kanidm: "Kanidm cannot send mail" is stale as of 1.10.4 — recheck what it justifies #339

Öppen
öppnade 2026-08-02 12:30:49 +00:00 av supernaut · 0 kommentarer
Ägare

Why

Several decisions rest on the claim that Kanidm has no mail capability. That was true when it was
written; it is false for the pinned 1.10.4, which ships an outgoing-message queue plus a
separate kanidm-mail-sender binary, documented upstream under "Outgoing Email", with
kanidm person credential send-reset-token as the user-facing verb.

The clearest surviving instance is in the identity-concealment CSS added for ADR 0038, whose comment
justifies hiding the email field with "a verified email change needs a mail sender and Kanidm has
none".

The decisions may well be correct anyway — keeping user mail on one branded channel with our chosen
EU provider is a defensible sovereignty and consistency argument. The problem is that they are
currently resting on a capability gap that has closed, so nobody re-examining them will reach the
real reason.

Scope

  • Re-read every "Kanidm cannot send mail" justification against 1.10.4 and restate it on grounds
    that are still true (sovereignty / branding / single channel), or change the decision.
  • Note in the runbook's Kanidm section that outbound mail exists upstream but is deliberately not
    deployed, and why.
  • Cross-check whether verified self-service email change is now feasible, since that was the
    specific capability ADR 0038 routed to the portal.

Done when

No comment or doc in this repo claims Kanidm cannot send mail, and the ADR 0038 routing decision
states a reason that survives the 1.10.4 facts.

Part of gitborg/gitborg-docs#69.

## Why Several decisions rest on the claim that Kanidm has no mail capability. That was true when it was written; it is **false for the pinned 1.10.4**, which ships an outgoing-message queue plus a separate `kanidm-mail-sender` binary, documented upstream under "Outgoing Email", with `kanidm person credential send-reset-token` as the user-facing verb. The clearest surviving instance is in the identity-concealment CSS added for ADR 0038, whose comment justifies hiding the email field with "a verified email change needs a mail sender and Kanidm has none". The decisions may well be correct anyway — keeping user mail on one branded channel with our chosen EU provider is a defensible sovereignty and consistency argument. The problem is that they are currently resting on a capability gap that has closed, so nobody re-examining them will reach the real reason. ## Scope - Re-read every "Kanidm cannot send mail" justification against 1.10.4 and restate it on grounds that are still true (sovereignty / branding / single channel), or change the decision. - Note in the runbook's Kanidm section that outbound mail exists upstream but is deliberately not deployed, and why. - Cross-check whether verified self-service email change is now feasible, since that was the specific capability ADR 0038 routed to the portal. ## Done when No comment or doc in this repo claims Kanidm cannot send mail, and the ADR 0038 routing decision states a reason that survives the 1.10.4 facts. Part of gitborg/gitborg-docs#69.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#339
Ingen beskrivning angiven.