feat(mail): move the sending domain to email.bitborg.se (§5 step 3) #387

Sammanfogat
supernaut sammanfogade 1 incheckning från feat/mail-domain-step3-move in i main 2026-08-05 20:31:44 +00:00
Ägare

Step 3 of the sending-domain move: mail_sending_domain → email.bitborg.se, and the allowlist
narrows back to the single derived entry. This is the last LEGACY-PIN in the mail path.

Part of #381. Depends on bitborg-web #198 (step 2) being deployed first — the ordering is the
whole mechanism, not a preference.

What one variable moves

mail_sending_domain is derived-everywhere by design (#113), so this line carries:

Consumer Where Effect
forgejo_mailer_from group_vars/all/vars.yml → app.ini Forgejo restart
EMAIL_ALLOWED_SENDER_DOMAINS roles/web/templates/…container.j2 portal restart
alert_email_from roles/monitoring/defaults/main.yml Alertmanager restart
monitoring_probe_mail_from roles/monitoring-agent/defaults/main.yml cross-probe script

Measured blast radius from the 2026-08-05 dry run: six changed tasks across both hosts. Note
that Alertmanager restarting means the alerting path itself moves, so it must be verified rather
than assumed.

Comment changes, and what was deliberately kept

Dropped only the notes describing this move as in flight — the TRANSITIONAL marker, the
"✅ NO LONGER BLOCKED" status note, and "this entry is still ahead of its consumer".

Kept the four-step procedure and the step-0 traps (published DNS is not a verified sending
domain; Sweego's 401 is identical for a dead key and an unauthorised sender and is not diagnosable
from a host; re-mint early). Those are not about this move — they are what makes the next one
survivable.

The measured 200/401 pair is now marked as taken with the then-current key, with the
post-rotation outcome recorded beside it, so it reads as "the differential is the diagnostic" rather
than as a standing fact about either domain.

vault.example.yml no longer tells a fresh setup to verify the old domain, and now says the API
and SMTP paths are authorised separately — one working does not imply the other, which is the
distinction that cost time here.

Gates

  • ansible-playbook site.yml --syntax-check — clean
  • --check gate and the apply to follow, reconciled by task name rather than by count
    (--check cannot see command/podman_secret tasks in either direction)
  • --diff deliberately not used: app.ini renders the SMTP user inline
Step 3 of the sending-domain move: `mail_sending_domain` → `email.bitborg.se`, and the allowlist narrows back to the single derived entry. This is the last `LEGACY-PIN` in the mail path. Part of #381. Depends on `bitborg-web` #198 (step 2) being deployed **first** — the ordering is the whole mechanism, not a preference. ## What one variable moves `mail_sending_domain` is derived-everywhere by design (#113), so this line carries: | Consumer | Where | Effect | | ---------------------------- | ---------------------------------------- | ----------------------- | | `forgejo_mailer_from` | `group_vars/all/vars.yml` → `app.ini` | **Forgejo restart** | | `EMAIL_ALLOWED_SENDER_DOMAINS` | `roles/web/templates/…container.j2` | **portal restart** | | `alert_email_from` | `roles/monitoring/defaults/main.yml` | **Alertmanager restart** | | `monitoring_probe_mail_from` | `roles/monitoring-agent/defaults/main.yml` | cross-probe script | Measured blast radius from the 2026-08-05 dry run: **six changed tasks across both hosts**. Note that Alertmanager restarting means the alerting path itself moves, so it must be verified rather than assumed. ## Comment changes, and what was deliberately kept Dropped only the notes describing this move as *in flight* — the `TRANSITIONAL` marker, the "✅ NO LONGER BLOCKED" status note, and "this entry is still ahead of its consumer". **Kept** the four-step procedure and the step-0 traps (published DNS is not a verified sending domain; Sweego's `401` is identical for a dead key and an unauthorised sender and is not diagnosable from a host; re-mint early). Those are not about this move — they are what makes the next one survivable. The measured `200`/`401` pair is now marked as taken with the **then-current** key, with the post-rotation outcome recorded beside it, so it reads as "the differential is the diagnostic" rather than as a standing fact about either domain. `vault.example.yml` no longer tells a fresh setup to verify the *old* domain, and now says the API and SMTP paths are authorised **separately** — one working does not imply the other, which is the distinction that cost time here. ## Gates - `ansible-playbook site.yml --syntax-check` — clean - `--check` gate and the apply to follow, reconciled **by task name** rather than by count (`--check` cannot see `command`/`podman_secret` tasks in either direction) - `--diff` deliberately not used: `app.ini` renders the SMTP user inline
supernaut lade till 1 incheckning 2026-08-05 20:18:51 +00:00
feat(mail): move the sending domain to email.bitborg.se
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m32s
012488b192
Step 3 of the sending-domain move, and the last LEGACY-PIN in the mail
path. mail_sending_domain carries forgejo_mailer_from, alert_email_from
and monitoring_probe_mail_from with it, so this one line moves Forgejo's
From address, Alertmanager's and the monitoring cross-probe's.

Narrows mail_allowed_sender_domains back to the single derived entry now
that the portal sends as the new domain (step 2, bitborg-web #198). The
transitional second entry existed only to span steps 1-3; leaving it would
re-open the infra/portal divergence the guard exists to detect.

Keeps the four-step procedure and the step-0 traps, which apply to any
future move, and drops only the notes describing THIS move as in flight.
The measured 200/401 pair is marked as pre-rotation so it is not read as a
standing fact about either domain. vault.example.yml no longer instructs a
fresh setup to verify the old domain, and now says the API and SMTP paths
are authorised separately.

Part of #381.
supernaut sammanfogade incheckning 2e9eb48b56 till main 2026-08-05 20:31:44 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!387
Ingen beskrivning angiven.