The Dovecot quota change, written out and not applied

DocsKlusterServices
Shipped
August 11, 2026 at 1:59 AM UTC
Author
Kamo
Commit
6daedfb

Object storage now refuses content that would take an organization past its ceiling, which covers every domain that goes through the object store. Inbound mail is not one of them: LMTP writes into the maildir with no Java code in the path, so Dovecot's own quota plugin is the only place that can stop it. The change is exact and reviewable, but deliberately not applied. This repo auto-applies manifests on push and a malformed mail_plugins line stops Dovecot from starting, taking mail down for every tenant at once — it wants a watched deploy. The rollout is ordered so the first two steps change no behaviour and are individually reversible. Also notes that both configmaps carry the mailserver MySQL password in plaintext, committed and readable from kubectl.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing