.unkin.net be_ceph_dashboard
|
||||||
mail-webadmin.main.unkin.net be_stalwart_webadmin
|
|
||||||
autoconfig.main.unkin.net be_stalwart_webadmin
|
|
||||||
autodiscovery.main.unkin.net be_stalwart_webadmin
|
|
||||||
auth.unkin.net be_k8s_kanidm
|
auth.unkin.net be_k8s_kanidm
|
||||||
|
|
||||||
fe_https.map: |
|
fe_https.map: |
|
||||||
@@ -40,9 +37,6 @@ data:
|
|||||||
git.unkin.net be_gitea
|
git.unkin.net be_gitea
|
||||||
grafana.unkin.net be_grafana
|
grafana.unkin.net be_grafana
|
||||||
dashboard.ceph.unkin.net be_ceph_dashboard
|
dashboard.ceph.unkin.net be_ceph_dashboard
|
||||||
mail-webadmin.main.unkin.net be_stalwart_webadmin
|
|
||||||
autoconfig.main.unkin.net be_stalwart_webadmin
|
|
||||||
autodiscovery.main.unkin.net be_stalwart_webadmin
|
|
||||||
auth.unkin.net be_k8s_kanidm
|
auth.unkin.net be_k8s_kanidm
|
||||||
|
|
||||||
haproxy.cfg: |
|
haproxy.cfg: |
|
||||||
@@ -101,26 +95,6 @@ data:
|
|||||||
use_backend be_letsencrypt if acl-letsencrypt
|
use_backend be_letsencrypt if acl-letsencrypt
|
||||||
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_https.map,be_default)]
|
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_https.map,be_default)]
|
||||||
|
|
||||||
frontend fe_imap
|
|
||||||
bind 0.0.0.0:143
|
|
||||||
mode tcp
|
|
||||||
description Frontend for Stalwart IMAP (STARTTLS)
|
|
||||||
default_backend be_stalwart_imap
|
|
||||||
log global
|
|
||||||
option tcplog
|
|
||||||
tcp-request inspect-delay 5s
|
|
||||||
tcp-request content accept if { req_len 0 }
|
|
||||||
|
|
||||||
frontend fe_imaps
|
|
||||||
bind 0.0.0.0:993
|
|
||||||
mode tcp
|
|
||||||
description Frontend for Stalwart IMAPS (implicit TLS)
|
|
||||||
default_backend be_stalwart_imaps
|
|
||||||
log global
|
|
||||||
option tcplog
|
|
||||||
tcp-request inspect-delay 5s
|
|
||||||
tcp-request content accept if { req_len 0 }
|
|
||||||
|
|
||||||
frontend fe_metrics
|
frontend fe_metrics
|
||||||
bind 0.0.0.0:8405
|
bind 0.0.0.0:8405
|
||||||
mode http
|
mode http
|
||||||
@@ -129,26 +103,6 @@ data:
|
|||||||
http-request set-header X-Real-IP %[src]
|
http-request set-header X-Real-IP %[src]
|
||||||
http-request use-service prometheus-exporter if { path /metrics }
|
http-request use-service prometheus-exporter if { path /metrics }
|
||||||
|
|
||||||
frontend fe_smtp
|
|
||||||
bind 0.0.0.0:25
|
|
||||||
mode tcp
|
|
||||||
description Frontend for Stalwart SMTP
|
|
||||||
default_backend be_stalwart_smtp
|
|
||||||
log global
|
|
||||||
option tcplog
|
|
||||||
tcp-request inspect-delay 5s
|
|
||||||
tcp-request content accept if { req_len 0 }
|
|
||||||
|
|
||||||
frontend fe_submission
|
|
||||||
bind 0.0.0.0:587
|
|
||||||
mode tcp
|
|
||||||
description Frontend for Stalwart SMTP Submission
|
|
||||||
default_backend be_stalwart_submission
|
|
||||||
log global
|
|
||||||
option tcplog
|
|
||||||
tcp-request inspect-delay 5s
|
|
||||||
tcp-request content accept if { req_len 0 }
|
|
||||||
|
|
||||||
backend be_ceph_dashboard
|
backend be_ceph_dashboard
|
||||||
description Backend for Ceph Dashboard from Mgr instances
|
description Backend for Ceph Dashboard from Mgr instances
|
||||||
balance roundrobin
|
balance roundrobin
|
||||||
@@ -332,82 +286,6 @@ data:
|
|||||||
redirect scheme https if !{ ssl_fc }
|
redirect scheme https if !{ ssl_fc }
|
||||||
server ausyd1nxvm2046 198.18.26.161:443 check cookie ausyd1nxvm2046 fall 2 inter 2s rise 3 ssl verify none
|
server ausyd1nxvm2046 198.18.26.161:443 check cookie ausyd1nxvm2046 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
backend be_stalwart_imap
|
|
||||||
description Backend for Stalwart IMAP (STARTTLS)
|
|
||||||
balance roundrobin
|
|
||||||
mode tcp
|
|
||||||
option tcp-check
|
|
||||||
option prefer-last-server
|
|
||||||
stick on src
|
|
||||||
stick-table type ip size 200k expire 30m
|
|
||||||
tcp-check connect port 143 send-proxy
|
|
||||||
tcp-check expect string "* OK"
|
|
||||||
tcp-check send "A001 STARTTLS\r\n"
|
|
||||||
tcp-check expect rstring "A001 (OK|2.0.0)"
|
|
||||||
server ausyd1nxvm2124 198.18.28.76:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
server ausyd1nxvm2125 198.18.29.44:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
server ausyd1nxvm2126 198.18.25.160:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
|
|
||||||
backend be_stalwart_imaps
|
|
||||||
description Backend for Stalwart IMAPS (implicit TLS)
|
|
||||||
balance roundrobin
|
|
||||||
mode tcp
|
|
||||||
option tcp-check
|
|
||||||
option prefer-last-server
|
|
||||||
stick on src
|
|
||||||
stick-table type ip size 200k expire 30m
|
|
||||||
tcp-check connect ssl send-proxy
|
|
||||||
tcp-check expect string "* OK"
|
|
||||||
server ausyd1nxvm2124 198.18.28.76:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
|
||||||
server ausyd1nxvm2125 198.18.29.44:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
|
||||||
server ausyd1nxvm2126 198.18.25.160:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
|
||||||
|
|
||||||
backend be_stalwart_smtp
|
|
||||||
description Backend for Stalwart SMTP
|
|
||||||
balance roundrobin
|
|
||||||
mode tcp
|
|
||||||
option tcp-check
|
|
||||||
option prefer-last-server
|
|
||||||
stick on src
|
|
||||||
stick-table type ip size 200k expire 30m
|
|
||||||
tcp-check connect port 25 send-proxy
|
|
||||||
tcp-check expect string "220 "
|
|
||||||
server ausyd1nxvm2124 198.18.28.76:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
server ausyd1nxvm2125 198.18.29.44:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
server ausyd1nxvm2126 198.18.25.160:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
|
|
||||||
backend be_stalwart_submission
|
|
||||||
description Backend for Stalwart SMTP Submission
|
|
||||||
balance roundrobin
|
|
||||||
mode tcp
|
|
||||||
option tcp-check
|
|
||||||
option prefer-last-server
|
|
||||||
stick on src
|
|
||||||
stick-table type ip size 200k expire 30m
|
|
||||||
tcp-check connect port 587 send-proxy
|
|
||||||
tcp-check expect string "220 "
|
|
||||||
server ausyd1nxvm2124 198.18.28.76:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
server ausyd1nxvm2125 198.18.29.44:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
server ausyd1nxvm2126 198.18.25.160:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
||||||
|
|
||||||
backend be_stalwart_webadmin
|
|
||||||
description Backend for Stalwart Webadmin
|
|
||||||
balance roundrobin
|
|
||||||
cookie SRVNAME insert indirect nocache
|
|
||||||
http-check expect status 200
|
|
||||||
http-request set-header X-Forwarded-Port %[dst_port]
|
|
||||||
http-request add-header X-Forwarded-Proto https if { dst_port 9443 }
|
|
||||||
http-reuse always
|
|
||||||
option httpchk GET /
|
|
||||||
option forwardfor
|
|
||||||
option http-keep-alive
|
|
||||||
option prefer-last-server
|
|
||||||
redirect scheme https if !{ ssl_fc }
|
|
||||||
stick-table type ip size 200k expire 30m
|
|
||||||
server ausyd1nxvm2124 198.18.28.76:443 check cookie ausyd1nxvm2124 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
|
||||||
server ausyd1nxvm2125 198.18.29.44:443 check cookie ausyd1nxvm2125 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
|
||||||
server ausyd1nxvm2126 198.18.25.160:443 check cookie ausyd1nxvm2126 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
|
||||||
|
|
||||||
# The `peers au-syd1-prod` section is dropped: peer names must be static and a
|
# The `peers au-syd1-prod` section is dropped: peer names must be static and a
|
||||||
# Deployment cannot provide them. Service sessionAffinity: ClientIP pins a
|
# Deployment cannot provide them. Service sessionAffinity: ClientIP pins a
|
||||||
# client to one replica so the per-replica stick-tables behave as before.
|
# client to one replica so the per-replica stick-tables behave as before.
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ spec:
|
|||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
capabilities:
|
capabilities:
|
||||||
drop: [ALL]
|
drop: [ALL]
|
||||||
# Frontends bind 25/80/143/443/587; the dst_port ACLs need the real ports.
|
# Frontends bind 80 and 443; the dst_port ACLs need the real ports.
|
||||||
add: [NET_BIND_SERVICE]
|
add: [NET_BIND_SERVICE]
|
||||||
ports:
|
ports:
|
||||||
- name: http
|
- name: http
|
||||||
@@ -59,18 +59,6 @@ spec:
|
|||||||
- name: https
|
- name: https
|
||||||
containerPort: 443
|
containerPort: 443
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
- name: smtp
|
|
||||||
containerPort: 25
|
|
||||||
protocol: TCP
|
|
||||||
- name: imap
|
|
||||||
containerPort: 143
|
|
||||||
protocol: TCP
|
|
||||||
- name: submission
|
|
||||||
containerPort: 587
|
|
||||||
protocol: TCP
|
|
||||||
- name: imaps
|
|
||||||
containerPort: 993
|
|
||||||
protocol: TCP
|
|
||||||
- name: health
|
- name: health
|
||||||
containerPort: 8404
|
containerPort: 8404
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
type: LoadBalancer
|
type: LoadBalancer
|
||||||
loadBalancerIP: "198.18.199.1"
|
loadBalancerIP: "198.18.199.1"
|
||||||
# Source IP must survive for acl_internalsubnets, X-Real-IP and SMTP.
|
# Source IP must survive for X-Real-IP.
|
||||||
externalTrafficPolicy: Local
|
externalTrafficPolicy: Local
|
||||||
# Pins a client to one replica, standing in for the dropped stick-table peers.
|
# Pins a client to one replica, standing in for the dropped stick-table peers.
|
||||||
sessionAffinity: ClientIP
|
sessionAffinity: ClientIP
|
||||||
@@ -25,19 +25,3 @@ spec:
|
|||||||
port: 443
|
port: 443
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
targetPort: https
|
targetPort: https
|
||||||
- name: smtp
|
|
||||||
port: 25
|
|
||||||
protocol: TCP
|
|
||||||
targetPort: smtp
|
|
||||||
- name: imap
|
|
||||||
port: 143
|
|
||||||
protocol: TCP
|
|
||||||
targetPort: imap
|
|
||||||
- name: submission
|
|
||||||
port: 587
|
|
||||||
protocol: TCP
|
|
||||||
targetPort: submission
|
|
||||||
- name: imaps
|
|
||||||
port: 993
|
|
||||||
protocol: TCP
|
|
||||||
targetPort: imaps
|
|
||||||
|
|||||||
Reference in New Issue
Block a user