Skip to content

Add production mail storage and recovery operations to Buddy #2200

Description

@chrisbbreuer

Goal

Provide repeatable Buddy commands and config for encrypted mail storage, off-host backups, restore drills, key custody, and Sieve forwarding.

Scope

  • Status, unlock, lock, externalize, backup, restore-check, and LUKS-header commands.
  • Restic repository initialization and scheduled S3 backup management.
  • Customer-managed KMS configuration.
  • Dedicated Hetzner volume provisioning and capacity checks.
  • Compile config/email.ts forwarding declarations to the mail server's canonical format.

Acceptance criteria

  • Commands are non-interactive, secret-safe, and produce actionable output.
  • No keys appear in argv, environment dumps, logs, or persistent host files.
  • Commands are idempotent and covered by tests.
  • Production status reports volume, backup age, restore check, key custody, and forwarding state.
  • Mail repository issues and commits are cross-linked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions