Set-OPS-Public/roles/serveur_postfix/defaults/main.yml
Daniel Allaire 8df1db3b47 serveur_rspamd (rspamd 3.x) : antispam + DKIM en milter Postfix — prouvé
Rôle antispam sur edge-mta : Redis local, worker proxy en mode milter
auto-scan (:11332), signature DKIM sortante (clé générée idempotente,
enregistrement DNS affiché pour l'Étape B). Config par local.d/.
Postfix branché via smtpd_milters (option serveur_postfix_rspamd_milter,
milter_default_action=accept = tolérant si rspamd down).

Prouvé : courriel traversant le milter → scanné (rspamc stat: 1) +
signé DKIM (DKIM-Signature d=...), livré, lu en IMAP.
Étape A (courriel interne) complète : dovecot + postfix + rspamd.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:04:44 -04:00

35 lines
1.7 KiB
YAML

---
# Postfix 3.x (Debian 13) — MTA du nœud edge-mta : réception :25, cartes LDAP (domaines,
# boîtes, alias), remise LMTP réseau vers le nœud mail-store (Dovecot). TLS via step_ca.
# NE STOCKE AUCUNE BOÎTE. Cf. docs/courriel-conception.md + docs/identite-sso.md.
serveur_postfix_paquets:
- postfix
- postfix-ldap
serveur_postfix_service: "postfix"
serveur_postfix_domaine: "{{ domaine_interne }}"
serveur_postfix_nom_hote: "{{ ansible_fqdn | default(ansible_hostname) }}"
# Réseaux internes de confiance (relais autorisé). À adapter au réseau de l'instance.
serveur_postfix_reseaux_confiance: "127.0.0.0/8 [::1]/128"
# --- Nœud mail-store (Dovecot) : remise LMTP réseau ---
# OBLIGATOIRE : le FQDN/nom du nœud qui héberge les boîtes (Dovecot LMTP).
serveur_postfix_mailstore_hote: ""
serveur_postfix_lmtp_port: 24
# --- Annuaire LDAP (validation domaines/boîtes/alias) ---
serveur_postfix_ldap_serveur: "ldaps://id-ldap-01.{{ domaine_interne }}:636"
serveur_postfix_ldap_base: "ou=people,dc={{ domaine_interne.split('.') | join(',dc=') }}"
serveur_postfix_ldap_bind_dn: "cn=admin,dc={{ domaine_interne.split('.') | join(',dc=') }}"
serveur_postfix_ldap_bind_password: "{{ vault_openldap_admin | default('') }}"
# --- Milter rspamd (antispam + DKIM) — si rspamd est co-localisé (nœud edge-mta) ---
serveur_postfix_rspamd_milter: false
serveur_postfix_rspamd_milter_port: 11332
# --- TLS via le certificat d'hôte step_ca (client_pki) ---
serveur_postfix_tls_actif: true
serveur_postfix_tls_source_cert: "/etc/step/certs/{{ ansible_fqdn | default(ansible_hostname) }}.crt"
serveur_postfix_tls_source_cle: "/etc/step/certs/{{ ansible_fqdn | default(ansible_hostname) }}.key"
serveur_postfix_tls_dir: "/etc/postfix/tls"