Skip to content

What it is

herbmail.com, as a file server. The Astro/Starlight build in apps/herbmail precompressed at build time and handed out by the axum in apps/herbmail/server on port 8080 — no credential in the image, and nothing in it that can answer /mail.

It served from Caddy for exactly one release. The binary is one small crate, it runs on the same base-runtime as memesh-web and rareicon-web, and it carries no file capabilities — which is what made the Caddy image refuse to exec under the pod’s allowPrivilegeEscalation: false.

Why the API is not in it

The KBVE tree shipped herbmail-api: an axum that served this site and answered /mail/* beside it. That made two things one release, and gave every other surface that wanted the same mailbox — rareicon.com first — no option but a second instance of the same API against the same database.

services/mail is that API, once, for all of them. The site keeps fetching relative paths because the split is at the gateway: herbmail-route sends /mail to mail-service in the mail namespace and everything else here, so the browser stays same-origin, the bearer never crosses an origin, and there is no CORS allowlist to keep in step with a new site.

Releasing

StepWhat happens
Bump version: aboveThe only edit a release needs
herbmail-web jobStamps version.toml and the crate manifest, builds, pushes $IMAGE:$VERSION
herbmail-web-deploy jobOpens a merge request repointing herbmail-web-deployment.yaml
ArgoCDSyncs the default branch

The footer reads version.toml, so the number a visitor sees is the tag that shipped rather than a string someone remembered to edit.