7b4549a35d
Phase 13. Two new packages and one new screen. internal/health owns the shared status vocabulary (ok/warn/error/unknown) and the local checks: supervisord's process table, TLS certificate expiry and the two milter sockets. Each check reports a problem as a status rather than an error, so one broken component costs a line and not the page. internal/dnscheck does the read-only lookups: forward-confirmed reverse DNS for SELFPOST_HOSTNAME, and per-domain DKIM (compared against the key this server actually signs with), SPF and DMARC. Every check is bounded by a timeout and cached, and the resolver sits behind an interface so the tests drive every branch without touching the network. The SPF check is deliberately shallow: it looks for a mechanism literally covering the server's address and does not follow include:/redirect=, so a record that authorises us through an include is reported as "cannot tell" rather than as a failure. /status renders both, with the local checks in an HTMX-polled fragment and the DNS lookups behind a Re-check button, and becomes the panel's landing page: / now redirects there and the domain list lives at /domains. The Reload button moves onto /status, where it reads as what it is — a drift-recovery for the daemons — with text explaining what it regenerates. A template test fails on any remaining href="/" so a stale link cannot silently land on the wrong screen. Also fixes a defect this made visible: the panel could never read the mail queue in the documented deployment. postqueue relies on its setgid-postdrop bit, which the compose file's no-new-privileges disables, so the Queue screen always said "Could not read the mail queue" — including in the released 1.0.0 image. The panel user is now a real member of postdrop, which needs no setgid transition. Verified in a container on the dev server against real DNS: PTR matching (selfpost.example.com) and not matching (example.com), DKIM absent and mismatched, SPF absent and via include:, DMARC p=quarantine/p=reject/absent, and a resolver timeout degrading to "unknown" without hanging the page. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
66 lines
2.2 KiB
HTML
66 lines
2.2 KiB
HTML
{{define "status_body"}}
|
|
<div id="status-body" hx-get="/status/fragment" hx-trigger="every 5s" hx-swap="outerHTML">
|
|
<div class="card">
|
|
<h2>Overall <span class="st st-{{.OverallStatus}}">{{.OverallStatus}}</span></h2>
|
|
<p class="muted">{{.OverallHeading}}</p>
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>Processes <span class="st st-{{.ProcessStatus}}">{{.ProcessStatus}}</span></h2>
|
|
{{if .ProcessError}}
|
|
<p class="error">Could not ask supervisord for the process list.</p>
|
|
{{else}}
|
|
<table>
|
|
<thead><tr><th>Program</th><th>State</th><th>Detail</th></tr></thead>
|
|
<tbody>
|
|
{{range .Processes}}
|
|
<tr>
|
|
<td>{{.Name}}</td>
|
|
<td><span class="st st-{{.Status}}">{{.State}}</span></td>
|
|
<td class="muted">{{.Detail}}</td>
|
|
</tr>
|
|
{{end}}
|
|
</tbody>
|
|
</table>
|
|
{{end}}
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>Mail queue <span class="st st-{{.QueueStatus}}">{{.QueueStatus}}</span></h2>
|
|
{{if .QueueError}}
|
|
<p class="error">{{.QueueError}}</p>
|
|
{{else}}
|
|
<p>{{if .QueueSummary}}{{.QueueSummary}}{{else}}Mail queue is empty.{{end}}
|
|
<a href="/queue">Full queue</a></p>
|
|
{{end}}
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>TLS certificate <span class="st st-{{.Cert.Status}}">{{.Cert.Status}}</span></h2>
|
|
<p class="muted">The certificate Postfix serves on port 465{{if .Cert.Subject}} ({{.Cert.Subject}}){{end}}.
|
|
It is supplied by the reverse proxy through a read-only mount; SelfPost only reads it.</p>
|
|
{{if not .Cert.NotAfter.IsZero}}
|
|
<label>Expires</label>
|
|
<span class="code">{{.Cert.NotAfter.UTC.Format "2006-01-02 15:04 UTC"}}</span>
|
|
{{end}}
|
|
<p class="{{if eq .Cert.Status "ok"}}muted{{else}}error{{end}}">{{.Cert.Detail}}</p>
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>Milter sockets <span class="st st-{{.SocketStatus}}">{{.SocketStatus}}</span></h2>
|
|
<table>
|
|
<thead><tr><th>Milter</th><th>Socket</th><th>State</th></tr></thead>
|
|
<tbody>
|
|
{{range .Sockets}}
|
|
<tr>
|
|
<td>{{.Name}}</td>
|
|
<td class="muted">{{.Path}}</td>
|
|
<td><span class="st st-{{.Status}}">{{.Status}}</span> {{.Detail}}</td>
|
|
</tr>
|
|
{{end}}
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
</div>
|
|
{{end}}
|