Ports release.yml and publish.yml, the two workflows left behind when the GitHub account was suspended; nothing has released INBUXA Admin since. weekly-release keeps release.yml's decision unchanged: on a schedule that sets RELEASE_WEEKLY=1, count the commits on main since the newest published release, stop if there are none, and otherwise pick today's version (YYYY.M.D, .2 and on for a second release in a day), commit it to main in inbuxa-version.json and cut the release at that commit. DRY_RUN=1 stops after the decision. What changes is how it writes. GitHub's job pushed the bump with GITHUB_TOKEN; here the bump goes through the commits API with RELEASE_TOKEN, and last_commit_id pins it to the commit the job counted from, so a main that moved underneath makes the job fail rather than release something the notes don't describe. The release and its tag go through the releases API with the same token, which as an ordinary push starts a tag pipeline -- replacing publish.yml's workflow_call, which only existed because a GITHUB_TOKEN release raises no event. publish runs in that tag pipeline, after the build job has built and tested the tag again. It pushes a two-architecture image (arm64 under QEMU, as ihasmail's does) to the project registry, registry.coffeylabs.org/inbuxa/inbuxa-admin, tagged with the version and latest. Only date tags publish, not the inherited v1.0.x, and a tag whose commit's inbuxa-version.json says anything else is refused, so an image never reports a version other than its tag. Tag lookups use git show-ref, after ihasmail's port found rev-parse --verify reading some tag names as describe output on the git in these images. Needs, on the project: a RELEASE_TOKEN variable (project access token, Maintainer, api scope, protected and masked) whose role may push to main, and a pipeline schedule on main, Mondays 09:37 UTC, setting RELEASE_WEEKLY=1.
INBUXA Admin
The administration interface for the INBUXA mail server: every server setting, first-boot setup, and recovery, in the browser.
It is schema-driven. After signing in it fetches the server's schema and builds every form, list and menu from it, so it covers every setting the server has without hardcoding any of them.
Design
- One edition. Every feature the server has is available here, with
nothing held back. See the INBUXA server's
docs/spec/. - Runs anywhere, not on the mail server. INBUXA Admin is its own
deployment, never installed onto the mail server. It's pointed at the server
either at build time (
VITE_API_BASE_URL) or at deploy time:<meta name="api-base-url" content="https://mail.example.com">inindex.html. Hosted like that, it signs in as the OAuth clientinbuxa-admin, which the server registers when it's started withINBUXA_ADMIN_URLset to INBUXA Admin's address (for development,http://localhost:5173). - INBUXA's look: the logo and ihasmail's palette.
- Two-factor setup names INBUXA as the issuer, and no longer makes authenticator apps fetch a logo from a third-party site.
Developing
npm ci
npm run dev # http://localhost:5173, against VITE_API_BASE_URL in .env.development
npm run typecheck && npx eslint src/ && npx vitest run
npm run build
Keeping up with upstream
The upstream codebase's history contains no code under a proprietary license,
so this is an ordinary git fork. upstream is a fetch-only remote:
git fetch upstream --tags
git merge v1.0.12 # the next release tag
Versions
INBUXA Admin has its own dated version (inbuxa-version.json), shown with the
upstream release it's based on: INBUXA Admin 2026.9.18 (base 1.0.11).
package.json keeps upstream's version, so upstream's bumps merge cleanly.
Source code
Every build carries its own source. The interface links to it (the user menu
and the sign-in page), and the build writes it next to the app as
source.tar.gz: the exact tree the running version was built from.
License and credits
Free software under the GNU Affero General Public License, version 3.
INBUXA Admin is forked from the upstream AGPL-3.0 web administration codebase originally developed by Stalwart Labs. Their copyright notices are kept on every file inherited from it, and INBUXA's own notice is added to the files it changes. Those files are offered upstream under the AGPL-3.0-only or a proprietary license. INBUXA uses them under the AGPL-3.0 only. INBUXA isn't affiliated with or endorsed by Stalwart Labs.