v10 is the current round. Old rounds preserved in git history and archive/questions/.
2.8 KiB
Questions — v8 (current round)
v7's PMG round is partially resolved — the 2026-09-03 mail audit (55 systems, read-only) answered several questions with ground truth and Charles answered others in chat. Answers recorded below; new questions PQ8–PQ10 need your go. Full map + deploy plan: Discourse t/322.
PMG round — resolved
PQ1 (backend). ✅ Cloudron VPS confirmed as backend:
mail.knownelement.com (152.53.37.179). Audit adds: public MX already
points there; fleet delivers direct today; knel.net zone has no MX.
PQ3 (outbound smarthost). ✅ Charles ruled: all hosts send through a shared VIP in front of the PMG pair. (Mechanics in PQ8 below.)
PQ4 (placement/sizing). ✅ Resolved by reality: the pair already exists — VM 604 on tsys6 (192.168.1.11) and VM 711 on tsys7 (192.168.1.10), both 2vCPU/4G/32G, running, onboot, PMG 9.1.0 installed, unclustered, default config. Nothing to build; configure only.
"Old relay in postfix?" ✅ None. relayhost is empty on every
audited system (16 postfix installs); no ssmtp/msmtp/nullmailer
anywhere. Fleet sends direct-to-MX today.
PMG round — still open
PQ2 (inbound path). Where does public :25 DNAT land — rrinfra Cisco? Any existing mail port-forwards? (Founder-side; only needed before the MX cut-over, not for outbound value.)
PQ5 (native PMG cluster?). Recommended: yes — config + quarantine replication between .1.11/.1.10, managed strictly serial. OK?
PQ6 (TLS from fleet CA #697?). Recommended: yes for the two admin UIs; SMTP stays opportunistic. OK?
PQ7 (notify address). Evidence says the pair already forwards to
coo@turnsys.com. Confirm that address for quarantine digests + PMG
alerts?
PQ8 (VIP specifics). Proposal: VIP 192.168.3.249 (pool ends
.3.200; .250-.254 is your infra block), keepalived VRRP VRID 10 on the
pair, dhcpd host-declaration pin (VRRP MAC 00:00:5e:00:01:0a), DNS A
record smtp.knel.net → 192.168.3.249. Confirm the number + name, or
name your preferred slot.
PQ9 (outbound cutover staging). Recommended: serial staged — PVE hosts + PBS first (verify a week), then the VM postfix set, one blue/green hop at a time. OK, or all at once?
PQ10 (side findings — sub-tickets?). (a) tsys-ucs-02 root alias
blackholes to systemmail@unassigned-hostname...; (b) Wazuh alerting
never configured (stock example smtp). Fix as ride-alongs in #696 or
separate sub-tickets? (Will create them either way — just tell me
where they land.)
Carried from v6 — still open
Q4. Second human approver in gitea? "Planned for very near future"; until then KNEL/access-roster merges are impossible by design. Does not block code/deploy work.
Carried from v7 — superseded questions
PQ1/PQ3/PQ4 answers above replace the v7 wording; v7 file remains in git history.