summaryrefslogtreecommitdiffstats
path: root/roles/out/templates/etc/postfix/canonical.j2
diff options
context:
space:
mode:
authorGuilhem Moulin <guilhem@fripost.org>2018-12-11 21:15:24 +0100
committerGuilhem Moulin <guilhem@fripost.org>2018-12-12 13:46:44 +0100
commit7beb915bb8dddac847ca3aca85c187e314a6c0fa (patch)
tree58007bea6929c6cdfb8d7b5abf483eb33fd3b609 /roles/out/templates/etc/postfix/canonical.j2
parent68d56db92b95f570a8e7236dbff3fc7fd0fcd2c3 (diff)
Outgoing SMTP: masquerade internal hostnames.
Use admin@fripost.org instead. We were sending out (to the admin team) system messages with non-existing or invalid envelope sender addresses, such as <logcheck@antilop.fripost.org> or <root@mistral.fripost.org>.
Diffstat (limited to 'roles/out/templates/etc/postfix/canonical.j2')
-rw-r--r--roles/out/templates/etc/postfix/canonical.j210
1 files changed, 10 insertions, 0 deletions
diff --git a/roles/out/templates/etc/postfix/canonical.j2 b/roles/out/templates/etc/postfix/canonical.j2
new file mode 100644
index 0000000..ed8bb4d
--- /dev/null
+++ b/roles/out/templates/etc/postfix/canonical.j2
@@ -0,0 +1,10 @@
+# {{ ansible_managed }}
+# Do NOT edit this file directly!
+
+# Addresses under $myhostname are typically not valid as envelope
+# recipients (eg, logcheck@, root@, etc.). This breaks the sender
+# address verification, so we use the admin team's address in the
+# envelope.
+{% for host in groups.all | sort %}
+@{{ hostvars[host].inventory_hostname }} admin@fripost.org
+{% endfor %}