Review: Hetzner: Request port 25 outbound unblock
Verdict: READY
Board item #1732 on board-stalwart-email. Forgejo issue: ldraney/pal-e-platform#497. Re-review after arch-edge-vps note creation.
Template Completeness
- [x] Type -- Feature
- [x] Lineage -- Standalone, part of stalwart-email project
- [x] Repo -- ldraney/pal-e-platform
- [x] User Story -- As a platform admin, I want outbound port 25 unblocked...
- [x] Context -- Explains Hetzner's 30-day anti-spam block, low-volume transactional use case
- [x] File Targets -- "No code changes" (manual action, appropriate)
- [x] Feature Flag -- none (correct, no code changes)
- [x] Acceptance Criteria -- 3 items, concrete
- [x] Test Expectations -- Manual SSH verification command
- [x] Constraints -- Timing, request wording, inbound port warning
- [x] Checklist -- Present
- [x] Related -- stalwart-email project referenced
Traceability
- [x] story:self-hosted label -- "As platform admin, I want zero third-party email dependencies so I control deliverability and avoid Gmail app password rotation"
- [x] story note verified -- found in project-stalwart-email user-stories section (key: self-hosted)
- [x] arch:edge-vps label -- references the Hetzner Edge VPS component
- [x] arch note verified -- arch-edge-vps note exists in pal-e-docs (project: stalwart-email, created 2026-07-04)
- [x] Forgejo issue -- ldraney/pal-e-platform#497, state: open
File Targets
No code changes -- this is a manual action in Hetzner Cloud Console. No file verification needed. Appropriate for the scope of work (submitting an external vendor request).
Repo Placement
OK. Issue is filed on pal-e-platform and the Repo section correctly identifies ldraney/pal-e-platform. Platform infrastructure work belongs here. No cross-repo concerns.
Dependencies
Issue Context explicitly states: "This is a blocking dependency for all other Stalwart work." Board confirms multiple downstream items depend on port 25:
- #1733 (pal-e-platform#498) -- story:self-hosted, arch:stalwart (likely Stalwart deployment)
- #1734 (pal-e-platform#499) -- story:self-hosted, arch:edge-vps
- #1735 (pal-e-platform#500) -- story:custom-domain, arch:edge-vps (PTR/rDNS)
- #1736, #1739, #1740 -- downstream Stalwart config and Keycloak integration
Dependency is well-documented in scope. No undocumented blockers found.
Acceptance Criteria
3 criteria, all verifiable:
- "Request submitted" -- verifiable by human (screenshot/confirmation email)
- "Request approved" -- verifiable by Hetzner response
- "telnet gmail-smtp-in.l.google.com 25 from edge VPS" -- concrete, automatable test command
Criteria are appropriate for a manual vendor-request ticket. An agent can verify criterion 3 via SSH.
Blast Radius
Minimal. No code changes, no downstream breakage risk. The unblock only enables outbound SMTP on port 25; inbound is explicitly excluded per Constraints. No sibling services affected.
Decomposition Assessment
No decomposition needed:
- 0 file targets (manual action)
- 3 acceptance criteria (under 5 threshold)
- Agent time: minimal (human-dependent wait for Hetzner approval)
Recommendation
No action needed. Scope is complete and well-defined.