generate_config.sh 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584
  1. #!/usr/bin/env bash
  2. set -o pipefail
  3. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  4. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  5. echo "Please update to 5.x or use another distribution."
  6. exit 1
  7. fi
  8. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  9. if grep -q Ubuntu <<< $(uname -a); then
  10. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  11. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  12. exit 1
  13. fi
  14. fi
  15. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  16. # This will also cover sort
  17. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  18. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  19. for bin in openssl curl docker git awk sha1sum grep cut; do
  20. if [[ -z $(which ${bin}) ]]; then echo "Cannot find ${bin}, exiting..."; exit 1; fi
  21. done
  22. if docker compose > /dev/null 2>&1; then
  23. if docker compose version --short | grep -e "^2." -e "^v2." > /dev/null 2>&1; then
  24. COMPOSE_VERSION=native
  25. echo -e "\e[33mFound Docker Compose Plugin (native).\e[0m"
  26. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  27. sleep 2
  28. echo -e "\e[33mNotice: You´ll have to update this Compose Version via your Package Manager manually!\e[0m"
  29. else
  30. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  31. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  32. exit 1
  33. fi
  34. elif docker-compose > /dev/null 2>&1; then
  35. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  36. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  37. COMPOSE_VERSION=standalone
  38. echo -e "\e[33mFound Docker Compose Standalone.\e[0m"
  39. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  40. sleep 2
  41. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  42. else
  43. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  44. echo -e "\e[31mPlease update/install manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  45. exit 1
  46. fi
  47. fi
  48. else
  49. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  50. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  51. exit 1
  52. fi
  53. detect_bad_asn() {
  54. echo -e "\e[33mDetecting if your IP is listed on Spamhaus Bad ASN List...\e[0m"
  55. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  56. if [ "$response" -eq 503 ]; then
  57. if [ -z "$SPAMHAUS_DQS_KEY" ]; then
  58. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  59. echo -e "\e[33mmailcow did not detected a value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf!\e[0m"
  60. sleep 2
  61. echo ""
  62. echo -e "\e[33mTo use the Spamhaus DNS Blocklists again, you will need to create a FREE account for their Data Query Service (DQS) at: https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account\e[0m"
  63. echo -e "\e[33mOnce done, enter your DQS API key in mailcow.conf and mailcow will do the rest for you!\e[0m"
  64. echo ""
  65. sleep 2
  66. else
  67. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  68. echo -e "\e[32mmailcow detected a Value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf. Postfix will use DQS with the given API key...\e[0m"
  69. fi
  70. elif [ "$response" -eq 200 ]; then
  71. echo -e "\e[33mCheck completed! Your IP is \e[32mclean\e[0m"
  72. elif [ "$response" -eq 429 ]; then
  73. echo -e "\e[33mCheck completed! \e[31mYour IP seems to be rate limited on the ASN Check service... please try again later!\e[0m"
  74. else
  75. echo -e "\e[31mCheck failed! \e[0mMaybe a DNS or Network problem?\e[0m"
  76. fi
  77. }
  78. ### If generate_config.sh is started with --dev or -d it will not check out nightly or master branch and will keep on the current branch
  79. if [[ ${1} == "--dev" || ${1} == "-d" ]]; then
  80. SKIP_BRANCH=y
  81. else
  82. SKIP_BRANCH=n
  83. fi
  84. if [ -f mailcow.conf ]; then
  85. read -r -p "A config file exists and will be overwritten, are you sure you want to continue? [y/N] " response
  86. case $response in
  87. [yY][eE][sS]|[yY])
  88. mv mailcow.conf mailcow.conf_backup
  89. chmod 600 mailcow.conf_backup
  90. ;;
  91. *)
  92. exit 1
  93. ;;
  94. esac
  95. fi
  96. echo "Press enter to confirm the detected value '[value]' where applicable or enter a custom value."
  97. while [ -z "${MAILCOW_HOSTNAME}" ]; do
  98. read -p "Mail server hostname (FQDN) - this is not your mail domain, but your mail servers hostname: " -e MAILCOW_HOSTNAME
  99. DOTS=${MAILCOW_HOSTNAME//[^.]};
  100. if [ ${#DOTS} -lt 1 ]; then
  101. echo -e "\e[31mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!\e[0m"
  102. sleep 1
  103. echo "Please change it to a FQDN and redeploy the stack with docker(-)compose up -d"
  104. exit 1
  105. elif [[ "${MAILCOW_HOSTNAME: -1}" == "." ]]; then
  106. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is ending with a dot. This is not a valid FQDN!"
  107. exit 1
  108. elif [ ${#DOTS} -eq 1 ]; then
  109. echo -e "\e[33mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) does not contain a Subdomain. This is not fully tested and may cause issues.\e[0m"
  110. echo "Find more information about why this message exists here: https://github.com/mailcow/mailcow-dockerized/issues/1572"
  111. read -r -p "Do you want to proceed anyway? [y/N] " response
  112. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  113. echo "OK. Procceding."
  114. else
  115. echo "OK. Exiting."
  116. exit 1
  117. fi
  118. fi
  119. done
  120. if [ -a /etc/timezone ]; then
  121. DETECTED_TZ=$(cat /etc/timezone)
  122. elif [ -a /etc/localtime ]; then
  123. DETECTED_TZ=$(readlink /etc/localtime|sed -n 's|^.*zoneinfo/||p')
  124. fi
  125. while [ -z "${MAILCOW_TZ}" ]; do
  126. if [ -z "${DETECTED_TZ}" ]; then
  127. read -p "Timezone: " -e MAILCOW_TZ
  128. else
  129. read -p "Timezone [${DETECTED_TZ}]: " -e MAILCOW_TZ
  130. [ -z "${MAILCOW_TZ}" ] && MAILCOW_TZ=${DETECTED_TZ}
  131. fi
  132. done
  133. MEM_TOTAL=$(awk '/MemTotal/ {print $2}' /proc/meminfo)
  134. if [ -z "${SKIP_CLAMD}" ]; then
  135. if [ ${MEM_TOTAL} -le "2621440" ]; then
  136. echo "Installed memory is <= 2.5 GiB. It is recommended to disable ClamAV to prevent out-of-memory situations."
  137. echo "ClamAV can be re-enabled by setting SKIP_CLAMD=n in mailcow.conf."
  138. read -r -p "Do you want to disable ClamAV now? [Y/n] " response
  139. case $response in
  140. [nN][oO]|[nN])
  141. SKIP_CLAMD=n
  142. ;;
  143. *)
  144. SKIP_CLAMD=y
  145. ;;
  146. esac
  147. else
  148. SKIP_CLAMD=n
  149. fi
  150. fi
  151. if [ -z "${SKIP_SOLR}" ]; then
  152. if [ ${MEM_TOTAL} -le "2097152" ]; then
  153. echo "Disabling Solr on low-memory system."
  154. SKIP_SOLR=y
  155. elif [ ${MEM_TOTAL} -le "3670016" ]; then
  156. echo "Installed memory is <= 3.5 GiB. It is recommended to disable Solr to prevent out-of-memory situations."
  157. echo "Solr is a prone to run OOM and should be monitored. The default Solr heap size is 1024 MiB and should be set in mailcow.conf according to your expected load."
  158. echo "Solr can be re-enabled by setting SKIP_SOLR=n in mailcow.conf but will refuse to start with less than 2 GB total memory."
  159. read -r -p "Do you want to disable Solr now? [Y/n] " response
  160. case $response in
  161. [nN][oO]|[nN])
  162. SKIP_SOLR=n
  163. ;;
  164. *)
  165. SKIP_SOLR=y
  166. ;;
  167. esac
  168. else
  169. SKIP_SOLR=n
  170. fi
  171. fi
  172. if [[ ${SKIP_BRANCH} != y ]]; then
  173. echo "Which branch of mailcow do you want to use?"
  174. echo ""
  175. echo "Available Branches:"
  176. echo "- master branch (stable updates) | default, recommended [1]"
  177. echo "- nightly branch (unstable updates, testing) | not-production ready [2]"
  178. sleep 1
  179. while [ -z "${MAILCOW_BRANCH}" ]; do
  180. read -r -p "Choose the Branch with it´s number [1/2] " branch
  181. case $branch in
  182. [2])
  183. MAILCOW_BRANCH="nightly"
  184. ;;
  185. *)
  186. MAILCOW_BRANCH="master"
  187. ;;
  188. esac
  189. done
  190. git fetch --all
  191. git checkout -f $MAILCOW_BRANCH
  192. elif [[ ${SKIP_BRANCH} == y ]]; then
  193. echo -e "\033[33mEnabled Dev Mode.\033[0m"
  194. echo -e "\033[33mNot checking out a different branch!\033[0m"
  195. MAILCOW_BRANCH=$(git rev-parse --short $(git rev-parse @{upstream}))
  196. else
  197. echo -e "\033[31mCould not determine branch input..."
  198. echo -e "\033[31mExiting."
  199. exit 1
  200. fi
  201. if [ ! -z "${MAILCOW_BRANCH}" ]; then
  202. git_branch=${MAILCOW_BRANCH}
  203. fi
  204. [ ! -f ./data/conf/rspamd/override.d/worker-controller-password.inc ] && echo '# Placeholder' > ./data/conf/rspamd/override.d/worker-controller-password.inc
  205. cat << EOF > mailcow.conf
  206. # ------------------------------
  207. # mailcow web ui configuration
  208. # ------------------------------
  209. # example.org is _not_ a valid hostname, use a fqdn here.
  210. # Default admin user is "admin"
  211. # Default password is "moohoo"
  212. MAILCOW_HOSTNAME=${MAILCOW_HOSTNAME}
  213. # Password hash algorithm
  214. # Only certain password hash algorithm are supported. For a fully list of supported schemes,
  215. # see https://docs.mailcow.email/models/model-passwd/
  216. MAILCOW_PASS_SCHEME=BLF-CRYPT
  217. # ------------------------------
  218. # SQL database configuration
  219. # ------------------------------
  220. DBNAME=mailcow
  221. DBUSER=mailcow
  222. # Please use long, random alphanumeric strings (A-Za-z0-9)
  223. DBPASS=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)
  224. DBROOT=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)
  225. # ------------------------------
  226. # HTTP/S Bindings
  227. # ------------------------------
  228. # You should use HTTPS, but in case of SSL offloaded reverse proxies:
  229. # Might be important: This will also change the binding within the container.
  230. # If you use a proxy within Docker, point it to the ports you set below.
  231. # Do _not_ use IP:PORT in HTTP(S)_BIND or HTTP(S)_PORT
  232. # IMPORTANT: Do not use port 8081, 9081 or 65510!
  233. # Example: HTTP_BIND=1.2.3.4
  234. # For IPv4 leave it as it is: HTTP_BIND= & HTTPS_PORT=
  235. # For IPv6 see https://docs.mailcow.email/post_installation/firststeps-ip_bindings/
  236. HTTP_PORT=80
  237. HTTP_BIND=
  238. HTTPS_PORT=443
  239. HTTPS_BIND=
  240. # ------------------------------
  241. # Other bindings
  242. # ------------------------------
  243. # You should leave that alone
  244. # Format: 11.22.33.44:25 or 12.34.56.78:465 etc.
  245. SMTP_PORT=25
  246. SMTPS_PORT=465
  247. SUBMISSION_PORT=587
  248. IMAP_PORT=143
  249. IMAPS_PORT=993
  250. POP_PORT=110
  251. POPS_PORT=995
  252. SIEVE_PORT=4190
  253. DOVEADM_PORT=127.0.0.1:19991
  254. SQL_PORT=127.0.0.1:13306
  255. SOLR_PORT=127.0.0.1:18983
  256. REDIS_PORT=127.0.0.1:7654
  257. # Your timezone
  258. # See https://en.wikipedia.org/wiki/List_of_tz_database_time_zones for a list of timezones
  259. # Use the column named 'TZ identifier' + pay attention for the column named 'Notes'
  260. TZ=${MAILCOW_TZ}
  261. # Fixed project name
  262. # Please use lowercase letters only
  263. COMPOSE_PROJECT_NAME=mailcowdockerized
  264. # Used Docker Compose version
  265. # Switch here between native (compose plugin) and standalone
  266. # For more informations take a look at the mailcow docs regarding the configuration options.
  267. # Normally this should be untouched but if you decided to use either of those you can switch it manually here.
  268. # Please be aware that at least one of those variants should be installed on your machine or mailcow will fail.
  269. DOCKER_COMPOSE_VERSION=${COMPOSE_VERSION}
  270. # Set this to "allow" to enable the anyone pseudo user. Disabled by default.
  271. # When enabled, ACL can be created, that apply to "All authenticated users"
  272. # This should probably only be activated on mail hosts, that are used exclusivly by one organisation.
  273. # Otherwise a user might share data with too many other users.
  274. ACL_ANYONE=disallow
  275. # Garbage collector cleanup
  276. # Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring
  277. # How long should objects remain in the garbage until they are being deleted? (value in minutes)
  278. # Check interval is hourly
  279. MAILDIR_GC_TIME=7200
  280. # Additional SAN for the certificate
  281. #
  282. # You can use wildcard records to create specific names for every domain you add to mailcow.
  283. # Example: Add domains "example.com" and "example.net" to mailcow, change ADDITIONAL_SAN to a value like:
  284. #ADDITIONAL_SAN=imap.*,smtp.*
  285. # This will expand the certificate to "imap.example.com", "smtp.example.com", "imap.example.net", "smtp.example.net"
  286. # plus every domain you add in the future.
  287. #
  288. # You can also just add static names...
  289. #ADDITIONAL_SAN=srv1.example.net
  290. # ...or combine wildcard and static names:
  291. #ADDITIONAL_SAN=imap.*,srv1.example.com
  292. #
  293. ADDITIONAL_SAN=
  294. # Obtain certificates for autodiscover.* and autoconfig.* domains.
  295. # This can be useful to switch off in case you are in a scenario where a reverse proxy already handles those.
  296. # There are mixed scenarios where ports 80,443 are occupied and you do not want to share certs
  297. # between services. So acme-mailcow obtains for maildomains and all web-things get handled
  298. # in the reverse proxy.
  299. AUTODISCOVER_SAN=y
  300. # Additional server names for mailcow UI
  301. #
  302. # Specify alternative addresses for the mailcow UI to respond to
  303. # This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.
  304. # If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.
  305. # You can understand this as server_name directive in Nginx.
  306. # Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f
  307. ADDITIONAL_SERVER_NAMES=
  308. # Skip running ACME (acme-mailcow, Let's Encrypt certs) - y/n
  309. SKIP_LETS_ENCRYPT=n
  310. # Create seperate certificates for all domains - y/n
  311. # this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames
  312. # see https://doc.dovecot.org/admin_manual/ssl/sni_support
  313. ENABLE_SSL_SNI=n
  314. # Skip IPv4 check in ACME container - y/n
  315. SKIP_IP_CHECK=n
  316. # Skip HTTP verification in ACME container - y/n
  317. SKIP_HTTP_VERIFICATION=n
  318. # Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n
  319. SKIP_UNBOUND_HEALTHCHECK=n
  320. # Skip ClamAV (clamd-mailcow) anti-virus (Rspamd will auto-detect a missing ClamAV container) - y/n
  321. SKIP_CLAMD=${SKIP_CLAMD}
  322. # Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n
  323. SKIP_SOGO=n
  324. # Skip Solr on low-memory systems or if you do not want to store a readable index of your mails in solr-vol-1.
  325. SKIP_SOLR=${SKIP_SOLR}
  326. # Solr heap size in MB, there is no recommendation, please see Solr docs.
  327. # Solr is a prone to run OOM and should be monitored. Unmonitored Solr setups are not recommended.
  328. SOLR_HEAP=1024
  329. # Allow admins to log into SOGo as email user (without any password)
  330. ALLOW_ADMIN_EMAIL_LOGIN=n
  331. # Enable watchdog (watchdog-mailcow) to restart unhealthy containers
  332. USE_WATCHDOG=y
  333. # Send watchdog notifications by mail (sent from watchdog@MAILCOW_HOSTNAME)
  334. # CAUTION:
  335. # 1. You should use external recipients
  336. # 2. Mails are sent unsigned (no DKIM)
  337. # 3. If you use DMARC, create a separate DMARC policy ("v=DMARC1; p=none;" in _dmarc.MAILCOW_HOSTNAME)
  338. # Multiple rcpts allowed, NO quotation marks, NO spaces
  339. #WATCHDOG_NOTIFY_EMAIL=a@example.com,b@example.com,c@example.com
  340. #WATCHDOG_NOTIFY_EMAIL=
  341. # Send notifications to a webhook URL that receives a POST request with the content type "application/json".
  342. # You can use this to send notifications to services like Discord, Slack and others.
  343. #WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
  344. # JSON body included in the webhook POST request. Needs to be in single quotes.
  345. # Following variables are available: SUBJECT, BODY
  346. #WATCHDOG_NOTIFY_WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  347. # Notify about banned IP (includes whois lookup)
  348. WATCHDOG_NOTIFY_BAN=n
  349. # Send a notification when the watchdog is started.
  350. WATCHDOG_NOTIFY_START=y
  351. # Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.
  352. #WATCHDOG_SUBJECT=
  353. # Checks if mailcow is an open relay. Requires a SAL. More checks will follow.
  354. # https://www.servercow.de/mailcow?lang=en
  355. # https://www.servercow.de/mailcow?lang=de
  356. # No data is collected. Opt-in and anonymous.
  357. # Will only work with unmodified mailcow setups.
  358. WATCHDOG_EXTERNAL_CHECKS=n
  359. # Enable watchdog verbose logging
  360. WATCHDOG_VERBOSE=n
  361. # Max log lines per service to keep in Redis logs
  362. LOG_LINES=9999
  363. # Internal IPv4 /24 subnet, format n.n.n (expands to n.n.n.0/24)
  364. # Use private IPv4 addresses only, see https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses
  365. IPV4_NETWORK=172.22.1
  366. # Internal IPv6 subnet in fc00::/7
  367. # Use private IPv6 addresses only, see https://en.wikipedia.org/wiki/Private_network#Private_IPv6_addresses
  368. IPV6_NETWORK=fd4d:6169:6c63:6f77::/64
  369. # Use this IPv4 for outgoing connections (SNAT)
  370. #SNAT_TO_SOURCE=
  371. # Use this IPv6 for outgoing connections (SNAT)
  372. #SNAT6_TO_SOURCE=
  373. # Create or override an API key for the web UI
  374. # You _must_ define API_ALLOW_FROM, which is a comma separated list of IPs
  375. # An API key defined as API_KEY has read-write access
  376. # An API key defined as API_KEY_READ_ONLY has read-only access
  377. # Allowed chars for API_KEY and API_KEY_READ_ONLY: a-z, A-Z, 0-9, -
  378. # You can define API_KEY and/or API_KEY_READ_ONLY
  379. #API_KEY=
  380. #API_KEY_READ_ONLY=
  381. #API_ALLOW_FROM=172.22.1.1,127.0.0.1
  382. # mail_home is ~/Maildir
  383. MAILDIR_SUB=Maildir
  384. # SOGo session timeout in minutes
  385. SOGO_EXPIRE_SESSION=480
  386. # DOVECOT_MASTER_USER and DOVECOT_MASTER_PASS must both be provided. No special chars.
  387. # Empty by default to auto-generate master user and password on start.
  388. # User expands to DOVECOT_MASTER_USER@mailcow.local
  389. # LEAVE EMPTY IF UNSURE
  390. DOVECOT_MASTER_USER=
  391. # LEAVE EMPTY IF UNSURE
  392. DOVECOT_MASTER_PASS=
  393. # Let's Encrypt registration contact information
  394. # Optional: Leave empty for none
  395. # This value is only used on first order!
  396. # Setting it at a later point will require the following steps:
  397. # https://docs.mailcow.email/troubleshooting/debug-reset_tls/
  398. ACME_CONTACT=
  399. # WebAuthn device manufacturer verification
  400. # After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed
  401. # root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates
  402. WEBAUTHN_ONLY_TRUSTED_VENDORS=n
  403. # Spamhaus Data Query Service Key
  404. # Optional: Leave empty for none
  405. # Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.
  406. # If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.
  407. # Otherwise it will work normally.
  408. SPAMHAUS_DQS_KEY=
  409. # Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n
  410. # CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost
  411. DISABLE_NETFILTER_ISOLATION_RULE=n
  412. EOF
  413. mkdir -p data/assets/ssl
  414. chmod 600 mailcow.conf
  415. # copy but don't overwrite existing certificate
  416. echo "Generating snake-oil certificate..."
  417. # Making Willich more popular
  418. openssl req -x509 -newkey rsa:4096 -keyout data/assets/ssl-example/key.pem -out data/assets/ssl-example/cert.pem -days 365 -subj "/C=DE/ST=NRW/L=Willich/O=mailcow/OU=mailcow/CN=${MAILCOW_HOSTNAME}" -sha256 -nodes
  419. echo "Copying snake-oil certificate..."
  420. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  421. # Set app_info.inc.php
  422. case ${git_branch} in
  423. master)
  424. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  425. ;;
  426. nightly)
  427. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  428. mailcow_last_git_version=""
  429. ;;
  430. *)
  431. mailcow_git_version=$(git rev-parse --short HEAD)
  432. mailcow_last_git_version=""
  433. ;;
  434. esac
  435. # if [ ${git_branch} == "master" ]; then
  436. # mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  437. # elif [ ${git_branch} == "nightly" ]; then
  438. # mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  439. # mailcow_last_git_version=""
  440. # else
  441. # mailcow_git_version=$(git rev-parse --short HEAD)
  442. # mailcow_last_git_version=""
  443. # fi
  444. if [[ $SKIP_BRANCH != "y" ]]; then
  445. mailcow_git_commit=$(git rev-parse origin/${git_branch})
  446. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  447. else
  448. mailcow_git_commit=$(git rev-parse ${git_branch})
  449. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  450. git_branch=$(git rev-parse --abbrev-ref HEAD)
  451. fi
  452. if [ $? -eq 0 ]; then
  453. echo '<?php' > data/web/inc/app_info.inc.php
  454. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  455. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  456. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  457. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  458. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  459. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  460. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  461. echo ' $MAILCOW_BRANCH="'$git_branch'";' >> data/web/inc/app_info.inc.php
  462. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  463. echo '?>' >> data/web/inc/app_info.inc.php
  464. else
  465. echo '<?php' > data/web/inc/app_info.inc.php
  466. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  467. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  468. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  469. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  470. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  471. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  472. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  473. echo ' $MAILCOW_BRANCH="'$git_branch'";' >> data/web/inc/app_info.inc.php
  474. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  475. echo '?>' >> data/web/inc/app_info.inc.php
  476. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  477. fi
  478. detect_bad_asn