I have abandonded this approach because of two reasons other than the inability to configure dovecot to my initial wish:
1. I realised I may leak secrets into /gnu/store with the doveadm_password line. 2. This is a semi-XY problem. While having a robust two-way replication of my mailbox on all my machines would be nice, I started with the real problem of Gnus locking up during regular usage. I ended up solving this with (nnimap-keepalive-intervals '(60 . 15)).
