Add private Hermes prerequisites and SOPS mail credentials #541
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/hermes-email"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Add the sean.pm DNS and gateway configuration, private Hermes repository and backup declarations, a read-only repository account, OIDC registration, and SOPS-encrypted credentials. The Gmail credential is restricted to sean@sean.io with gmail.readonly. Object backups use the existing private seanfarm bucket under hermes/.
Exclude only the hermes namespace from the broad Cilium allow policy, so the application's explicit policy can restrict its traffic. Add a pre-destroy Hermes backup/restore guard. Preserve the current ACME issuer and its existing approval.
Validation: the full tests/check.sh suite passes; all changed Kustomize sources render; live Gmail token refresh, search and read pass; a live SOPS backup upload/read-back/restore passed with a test file.
The app companion begins with zero replicas. Add the permanent state-required marker during activation. No routine cluster changes were applied from the worktree. Companions: sean/hermes feat/email-assistant; sean/binjovi-plans feat/hermes-email.
fdcdd8f17a5c16bc3093