ops(rs2000-legacy): migrate OpenClaw mail config bind mounts #544

Closed
opened 2026-05-28 01:37:52 +02:00 by codex · 2 comments
Collaborator

Scope

Move OpenClaw mail infra config bind mounts off legacy path into canonical runtime import path, then update compose references.

Observed legacy mounts

  • home-platform-openclaw-mail-gateway-1: /opt/vps-home-platform-infra/products/openclaw-mail-infra/config -> /config ro
  • home-platform-openclaw-mail-worker-1: /opt/vps-home-platform-infra/products/openclaw-mail-infra/config -> /config ro

Target shape

  • Copy config as-is under /opt/pdurlej-platform/runtime/legacy-import/products/openclaw-mail-infra/config or a more specific canonical path if already established.
  • Update compose/module docs to reference the new path.

Acceptance criteria

  • Dry-run copy plan records source, target, owner/mode preservation, and rollback.
  • PR updates only OpenClaw mail gateway/worker bind paths and relevant docs.
  • Runtime recreate is limited to gateway + worker after explicit approval.
  • Smoke verifies gateway/worker health and no new mail route regression.
  • Legacy mount count decreases for these two containers.

Out of scope

  • Changing mail gateway app behavior.
  • Editing secrets inside config.
  • Changing public ingress.

Common safety rules

  • Recommended executor: Gemini 3.5 Flash local for repo/doc/plan work.
  • Do not delete, rename, prune, or edit /opt/vps-home-platform-infra in this issue.
  • Do not print secrets, env values, private messages, emails, or Iskra memory.
  • Runtime execution requires a separate explicit operator approval in the PR/issue thread.
  • First step is always read-only evidence refresh.
  • Preserve ownership, modes, symlinks, and timestamps when copying data/config.
  • Update compose/module docs through a PR before recreating affected services.
  • Recreate only affected service(s), never the whole platform, unless a later operator gate says otherwise.
## Scope Move OpenClaw mail infra config bind mounts off legacy path into canonical runtime import path, then update compose references. ## Observed legacy mounts - `home-platform-openclaw-mail-gateway-1`: `/opt/vps-home-platform-infra/products/openclaw-mail-infra/config` -> `/config` ro - `home-platform-openclaw-mail-worker-1`: `/opt/vps-home-platform-infra/products/openclaw-mail-infra/config` -> `/config` ro ## Target shape - Copy config as-is under `/opt/pdurlej-platform/runtime/legacy-import/products/openclaw-mail-infra/config` or a more specific canonical path if already established. - Update compose/module docs to reference the new path. ## Acceptance criteria - Dry-run copy plan records source, target, owner/mode preservation, and rollback. - PR updates only OpenClaw mail gateway/worker bind paths and relevant docs. - Runtime recreate is limited to gateway + worker after explicit approval. - Smoke verifies gateway/worker health and no new mail route regression. - Legacy mount count decreases for these two containers. ## Out of scope - Changing mail gateway app behavior. - Editing secrets inside config. - Changing public ingress. ## Common safety rules - Recommended executor: Gemini 3.5 Flash local for repo/doc/plan work. - Do not delete, rename, prune, or edit `/opt/vps-home-platform-infra` in this issue. - Do not print secrets, env values, private messages, emails, or Iskra memory. - Runtime execution requires a separate explicit operator approval in the PR/issue thread. - First step is always read-only evidence refresh. - Preserve ownership, modes, symlinks, and timestamps when copying data/config. - Update compose/module docs through a PR before recreating affected services. - Recreate only affected service(s), never the whole platform, unless a later operator gate says otherwise.
Author
Collaborator

Current evidence after PRs #583-#593:

  • running containers: home-platform-openclaw-mail-gateway-1, home-platform-openclaw-mail-worker-1
  • compose origin label: /tmp/openclaw-mail-phase2.compose.yaml
  • env_file label/source: /root/openclaw-mail-phase2.env (do not print values)
  • both mount /opt/vps-home-platform-infra/products/openclaw-mail-infra/config -> /config:ro
  • image: home-platform-openclaw-mail-gateway:0.2.0
  • gateway networks: hp_internal, hp_proxy; worker network: hp_internal

Important drift: modules/openclaw-mail-gateway/module.yaml currently describes vps1000/systemd/public gateway, while live RS2000 Docker containers exist. Next PR must first reconcile owner/source boundary, then remount config. Do not blindly recreate from repo compose because no repo compose definition currently owns these containers.

Current evidence after PRs #583-#593: - running containers: `home-platform-openclaw-mail-gateway-1`, `home-platform-openclaw-mail-worker-1` - compose origin label: `/tmp/openclaw-mail-phase2.compose.yaml` - env_file label/source: `/root/openclaw-mail-phase2.env` (do not print values) - both mount `/opt/vps-home-platform-infra/products/openclaw-mail-infra/config` -> `/config:ro` - image: `home-platform-openclaw-mail-gateway:0.2.0` - gateway networks: `hp_internal`, `hp_proxy`; worker network: `hp_internal` Important drift: `modules/openclaw-mail-gateway/module.yaml` currently describes vps1000/systemd/public gateway, while live RS2000 Docker containers exist. Next PR must first reconcile owner/source boundary, then remount config. Do not blindly recreate from repo compose because no repo compose definition currently owns these containers.
Author
Collaborator

Completed in the M01 orphan remount pass.

Runtime evidence:

  • home-platform-openclaw-mail-gateway-1 remapped /config to /opt/pdurlej-platform/runtime/legacy-import/products/openclaw-mail-infra/config.
  • home-platform-openclaw-mail-worker-1 remapped /config to the same legacy-import target.
  • Both containers recreated from Docker inspect snapshot via Docker API; old env values were preserved in-memory and not printed.
  • Both containers ended running / healthy.
  • Rollback snapshots stored under /opt/pdurlej-platform/runtime/m01-container-snapshots mode 0600.

No source data/config was deleted.

Completed in the M01 orphan remount pass. Runtime evidence: - `home-platform-openclaw-mail-gateway-1` remapped `/config` to `/opt/pdurlej-platform/runtime/legacy-import/products/openclaw-mail-infra/config`. - `home-platform-openclaw-mail-worker-1` remapped `/config` to the same legacy-import target. - Both containers recreated from Docker inspect snapshot via Docker API; old env values were preserved in-memory and not printed. - Both containers ended `running` / `healthy`. - Rollback snapshots stored under `/opt/pdurlej-platform/runtime/m01-container-snapshots` mode 0600. No source data/config was deleted.
codex closed this issue 2026-05-29 01:48:38 +02:00
Sign in to join this conversation.
No labels
W6d-automerge-calibration
agent/claude-code
agent/codex
agent/hermes
agent/iskra
agent/ollama
agent/patchwarden
automerge-candidate
class/security-sensitive
cutover-gate
dependency/blocked
dependency/blocks-others
dependency/cross-repo
dependency/needs-confirmation
domain:agents
domain:ci
domain:docs
domain:forgejo
domain:infra
domain:memory
domain:runtime
domain:signal
domain:ux
flow/architecture
flow/blocked
flow/deployed
flow/done
flow/implementation
flow/intake
flow/maintained
flow/observed
flow/ready
flow/refining
flow/retired
flow/review
iterating
judge/codex-candidate
judge/hermes-candidate
judge/low-confidence
judge/needs-refinement
judge/operator-needed
judge/p0
judge/p1
judge/p2
judge/p3
judge/park
judge/patchwarden-candidate
judge/stale-priority
kind/adr
kind/bug
kind/chore
kind/feature
kind/infra
kind/ops
kind/refactor
kind/research
large-impact
merge/auto
merge/manual
merge/manual-dependency-conflict
merge/manual-failing-tests
merge/manual-merge-conflict
merge/manual-missing-review
merge/manual-operator-preference
merge/manual-red-zone
merge/manual-security-sensitive
merge/manual-unclear-scope
merge/manual-unknown
meta
mode:operator-only
mode:patchwarden-iskra-approved
mode:safe-auto
needs-operator-decision
needs-triage
not-ready
observed/erroring
observed/needs-followup
observed/pending
observed/retire-candidate
observed/unused
observed/used
operator-emotional
owner-attention
phase/02
phase/03
priority:p0
priority:p1
priority:p2
priority:p3
proposed
ready-for-agent
ready-for-operator
recovery
review:claude-reviewed
review:codex-reviewed
review:dziadek-reviewed
review:needs-human
risk/exposure
risk/process
risk/product
risk/runtime
safety:external-write
safety:no-prod-mutation
safety:prod-impact
safety:secret-touch
size/large
size/medium
size/small
size/tiny
size/unknown
source/adr
source/agent-generated
source/manual
source/operator-chat
source/voice-note
status:blocked
status:codex-ready
status:merged:pending-evidence
status:needs-evidence
status:operator-needed
status:parked
tier/full
tier/lite
tier/stacked
tier:0-platform-substrate
tier:1-iskra-value-layer
tier:2-tools-products-modules
type:bug
type:chore
type:docs
type:feat
type:policy
type:research
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
pdurlej/platform#544
No description provided.