feat(mail): move the sending domain to email.bitborg.se (§5 step 3) #387
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!387
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/mail-domain-step3-move"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Step 3 of the sending-domain move:
mail_sending_domain→email.bitborg.se, and the allowlistnarrows back to the single derived entry. This is the last
LEGACY-PINin the mail path.Part of #381. Depends on
bitborg-web#198 (step 2) being deployed first — the ordering is thewhole mechanism, not a preference.
What one variable moves
mail_sending_domainis derived-everywhere by design (#113), so this line carries:forgejo_mailer_fromgroup_vars/all/vars.yml→app.iniEMAIL_ALLOWED_SENDER_DOMAINSroles/web/templates/…container.j2alert_email_fromroles/monitoring/defaults/main.ymlmonitoring_probe_mail_fromroles/monitoring-agent/defaults/main.ymlMeasured blast radius from the 2026-08-05 dry run: six changed tasks across both hosts. Note
that Alertmanager restarting means the alerting path itself moves, so it must be verified rather
than assumed.
Comment changes, and what was deliberately kept
Dropped only the notes describing this move as in flight — the
TRANSITIONALmarker, the"✅ NO LONGER BLOCKED" status note, and "this entry is still ahead of its consumer".
Kept the four-step procedure and the step-0 traps (published DNS is not a verified sending
domain; Sweego's
401is identical for a dead key and an unauthorised sender and is not diagnosablefrom a host; re-mint early). Those are not about this move — they are what makes the next one
survivable.
The measured
200/401pair is now marked as taken with the then-current key, with thepost-rotation outcome recorded beside it, so it reads as "the differential is the diagnostic" rather
than as a standing fact about either domain.
vault.example.ymlno longer tells a fresh setup to verify the old domain, and now says the APIand SMTP paths are authorised separately — one working does not imply the other, which is the
distinction that cost time here.
Gates
ansible-playbook site.yml --syntax-check— clean--checkgate and the apply to follow, reconciled by task name rather than by count(
--checkcannot seecommand/podman_secrettasks in either direction)--diffdeliberately not used:app.inirenders the SMTP user inline