What it is
herbmail.com, as a file server. The Astro/Starlight build in apps/herbmail
precompressed at build time and handed out by the axum in
apps/herbmail/server on port 8080 — no credential in the image, and nothing
in it that can answer /mail.
It served from Caddy for exactly one release. The binary is one small crate, it
runs on the same base-runtime as memesh-web and rareicon-web, and it carries
no file capabilities — which is what made the Caddy image refuse to exec under
the pod’s allowPrivilegeEscalation: false.
Why the API is not in it
The KBVE tree shipped herbmail-api: an axum that served this site and
answered /mail/* beside it. That made two things one release, and gave every
other surface that wanted the same mailbox — rareicon.com first — no option but
a second instance of the same API against the same database.
services/mail is that API, once, for all of them. The site keeps fetching
relative paths because the split is at the gateway: herbmail-route sends
/mail to mail-service in the mail namespace and everything else here, so
the browser stays same-origin, the bearer never crosses an origin, and there is
no CORS allowlist to keep in step with a new site.
Releasing
| Step | What happens |
|---|---|
Bump version: above | The only edit a release needs |
herbmail-web job | Stamps version.toml and the crate manifest, builds, pushes $IMAGE:$VERSION |
herbmail-web-deploy job | Opens a merge request repointing herbmail-web-deployment.yaml |
| ArgoCD | Syncs the default branch |
The footer reads version.toml, so the number a visitor sees is the tag that
shipped rather than a string someone remembered to edit.