App Suite UI (latest)
All versions
Imprint
All versions
Imprint
  • Feature Catalog
    • General
      • Getting around
      • Search and notifications
      • Settings and appearance
      • Signing in
      • Account and security
      • Onboarding and devices
      • Working with content
      • Sharing and delegation
      • Storage, plans and feedback
      • Progressive Web App
      • Feedback
      • Upsell
      • Triggers
    • Mail
      • Reading and organizing
      • Attachments
      • Writing and sending
      • Security and trust
      • Accounts and automation
      • Signatures and templates
      • Working with the other apps
      • BIMI
    • Calendar
      • Seeing your day
      • Appointments
      • People and invitations
      • Calendars and subscriptions
      • Rooms and resources
      • Video meetings
      • Search, print and transfer
    • Address Book
      • Contacts
      • Address books
      • Finding people
      • Lists and the other apps
    • Tasks
      • Tasks
      • Task lists and delegation
      • Working with the other apps
    • Drive
      • Working with files
      • Finding and arranging
      • Sharing
      • Storages and capacity
      • Working with the other apps
      • OpenCloud Drive Integration
    • Portal
    • Enterprise and Provider Edition
    • Compliance

      • Accessibility
      • Accessibility Conformance Report
      • Data protection
  • Upgrade Guide
    • Everything new since 7.10.6
    • From 7.10.6 to 8.35
    • From 8.35 to 8.47
    • From 8.47 to 8.55
    • Breaking changes and requirements
  • Deployment Guide

    • Configuration
    • Settings list
    • Login page
    • What's New dialog
    • Mail assets
    • Mail rendering and security
    • All messages folder
    • Unseen messages folder
    • Theming
    • Authentication
    • Browser support
  • Customize & Extend
    • Manifests
    • Toolbars and menus
    • Portal widget
    • Sign In
    • Internationalization
  • Architecture
    • Core UI service

Core UI service

The Core UI service is the Node.js process that ships inside the UI container. It serves the web client's static assets and provides the HTTP endpoints that belong to the frontend rather than to App Suite Middleware. It follows the Backend-for-Frontend pattern: a small server owned by the UI team, deployed with the UI, released on the UI's cadence.

It replaced the previous static nginx container in 8.46. It has different resource characteristics - read Breaking changes and requirements before upgrading an existing deployment.

Why it exists

Some work cannot be done in the browser and does not belong in the Java middleware:

  • Requests that must not originate from the user's browser, because they would leak the user's IP address or require outbound network access the browser does not have - DNS lookups for BIMI, or one-click unsubscribe requests to a sender's endpoint.
  • Work that needs secrets, such as signing JWTs.
  • Operator-provided content that is mounted into the container, such as signature and template catalogs.

Putting these in the UI stack means they can be built, configured and released with the UI, rather than requiring a middleware release.

It deliberately does not hold domain data. Mail, calendar, contacts, tasks and files stay with the Middleware.

What it serves

All routes are mounted under the /ui prefix.

RoutePurpose
/ui/.well-known/jwks.jsonThe public key set that downstream services use to verify JWTs
/ui/.well-known/openid-configurationIssuer discovery for those services
/ui/v1/tokenExchanges an App Suite session for a signed JWT
/ui/v1/bimi/:domainBIMI record lookup and verification for a sender domain
/ui/v1/bimi/:domain/:selector/logoThe sanitized sender logo
/ui/v1/unsubscribeServer-side one-click unsubscribe (RFC 8058)
/ui/v1/assets/mail/signaturesAdministrator-provided signature catalog
/ui/v1/assets/mail/templatesAdministrator-provided mail template catalog
/ui/v1/assets/mail/designsSignature Designer designs

Static UI assets are served from the same process.

Authentication

The service issues the JWTs that newer services - for example the AI Service - use to authenticate requests, bridging from App Suite's cookie-based session via the Middleware's token login API. The flow, the required Middleware properties and the service configuration are documented under Authentication.

Outbound requests

Both BIMI and one-click unsubscribe make requests to hosts named in a message. That makes them an SSRF surface, so the service resolves and validates the target first: hostnames are resolved explicitly and the resulting addresses are rejected if they fall into loopback, link-local, private, unique-local, multicast or other reserved ranges, and requests are bounded by a timeout. Logos are sanitized before they are served to the browser.

Deployments that route egress through a proxy or use a custom CA need to configure that at the container level; see the Helm chart values.

Configuration

The service reads a YAML configuration file, mounted into the container. Its own feature switches are separate from the UI's settings - the UI's feature toggles come from the Middleware over JSlob, while this file configures the service itself. BIMI, for example, is enabled here and additionally accepts operator-configured logo records for specific domains.

features:
  bimi: true
bimi:
  records:
    - domain: example.com
      selector: default
      type: cmc
      file: /etc/bimi/example.svg

See BIMI for the full set of options.

Storage and metrics

The service uses a MariaDB schema for the data it caches itself, with migrations applied on start. It exposes Prometheus metrics, and dashboards are shipped alongside the chart.

Sizing

The Node.js service needs more memory than the static nginx container it replaced, particularly with BIMI enabled. The chart defaults to 256Mi for both request and limit, and deploys two replicas. A CPU request is set but no CPU limit, so the service can absorb short bursts without being throttled; if your cluster policy requires a limit, 1 CPU is a reasonable value.

Last Updated: 10/7/26, 2:41 PM