Skip to content

Add production mail storage and recovery operations to Buddy #2200

Description

@chrisbbreuer

Goal

Provide repeatable Buddy commands and config for encrypted mail storage, off-host backups, restore drills, key custody, and Sieve forwarding.

Scope

  • Status, unlock, lock, externalize, backup, restore-check, and LUKS-header commands.
  • Restic repository initialization and scheduled S3 backup management.
  • Customer-managed KMS configuration.
  • Dedicated Hetzner volume provisioning and capacity checks.
  • Compile config/email.ts forwarding declarations to the mail server's canonical format.

Acceptance criteria

  • Commands are non-interactive, secret-safe, and produce actionable output.
  • No keys appear in argv, environment dumps, logs, or persistent host files.
  • Commands are idempotent and covered by tests.
  • Production status reports volume, backup age, restore check, key custody, and forwarding state.
  • Mail repository issues and commits are cross-linked.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions