feat(mail): reissue Sweego credentials and move sending to mail.gitborg.se #272
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!272
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "sweego-credentials"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Reissues the Sweego credentials and moves the outbound sending domain from
email.gitborg.setomail.gitborg.se.Changes
group_vars/all/vars.ymlforgejo_mailer_from→bitborg <no-reply@mail.gitborg.se>group_vars/all/vault.ymlgroup_vars/vault.example.ymlroles/monitoring/defaults/main.ymlalert_email_from→alerts@mail.gitborg.seroles/monitoring-agent/defaults/main.ymlmonitoring_probe_mail_from→alerts@mail.gitborg.seroles/web/templates/bitborg-web.container.j2Alertmanager and the blackbox probe reuse the same relay credentials
(
alert_smtp_*→vault_forgejo_mailer_*), so they are covered by the same apply. Sweego verifiesthe domain, not the local part, so
alerts@needs no separate setup.DNS state (verified live)
sweego1._domainkey.mail.gitborg.se…-dkim.sweego.co, validv=DKIM1key_dmarc.mail.gitborg.sev=DMARC1; p=none;TXT mail.gitborg.se(SPF)gitborg.seapex SPFinclude:spf.messagingengine.com ?all— does not authorise SweegoThe absent SPF record is most likely fine: SPF authenticates the envelope Return-Path, which Sweego
owns, and DMARC passes on DKIM alignment alone (
d=mail.gitborg.sealigns with the From underrelaxed alignment). Worth confirming the Sweego dashboard shows the domain fully verified and is not
asking for a return-path record —
bounce,bounces,return,rp,tracking,link,clickand
twere probed and none exist.Companion change — required, not optional
The portal's From address is hardcoded in bitborg-web and not env-configurable, so this PR cannot
move it. Without gitborg/gitborg-web#114, portal mail keeps sending as
no-reply@email.gitborg.se,which now has no DNS records at all — Sweego will likely reject it as an unverified sending domain,
and anything delivered would fail DKIM alignment. The affected path is the sign-up credential-reset
email, so sign-up completes and the user never gets the link.
Follow-up for the duplication itself: gitborg/gitborg-web#113.
Apply notes
Until this is applied, production Forgejo and Alertmanager still hold the previous credentials.
If those were revoked when the new ones were issued, outbound mail from Forgejo is already failing —
Loki showed no SMTP errors in the last 24 h, but also no send attempts, so that is not evidence of
health either way.
Verify after applying:
dkim=passwithd=mail.gitborg.se.Separately: DMARC is
p=none, so none of this is policy-enforced. Once both senders are on the newdomain and confirmed passing, tightening to
p=quarantineis cheap hardening — out of scope here.