Operations
Kubernetes deployment
Run OwnSMTP with probes, resource bounds, and a restricted security context.
Secret
yaml
apiVersion: v1
kind: Secret
metadata:
name: ownsmtp-secrets
type: Opaque
stringData:
API_KEY: replace-with-a-32-character-minimum-key
SMTP_USERNAME: smtp-user
SMTP_PASSWORD: replace-meConfigMap
yaml
apiVersion: v1
kind: ConfigMap
metadata:
name: ownsmtp-config
data:
SMTP_HOST: smtp.yourdomain.com
SMTP_PORT: "587"
SMTP_AUTH: "true"
SMTP_SECURITY: starttls
SMTP_FROM_EMAIL: notifications@yourdomain.com
SMTP_FROM_NAME: Your Company
ALLOWED_FROM_DOMAINS: yourdomain.com
SMTP_TIMEOUT_SECONDS: "10"
LOG_LEVEL: INFO
DISABLE_DOCS: "true"Deployment
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: ownsmtp
spec:
replicas: 2
selector:
matchLabels: { app: ownsmtp }
template:
metadata:
labels: { app: ownsmtp }
spec:
securityContext:
runAsNonRoot: true
seccompProfile: { type: RuntimeDefault }
containers:
- name: ownsmtp
image: ghcr.io/samirkoirala/ownsmtp:1.1.2
ports:
- { name: http, containerPort: 8000 }
envFrom:
- configMapRef: { name: ownsmtp-config }
- secretRef: { name: ownsmtp-secrets }
livenessProbe:
httpGet: { path: /healthz, port: http }
initialDelaySeconds: 5
readinessProbe:
httpGet: { path: /readyz, port: http }
initialDelaySeconds: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities: { drop: ["ALL"] }
resources:
requests: { cpu: 50m, memory: 64Mi }
limits: { cpu: 500m, memory: 256Mi }
volumeMounts:
- { name: tmp, mountPath: /tmp }
volumes:
- name: tmp
emptyDir: { sizeLimit: 16Mi }ClusterIP Service
yaml
apiVersion: v1
kind: Service
metadata:
name: ownsmtp
spec:
type: ClusterIP
selector: { app: ownsmtp }
ports:
- { name: http, port: 8000, targetPort: http }Apply and verify
bash
kubectl apply -f secret.yaml -f configmap.yaml -f deployment.yaml -f service.yaml
kubectl rollout status deployment/ownsmtp
kubectl port-forward service/ownsmtp 8000:8000
curl --fail http://127.0.0.1:8000/readyz