It’d be awesome if there were two separate sites using SNI:
Site 1 would be for all admin activity
Site 2 would be for lower permission level, non-admin user activity
Then we could just expose the non-admin site to the internet and keep the admin site on the private network.
I know that would be more legwork on the dev side, probably require some api changes for permission levels, but it sure would add value to Mailcow