Skip to content

Docker Compose: no e-mail can be delivered (hardcoded STARTTLS, no SMTP) and every start logs a libgssapi load failure #1408

Description

@marcelo-maciel

Problem

Two problems show up as soon as the Docker Compose stack (deploy/docker/docker-compose.yml) is running.

No e-mail is ever delivered. The compose file does not configure mail, so the API uses the MailOptions:Smtp block from appsettings.json: host smtp.ethereal.email, port 587, empty credentials. Every confirmation, password-reset and welcome e-mail fails with authentication Required. The visible result is that a user registered by an operator cannot sign in, because the confirmation e-mail never arrives and someone has to confirm the address by hand (the operator's Confirm email action in the user detail page).

A local SMTP catcher such as Mailpit does not help either. SmtpMailService (src/BuildingBlocks/Mailing/Services/SmtpMailService.cs) always calls ConnectAsync(host, port, SecureSocketOptions.StartTls, ct), so a server that does not advertise STARTTLS is refused with The SMTP server does not support the STARTTLS extension before anything is sent. The same hardcoded mode also rules out providers that use implicit TLS on port 465.

Every API and migrator start logs a Kerberos error. Both images are built on aspnet:10.0-noble-chiseled, which does not include libgssapi_krb5.so.2. Npgsql defaults GSS Encryption Mode to Prefer, so the first connection logs Cannot load library libgssapi_krb5.so.2 and libgssapi_krb5.so.2: cannot open shared object file. The connection then succeeds, but the log reads as a failure.

Reproduction

  1. cd deploy/docker && cp .env.example .env, fill in the required values, then docker compose up -d --build.
  2. docker logs fsh-api: the libgssapi_krb5.so.2 lines appear on the first database connection.
  3. Sign in to the admin console and register a new user, or trigger forgot-password.
  4. The e-mail job fails (authentication Required in the API log), and the new user cannot sign in.

Expected

  • The compose stack delivers the e-mails it sends somewhere an operator can read them, with no external account needed, and documents how to switch to a real provider.
  • The SMTP connection mode (None, SslOnConnect, StartTls, ...) is configurable, and StartTls stays the default so existing deployments do not change.
  • A normal start of the compose stack logs no libgssapi_krb5 error.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions