- Shipped
- October 4, 2026 at 5:57 PM UTC
- Author
- Kamo
- Commit
- 750e9b7
rspamd parses untrusted mail and logs in to the platform Redis, beside every member's session, and no ACL can keep it from them there: a user cannot be scoped to one database; rspamd's scripts pass class labels, flags and msgpack blobs as KEYS, so a key-pattern ACL refuses every Bayes learn; and its Bayes expiry SCANs, which lists every key name (*** and OTK names are bearer credentials) whatever the patterns. This adds rspamd-redis in mail: the platform Redis's build, pinned to k1m1 beside rspamd with its files on that node's disk, one database, PING only without a login, mail_rspamd with rspamd's existing password, kamo_ops for operators, and a NetworkPolicy that admits rspamd's pods alone. CI applies it and waits for it before rspamd. rspamd itself is unchanged until the next commit (SP98-M-1, stage 1 of 3).
