Keila source and recovery audit · 30 Sep 2026
Keila v0.30.3: more source evidence, but no real-send clearance.
The exact release, tagged README and build files, and a registry-listed image digest were readable. The tagged licence and extra/ notice, complete archive and image contents were not. Keila remains a private-evaluation candidate, not a send-ready or shortlisted tool.
Three gates remain open
| Gate | What moved | What still blocks real recipients |
|---|---|---|
| K1 · package and licence Partly advanced · open | The release identifies commit bccb0a8e…042cd6c. The tagged README says AGPLv3-or-later except the logo and every file under extra/. Tagged build files and a Docker Hub digest were readable. | The exact licence and extra/ notice, archive inventory, checksums, final-image contents and source-to-image provenance were not verified. A cache miss does not mean a file is absent. |
| K3 · recovery and disclosure Open | Official docs and tagged configuration identify PostgreSQL, uploads, secrets, mail settings and queued work. | No coordinated DB + upload + secret restore, safe scheduler restart, upgrade rollback, or current private security-report route was verified. No restore was tried. |
| X1 · sender outcomes Open | Official docs distinguish managed-service handling and optional self-hosted SES bounce/complaint handling from other sender choices. | Plain SMTP acceptance, failure, bounce, complaint, suppression and retry/duplicate correlation were not established. SES or Cloud behavior cannot be generalized to SMTP. |
What the v0.30.3 build evidence means
The tagged mix.exs includes extra/ on the compilation path only when WITH_EXTRA is enabled. The tagged Dockerfile declares WITH_EXTRA=0 as a build argument, copies source into a builder, and copies a release into the runtime stage. Inference: the default code path appears designed to omit extra/ modules from compilation. That does not prove what the published image contains, which build arguments were used, or the licence of every repository path or asset. Repository inclusion, compiled runtime inclusion and paid/cloud entitlement are different questions.
The official Docker Hub listing advertises pentacent/keila:0.30.3 and digest sha256:b9aa7123…a89522a. This is a listed digest, not a calculated archive checksum or a verified build attestation; the layer page and image were unread. Reads of the tag tree and archive also failed in this environment. The older 0.19.0 cloud-only scope note is background, not a substitute for the unread v0.30.3 notice.
Recovery inputs are identifiable; a restore is not proven
| Surface | Documented basis | Required operator check |
|---|---|---|
| Database and queue | Installation requires PostgreSQL. Tagged runtime config reads DB_URL and configures an Oban DB prefix; mix.exs includes Oban. The 0.20.0 release describes scheduler and message-schema changes. | Take and restore a consistent DB snapshot, then inspect queued and message state before restart. The checked docs did not supply an end-to-end procedure or exactly-once guarantee. |
| Uploads, secrets and logs | Configuration names USER_CONTENT_DIR, a persistence volume, SECRET_KEY_BASE, HASHID_SALT, mailer credentials and LOG_LEVEL. First steps says root credentials may print to stdout. | Restore uploads with DB and protected secrets; restrict first-boot output and logs. A DB-only copy can leave uploaded content behind. This is an operator inference, not a tested Keila runbook. |
| Upgrade and disclosure | The 0.30.0 release describes automatic template migration. Cached GitHub security and policy views plus the docs index did not verify a private report route. | Test rollback with the pinned version and confirm a confidential maintainer route. Cached policy views do not prove no route exists. |
Do not transfer SES or Cloud promises to SMTP
Sender documentation lists SMTP and SES for self-hosting and “Send with Keila” for managed Cloud. The analytics explanation attributes automatic managed bounce and complaint handling to Cloud and says self-hosters can enable it for SES. The 0.20.0 release describes a failed-message count, not proof of provider acceptance or final delivery. The checked official material does not establish generic plain-SMTP event ingestion, suppression reconciliation, or exactly-once sending.
Stop condition and next evidence
- A licence/build owner obtains the v0.30.3 archive, both tagged notices and path inventory; records checksums; pins and inspects the image; and verifies effective build inputs and source-to-image provenance.
- A platform operator performs an isolated DB + uploads + secrets restore, reconciles queued/message state before resume, and tests upgrade rollback. A security owner verifies a private maintainer disclosure route.
- A mail operator maps the chosen provider’s accepted, failed, bounced and complained events to messages, suppressions and retries, including duplicate ambiguity. A content/consent approver separately reviews eligibility, copy, sender and launch.
Until K1 and K3 close, do not run conditional small-list workflow validation with real recipients, production credentials, a public form, outbound mail or an unattended schedule. For this small-list job, the existing operated sender remains the first conditional option if it already records consent, opt-outs, review and provider outcomes. That path also needs named owners; it is not an exemption.
Evidence limit: tagged files were read where accessible on 30 September 2026; product documentation is not necessarily version-pinned. This is source reading, not a legal opinion, security assessment, recovery test or delivery recommendation. See the research library and evidence notes.