Skip to content
OwnSMTP

Operations

Kubernetes deployment

Run OwnSMTP with probes, resource bounds, and a restricted security context.

Secret

yaml
apiVersion: v1
kind: Secret
metadata:
  name: ownsmtp-secrets
type: Opaque
stringData:
  API_KEY: replace-with-a-32-character-minimum-key
  SMTP_USERNAME: smtp-user
  SMTP_PASSWORD: replace-me

ConfigMap

yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: ownsmtp-config
data:
  SMTP_HOST: smtp.yourdomain.com
  SMTP_PORT: "587"
  SMTP_AUTH: "true"
  SMTP_SECURITY: starttls
  SMTP_FROM_EMAIL: notifications@yourdomain.com
  SMTP_FROM_NAME: Your Company
  ALLOWED_FROM_DOMAINS: yourdomain.com
  SMTP_TIMEOUT_SECONDS: "10"
  LOG_LEVEL: INFO
  DISABLE_DOCS: "true"

Deployment

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: ownsmtp
spec:
  replicas: 2
  selector:
    matchLabels: { app: ownsmtp }
  template:
    metadata:
      labels: { app: ownsmtp }
    spec:
      securityContext:
        runAsNonRoot: true
        seccompProfile: { type: RuntimeDefault }
      containers:
        - name: ownsmtp
          image: ghcr.io/samirkoirala/ownsmtp:1.1.2
          ports:
            - { name: http, containerPort: 8000 }
          envFrom:
            - configMapRef: { name: ownsmtp-config }
            - secretRef: { name: ownsmtp-secrets }
          livenessProbe:
            httpGet: { path: /healthz, port: http }
            initialDelaySeconds: 5
          readinessProbe:
            httpGet: { path: /readyz, port: http }
            initialDelaySeconds: 3
          securityContext:
            allowPrivilegeEscalation: false
            readOnlyRootFilesystem: true
            capabilities: { drop: ["ALL"] }
          resources:
            requests: { cpu: 50m, memory: 64Mi }
            limits: { cpu: 500m, memory: 256Mi }
          volumeMounts:
            - { name: tmp, mountPath: /tmp }
      volumes:
        - name: tmp
          emptyDir: { sizeLimit: 16Mi }

ClusterIP Service

yaml
apiVersion: v1
kind: Service
metadata:
  name: ownsmtp
spec:
  type: ClusterIP
  selector: { app: ownsmtp }
  ports:
    - { name: http, port: 8000, targetPort: http }

Apply and verify

bash
kubectl apply -f secret.yaml -f configmap.yaml -f deployment.yaml -f service.yaml
kubectl rollout status deployment/ownsmtp
kubectl port-forward service/ownsmtp 8000:8000
curl --fail http://127.0.0.1:8000/readyz