Skip to content

feat(web1): add mailflow webmail stack, drop tmail webmail - #485

Merged
anatolinicolae merged 2 commits into
mainfrom
anatoli/mailflow
Oct 4, 2026
Merged

anatolinicolae merged 2 commits into
mainfrom
anatoli/mailflow

Conversation

@anatolinicolae

Copy link
Copy Markdown
Member

Summary

Replaces the retired tmail-web "webmail" stack with MailFlow, a unified IMAP/SMTP webmail client. This includes the new MailFlow compose configuration, environment setup, migration cleanup, and documentation updates.

Changes

  • New MailFlow stack (web1/containers/mailflow/):

    • docker-compose.yml: Four-service stack (frontend nginx, Node.js backend, PostgreSQL 18, Valkey 9.1)
    • Frontend and backend pinned to v3.8.1 with SHA256 digests
    • All services hardened per project conventions: cap_drop: [ALL], no-new-privileges: true, read-only roots with tmpfs
    • Frontend bound to 127.0.0.1:3008 (TLS terminated by host reverse proxy)
    • Backend health checks on /api/health; database and cache health checks included
    • .env.example: Template for required secrets (SESSION_SECRET, DB_PASSWORD, ENCRYPTION_KEY) and optional features (web push, Google OAuth, IMAP tuning)
  • Removed old webmail stack (web1/containers/webmail/):

    • Deleted tmail-web compose configuration
  • Migration task (web1/ansible/migrations/20261004_0004_remove_webmail_stack.yml):

    • Safely removes leftover webmail containers and /opt/containers/webmail directory on deploy
  • Ansible configuration updates:

    • docker_stacks in roles/system/containers/defaults/main.yml: Changed webmail from state: stopped to mailflow with state: present and env_file: true
    • Removed webmail env.file creation task from roles/system/containers/tasks/main.yml
  • Documentation (CLAUDE.md):

    • Updated read-only container examples to reference mailflow frontend + backend instead of webmail

Implementation Details

  • MailFlow backend requires TRUST_PROXY_HOPS=2 (frontend nginx + host reverse proxy)
  • Encryption key (ENCRYPTION_KEY) is critical — changing it invalidates stored IMAP/SMTP credentials
  • Image versions are pinned and managed by Renovate; UPDATE_CHECK_DISABLED=true prevents redundant checks
  • Uses Valkey (Redis fork) for session/cache storage with persistence (--save 60 1)
  • PostgreSQL 18 with version-specific PGDATA path for future upgrade safety

https://claude.ai/code/session_011mzrFnReayRM6LnqhZks6R

Replace the stopped tmail-web "webmail" stack on web1 with MailFlow
3.8.1 (unified IMAP/SMTP webmail): nginx frontend, Node backend,
PostgreSQL 18 and Valkey, adapted from upstream docker-compose.ghcr.yml.

- Frontend published HTTP-only on 127.0.0.1:3008; TLS stays with the
  host reverse proxy, upstream's Caddy profile is dropped.
- Frontend and backend: cap_drop ALL, no-new-privileges, read_only with
  tmpfs. nginx needs CHOWN/SETUID/SETGID (temp dirs, worker drop) plus
  NET_BIND_SERVICE for :80/:443.
- Postgres/Valkey are exempt per the data-store rule; images match the
  digests already pinned for twenty.
- Migration 0004 composes down the old webmail project and removes
  /opt/containers/webmail, which the copy task would otherwise leave.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011mzrFnReayRM6LnqhZks6R
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 30 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b51bc775-6a51-49d5-96bf-c122b6d66921
📥 Commits

Reviewing files that changed from the base of the PR and between eb3c1d7 and e3665b6.

📒 Files selected for processing (8)
  • CLAUDE.md
  • web1/ansible/migrations/20261004_0004_remove_webmail_stack.yml
  • web1/ansible/roles/system/containers/defaults/main.yml
  • web1/ansible/roles/system/containers/tasks/main.yml
  • web1/containers/mailflow/.env.example
  • web1/containers/mailflow/.env.postgres.example
  • web1/containers/mailflow/docker-compose.yml
  • web1/containers/webmail/docker-compose.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@anatolinicolae anatolinicolae changed the title Replace tmail-web with MailFlow webmail stack feat(web1): add mailflow webmail stack, drop tmail webmail Oct 4, 2026
Drop the inline environment blocks: backend wiring now lives in .env and
the postgres container reads its own .env.postgres (twenty's pattern),
both with committed .example files. The pg_isready healthcheck reads
POSTGRES_USER/POSTGRES_DB from the container env instead of hardcoding.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011mzrFnReayRM6LnqhZks6R
@anatolinicolae
anatolinicolae merged commit b8833e9 into main Oct 4, 2026
@anatolinicolae
anatolinicolae deleted the anatoli/mailflow branch October 4, 2026 21:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants