update.sh 33 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766
  1. #!/usr/bin/env bash
  2. # Check permissions
  3. if [ "$(id -u)" -ne "0" ]; then
  4. echo "You need to be root"
  5. exit 1
  6. fi
  7. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  8. # Run pre-update-hook
  9. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  10. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  11. fi
  12. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  13. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  14. echo "Please update to 5.x or use another distribution."
  15. exit 1
  16. fi
  17. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  18. if grep -q Ubuntu <<< $(uname -a); then
  19. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  20. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  21. exit 1
  22. fi
  23. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  24. read -p "Press any key to continue..." < /dev/tty
  25. fi
  26. # Exit on error and pipefail
  27. set -o pipefail
  28. # Setting high dc timeout
  29. export COMPOSE_HTTP_TIMEOUT=600
  30. # Add /opt/bin to PATH
  31. PATH=$PATH:/opt/bin
  32. umask 0022
  33. for bin in curl docker-compose docker git awk sha1sum; do
  34. if [[ -z $(which ${bin}) ]]; then echo "Cannot find ${bin}, exiting..."; exit 1; fi
  35. done
  36. export LC_ALL=C
  37. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  38. BRANCH=$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)
  39. check_online_status() {
  40. CHECK_ONLINE_IPS=(1.1.1.1 9.9.9.9 8.8.8.8)
  41. for ip in "${CHECK_ONLINE_IPS[@]}"; do
  42. if timeout 3 ping -c 1 ${ip} > /dev/null; then
  43. return 0
  44. fi
  45. done
  46. return 1
  47. }
  48. prefetch_images() {
  49. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  50. git fetch origin #${BRANCH}
  51. while read image; do
  52. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  53. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  54. continue
  55. fi
  56. fi
  57. RET_C=0
  58. until docker pull ${image}; do
  59. RET_C=$((RET_C + 1))
  60. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  61. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  62. sleep 1
  63. done
  64. done < <(git show origin/${BRANCH}:docker-compose.yml | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  65. }
  66. docker_garbage() {
  67. IMGS_TO_DELETE=()
  68. for container in $(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"); do
  69. REPOSITORY=${container/:*}
  70. TAG=${container/*:}
  71. V_MAIN=${container/*.}
  72. V_SUB=${container/*.}
  73. EXISTING_TAGS=$(docker images | grep ${REPOSITORY} | awk '{ print $2 }')
  74. for existing_tag in ${EXISTING_TAGS[@]}; do
  75. V_MAIN_EXISTING=${existing_tag/*.}
  76. V_SUB_EXISTING=${existing_tag/*.}
  77. # Not an integer
  78. [[ ! $V_MAIN_EXISTING =~ ^[0-9]+$ ]] && continue
  79. [[ ! $V_SUB_EXISTING =~ ^[0-9]+$ ]] && continue
  80. if [[ $V_MAIN_EXISTING == "latest" ]]; then
  81. echo "Found deprecated label \"latest\" for repository $REPOSITORY, it should be deleted."
  82. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  83. elif [[ $V_MAIN_EXISTING -lt $V_MAIN ]]; then
  84. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  85. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  86. elif [[ $V_SUB_EXISTING -lt $V_SUB ]]; then
  87. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  88. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  89. fi
  90. done
  91. done
  92. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  93. echo "Run the following command to delete unused image tags:"
  94. echo
  95. echo " docker rmi ${IMGS_TO_DELETE[*]}"
  96. echo
  97. if [ ! $FORCE ]; then
  98. read -r -p "Do you want to delete old image tags right now? [y/N] " response
  99. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  100. docker rmi ${IMGS_TO_DELETE[*]}
  101. else
  102. echo "OK, skipped."
  103. fi
  104. else
  105. echo "Running image removal without extra confirmation due to force mode."
  106. docker rmi ${IMGS_TO_DELETE[*]}
  107. fi
  108. echo -e "\e[32mFurther cleanup...\e[0m"
  109. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  110. fi
  111. }
  112. in_array() {
  113. local e match="$1"
  114. shift
  115. for e; do [[ "$e" == "$match" ]] && return 0; done
  116. return 1
  117. }
  118. migrate_docker_nat() {
  119. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  120. # Min Docker version
  121. DOCKERV_REQ=20.10.2
  122. # Current Docker version
  123. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  124. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  125. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  126. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  127. echo '!!! This step is recommended !!!'
  128. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  129. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  130. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  131. echo "OK, skipping this step."
  132. return 0
  133. fi
  134. fi
  135. # Sort versions and check if we are running a newer or equal version to req
  136. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  137. # If Dockerd daemon json exists
  138. if [ -s /etc/docker/daemon.json ]; then
  139. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  140. if ! in_array ipv6true "${dockerconfig[@]}" || \
  141. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  142. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  143. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  144. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  145. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  146. echo -e "Please merge the following content and restart the Docker daemon:\n"
  147. echo ${NAT_CONFIG}
  148. return 1
  149. fi
  150. else
  151. echo "Working on IPv6 NAT, please wait..."
  152. echo ${NAT_CONFIG} > /etc/docker/daemon.json
  153. ip6tables -F -t nat
  154. [[ -e /etc/alpine-release ]] && rc-service docker restart || systemctl restart docker.service
  155. if [[ $? -ne 0 ]]; then
  156. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  157. rm /etc/docker/daemon.json
  158. if [[ -e /etc/alpine-release ]]; then
  159. rc-service docker restart
  160. else
  161. systemctl reset-failed docker.service
  162. systemctl restart docker.service
  163. fi
  164. return 1
  165. fi
  166. fi
  167. # Removing legacy container
  168. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  169. if [ -s docker-compose.override.yml ]; then
  170. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  171. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  172. mv docker-compose.override.yml docker-compose.override.yml_backup
  173. fi
  174. fi
  175. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  176. else
  177. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  178. return 0
  179. fi
  180. }
  181. while (($#)); do
  182. case "${1}" in
  183. --check|-c)
  184. echo "Checking remote code for updates..."
  185. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized ${BRANCH} | cut -f1)
  186. if [ $? -ne 0 ]; then
  187. echo "A problem occurred while trying to fetch the latest revision from github."
  188. exit 99
  189. fi
  190. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  191. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  192. git log --date=short --pretty=format:"%ad - %s" $(git rev-parse --short HEAD)..origin/master
  193. exit 0
  194. else
  195. echo "No updates available."
  196. exit 3
  197. fi
  198. ;;
  199. --ours)
  200. MERGE_STRATEGY=ours
  201. ;;
  202. --skip-start)
  203. SKIP_START=y
  204. ;;
  205. --gc)
  206. echo -e "\e[32mCollecting garbage...\e[0m"
  207. docker_garbage
  208. exit 0
  209. ;;
  210. --prefetch)
  211. echo -e "\e[32mPrefetching images...\e[0m"
  212. prefetch_images
  213. exit 0
  214. ;;
  215. -f|--force)
  216. echo -e "\e[32mRunning in forced mode...\e[0m"
  217. FORCE=y
  218. ;;
  219. --no-update-compose)
  220. NO_UPDATE_COMPOSE=y
  221. ;;
  222. --skip-ping-check)
  223. SKIP_PING_CHECK=y
  224. ;;
  225. --help|-h)
  226. echo './update.sh [-c|--check, --ours, --gc, --no-update-compose, --prefetch, --skip-start, --skip-ping-check, -f|--force, -h|--help]
  227. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  228. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  229. --gc - Run garbage collector to delete old image tags
  230. --no-update-compose - Do not update docker-compose
  231. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  232. --skip-start - Do not start mailcow after update
  233. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you´ve blocked any ICMP Connections to your mailcow machine).
  234. -f|--force - Force update, do not ask questions
  235. '
  236. exit 1
  237. esac
  238. shift
  239. done
  240. [[ ! -f mailcow.conf ]] && { echo "mailcow.conf is missing"; exit 1;}
  241. chmod 600 mailcow.conf
  242. source mailcow.conf
  243. DOTS=${MAILCOW_HOSTNAME//[^.]};
  244. if [ ${#DOTS} -lt 2 ]; then
  245. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!"
  246. echo "Please change it to a FQDN and run docker-compose down followed by docker-compose up -d"
  247. exit 1
  248. fi
  249. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  250. # This will also cover sort
  251. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  252. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  253. CONFIG_ARRAY=(
  254. "SKIP_LETS_ENCRYPT"
  255. "SKIP_SOGO"
  256. "USE_WATCHDOG"
  257. "WATCHDOG_NOTIFY_EMAIL"
  258. "WATCHDOG_NOTIFY_BAN"
  259. "WATCHDOG_EXTERNAL_CHECKS"
  260. "WATCHDOG_SUBJECT"
  261. "SKIP_CLAMD"
  262. "SKIP_IP_CHECK"
  263. "ADDITIONAL_SAN"
  264. "DOVEADM_PORT"
  265. "IPV4_NETWORK"
  266. "IPV6_NETWORK"
  267. "LOG_LINES"
  268. "SNAT_TO_SOURCE"
  269. "SNAT6_TO_SOURCE"
  270. "COMPOSE_PROJECT_NAME"
  271. "SQL_PORT"
  272. "API_KEY"
  273. "API_KEY_READ_ONLY"
  274. "API_ALLOW_FROM"
  275. "MAILDIR_GC_TIME"
  276. "MAILDIR_SUB"
  277. "ACL_ANYONE"
  278. "SOLR_HEAP"
  279. "SKIP_SOLR"
  280. "ENABLE_SSL_SNI"
  281. "ALLOW_ADMIN_EMAIL_LOGIN"
  282. "SKIP_HTTP_VERIFICATION"
  283. "SOGO_EXPIRE_SESSION"
  284. "REDIS_PORT"
  285. "DOVECOT_MASTER_USER"
  286. "DOVECOT_MASTER_PASS"
  287. "MAILCOW_PASS_SCHEME"
  288. "ADDITIONAL_SERVER_NAMES"
  289. "ACME_CONTACT"
  290. "WATCHDOG_VERBOSE"
  291. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  292. )
  293. sed -i --follow-symlinks '$a\' mailcow.conf
  294. for option in ${CONFIG_ARRAY[@]}; do
  295. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  296. if ! grep -q ${option} mailcow.conf; then
  297. echo "Adding new option \"${option}\" to mailcow.conf"
  298. echo "${option}=" >> mailcow.conf
  299. fi
  300. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  301. if ! grep -q ${option} mailcow.conf; then
  302. echo "Adding new option \"${option}\" to mailcow.conf"
  303. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  304. fi
  305. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  306. if ! grep -q ${option} mailcow.conf; then
  307. echo "Adding new option \"${option}\" to mailcow.conf"
  308. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  309. fi
  310. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  311. if ! grep -q ${option} mailcow.conf; then
  312. echo "Adding new option \"${option}\" to mailcow.conf"
  313. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  314. fi
  315. elif [[ ${option} == "LOG_LINES" ]]; then
  316. if ! grep -q ${option} mailcow.conf; then
  317. echo "Adding new option \"${option}\" to mailcow.conf"
  318. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  319. echo "LOG_LINES=9999" >> mailcow.conf
  320. fi
  321. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  322. if ! grep -q ${option} mailcow.conf; then
  323. echo "Adding new option \"${option}\" to mailcow.conf"
  324. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  325. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  326. fi
  327. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  328. if ! grep -q ${option} mailcow.conf; then
  329. echo "Adding new option \"${option}\" to mailcow.conf"
  330. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  331. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  332. fi
  333. elif [[ ${option} == "SQL_PORT" ]]; then
  334. if ! grep -q ${option} mailcow.conf; then
  335. echo "Adding new option \"${option}\" to mailcow.conf"
  336. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  337. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  338. fi
  339. elif [[ ${option} == "API_KEY" ]]; then
  340. if ! grep -q ${option} mailcow.conf; then
  341. echo "Adding new option \"${option}\" to mailcow.conf"
  342. echo '# Create or override API key for web UI' >> mailcow.conf
  343. echo "#API_KEY=" >> mailcow.conf
  344. fi
  345. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  346. if ! grep -q ${option} mailcow.conf; then
  347. echo "Adding new option \"${option}\" to mailcow.conf"
  348. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  349. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  350. fi
  351. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  352. if ! grep -q ${option} mailcow.conf; then
  353. echo "Adding new option \"${option}\" to mailcow.conf"
  354. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  355. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  356. echo "#API_ALLOW_FROM=" >> mailcow.conf
  357. fi
  358. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  359. if ! grep -q ${option} mailcow.conf; then
  360. echo "Adding new option \"${option}\" to mailcow.conf"
  361. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  362. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  363. fi
  364. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  365. if ! grep -q ${option} mailcow.conf; then
  366. echo "Adding new option \"${option}\" to mailcow.conf"
  367. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  368. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  369. fi
  370. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  371. if ! grep -q ${option} mailcow.conf; then
  372. echo "Adding new option \"${option}\" to mailcow.conf"
  373. echo '# Garbage collector cleanup' >> mailcow.conf
  374. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  375. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  376. echo '# Check interval is hourly' >> mailcow.conf
  377. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  378. fi
  379. elif [[ ${option} == "ACL_ANYONE" ]]; then
  380. if ! grep -q ${option} mailcow.conf; then
  381. echo "Adding new option \"${option}\" to mailcow.conf"
  382. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  383. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  384. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  385. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  386. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  387. fi
  388. elif [[ ${option} == "SOLR_HEAP" ]]; then
  389. if ! grep -q ${option} mailcow.conf; then
  390. echo "Adding new option \"${option}\" to mailcow.conf"
  391. echo '# Solr heap size, there is no recommendation, please see Solr docs.' >> mailcow.conf
  392. echo '# Solr is a prone to run OOM on large systems and should be monitored. Unmonitored Solr setups are not recommended.' >> mailcow.conf
  393. echo '# Solr will refuse to start with total system memory below or equal to 2 GB.' >> mailcow.conf
  394. echo "SOLR_HEAP=1024" >> mailcow.conf
  395. fi
  396. elif [[ ${option} == "SKIP_SOLR" ]]; then
  397. if ! grep -q ${option} mailcow.conf; then
  398. echo "Adding new option \"${option}\" to mailcow.conf"
  399. echo '# Solr is disabled by default after upgrading from non-Solr to Solr-enabled mailcows.' >> mailcow.conf
  400. echo '# Disable Solr or if you do not want to store a readable index of your mails in solr-vol-1.' >> mailcow.conf
  401. echo "SKIP_SOLR=y" >> mailcow.conf
  402. fi
  403. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  404. if ! grep -q ${option} mailcow.conf; then
  405. echo "Adding new option \"${option}\" to mailcow.conf"
  406. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  407. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  408. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  409. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  410. fi
  411. elif [[ ${option} == "SKIP_SOGO" ]]; then
  412. if ! grep -q ${option} mailcow.conf; then
  413. echo "Adding new option \"${option}\" to mailcow.conf"
  414. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  415. echo "SKIP_SOGO=n" >> mailcow.conf
  416. fi
  417. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  418. if ! grep -q ${option} mailcow.conf; then
  419. echo "Adding new option \"${option}\" to mailcow.conf"
  420. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  421. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  422. echo "MAILDIR_SUB=" >> mailcow.conf
  423. fi
  424. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  425. if ! grep -q ${option} mailcow.conf; then
  426. echo "Adding new option \"${option}\" to mailcow.conf"
  427. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  428. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  429. fi
  430. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  431. if ! grep -q ${option} mailcow.conf; then
  432. echo "Adding new option \"${option}\" to mailcow.conf"
  433. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  434. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  435. fi
  436. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  437. if ! grep -q ${option} mailcow.conf; then
  438. echo "Adding new option \"${option}\" to mailcow.conf"
  439. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  440. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  441. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  442. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  443. fi
  444. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  445. if ! grep -q ${option} mailcow.conf; then
  446. echo "Adding new option \"${option}\" to mailcow.conf"
  447. echo '# SOGo session timeout in minutes' >> mailcow.conf
  448. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  449. fi
  450. elif [[ ${option} == "REDIS_PORT" ]]; then
  451. if ! grep -q ${option} mailcow.conf; then
  452. echo "Adding new option \"${option}\" to mailcow.conf"
  453. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  454. fi
  455. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  456. if ! grep -q ${option} mailcow.conf; then
  457. echo "Adding new option \"${option}\" to mailcow.conf"
  458. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  459. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  460. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  461. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  462. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  463. fi
  464. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  465. if ! grep -q ${option} mailcow.conf; then
  466. echo "Adding new option \"${option}\" to mailcow.conf"
  467. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  468. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  469. fi
  470. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  471. if ! grep -q ${option} mailcow.conf; then
  472. echo "Adding new option \"${option}\" to mailcow.conf"
  473. echo '# Password hash algorithm' >> mailcow.conf
  474. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  475. echo '# see https://mailcow.github.io/mailcow-dockerized-docs/models/model-passwd/' >> mailcow.conf
  476. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  477. fi
  478. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  479. if ! grep -q ${option} mailcow.conf; then
  480. echo '# Additional server names for mailcow UI' >> mailcow.conf
  481. echo '#' >> mailcow.conf
  482. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  483. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  484. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  485. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  486. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  487. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  488. fi
  489. elif [[ ${option} == "ACME_CONTACT" ]]; then
  490. if ! grep -q ${option} mailcow.conf; then
  491. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  492. echo '# Optional: Leave empty for none' >> mailcow.conf
  493. echo '# This value is only used on first order!' >> mailcow.conf
  494. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  495. echo '# https://mailcow.github.io/mailcow-dockerized-docs/troubleshooting/debug-reset_tls/' >> mailcow.conf
  496. echo 'ACME_CONTACT=' >> mailcow.conf
  497. fi
  498. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  499. if ! grep -q ${option} mailcow.conf; then
  500. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  501. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  502. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  503. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  504. fi
  505. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  506. if ! grep -q ${option} mailcow.conf; then
  507. echo '# Enable watchdog verbose logging' >> mailcow.conf
  508. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  509. fi
  510. elif ! grep -q ${option} mailcow.conf; then
  511. echo "Adding new option \"${option}\" to mailcow.conf"
  512. echo "${option}=n" >> mailcow.conf
  513. fi
  514. done
  515. if [[( ${SKIP_PING_CHECK} == "y")]]; then
  516. echo -e "\e[32mSkipping Ping Check...\e[0m"
  517. else
  518. echo -en "Checking internet connection... "
  519. if ! check_online_status; then
  520. echo -e "\e[31mfailed\e[0m"
  521. exit 1
  522. else
  523. echo -e "\e[32mOK\e[0m"
  524. fi
  525. fi
  526. echo -e "\e[32mChecking for newer update script...\e[0m"
  527. SHA1_1=$(sha1sum update.sh)
  528. git fetch origin #${BRANCH}
  529. git checkout origin/${BRANCH} update.sh
  530. SHA1_2=$(sha1sum update.sh)
  531. if [[ ${SHA1_1} != ${SHA1_2} ]]; then
  532. echo "update.sh changed, please run this script again, exiting."
  533. chmod +x update.sh
  534. exit 2
  535. fi
  536. if [[ -f mailcow.conf ]]; then
  537. source mailcow.conf
  538. else
  539. echo -e "\e[31mNo mailcow.conf - is mailcow installed?\e[0m"
  540. exit 1
  541. fi
  542. if [ ! $FORCE ]; then
  543. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  544. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  545. echo "OK, exiting."
  546. exit 0
  547. fi
  548. migrate_docker_nat
  549. fi
  550. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  551. if ! docker-compose config -q; then
  552. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  553. exit 1
  554. fi
  555. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  556. MAILCOW_BRIDGE=$(docker-compose config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  557. while read NAT_ID; do
  558. iptables -t nat -D POSTROUTING $NAT_ID
  559. done < <(iptables -L -vn -t nat --line-numbers | grep $IPV4_NETWORK | grep -E 'MASQUERADE.*all' | grep -v ${MAILCOW_BRIDGE} | cut -d' ' -f1)
  560. DIFF_DIRECTORY=update_diffs
  561. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  562. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  563. if ! git diff-index --quiet HEAD; then
  564. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  565. mkdir -p ${DIFF_DIRECTORY}
  566. git diff --stat > ${DIFF_FILE}
  567. git diff >> ${DIFF_FILE}
  568. fi
  569. echo -e "\e[32mPrefetching images...\e[0m"
  570. prefetch_images
  571. echo -e "\e[32mStopping mailcow...\e[0m"
  572. sleep 2
  573. MAILCOW_CONTAINERS=($(docker-compose ps -q))
  574. docker-compose down
  575. echo -e "\e[32mChecking for remaining containers...\e[0m"
  576. sleep 2
  577. for container in "${MAILCOW_CONTAINERS[@]}"; do
  578. docker rm -f "$container" 2> /dev/null
  579. done
  580. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  581. # Silently fixing remote url from andryyy to mailcow
  582. git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  583. echo -e "\e[32mCommitting current status...\e[0m"
  584. [[ -z "$(git config user.name)" ]] && git config user.name moo
  585. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  586. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  587. git add -u
  588. git commit -am "Before update on ${DATE}" > /dev/null
  589. echo -e "\e[32mFetching updated code from remote...\e[0m"
  590. git fetch origin #${BRANCH}
  591. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  592. git config merge.defaultToUpstream true
  593. git merge -X${MERGE_STRATEGY:-theirs} -Xpatience -m "After update on ${DATE}"
  594. # Need to use a variable to not pass return codes of if checks
  595. MERGE_RETURN=$?
  596. if [[ ${MERGE_RETURN} == 128 ]]; then
  597. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  598. exit 1
  599. elif [[ ${MERGE_RETURN} == 1 ]]; then
  600. echo -e "\e[93mPotenial conflict, trying to fix...\e[0m"
  601. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  602. git add -A
  603. git commit -m "After update on ${DATE}" > /dev/null
  604. git checkout .
  605. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  606. elif [[ ${MERGE_RETURN} != 0 ]]; then
  607. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  608. echo
  609. echo "Run docker-compose up -d to restart your stack without updates or try again after fixing the mentioned errors."
  610. exit 1
  611. fi
  612. if [[ ${NO_UPDATE_COMPOSE} == "y" ]]; then
  613. echo -e "\e[33mNot fetching latest docker-compose, please check for updates manually!\e[0m"
  614. elif [[ -e /etc/alpine-release ]]; then
  615. echo -e "\e[33mNot fetching latest docker-compose, because you are using Alpine Linux without glibc support. Please update docker-compose via apk!\e[0m"
  616. else
  617. echo -e "\e[32mFetching new docker-compose version...\e[0m"
  618. echo -e "\e[32mTrying to determine GLIBC version...\e[0m"
  619. if ldd --version > /dev/null; then
  620. GLIBC_V=$(ldd --version | grep -E '(GLIBC|GNU libc)' | rev | cut -d ' ' -f1 | rev | cut -d '.' -f2)
  621. if [ ! -z "${GLIBC_V}" ] && [ ${GLIBC_V} -gt 27 ]; then
  622. DC_DL_SUFFIX=
  623. else
  624. DC_DL_SUFFIX=legacy
  625. fi
  626. else
  627. DC_DL_SUFFIX=legacy
  628. fi
  629. sleep 1
  630. if [[ ! -z $(which pip) && $(pip list --local 2>&1 | grep -v DEPRECATION | grep -c docker-compose) == 1 ]]; then
  631. true
  632. #prevent breaking a working docker-compose installed with pip
  633. elif [[ $(curl -sL -w "%{http_code}" https://www.servercow.de/docker-compose/latest.php?vers=${DC_DL_SUFFIX} -o /dev/null) == "200" ]]; then
  634. LATEST_COMPOSE=$(curl -#L https://www.servercow.de/docker-compose/latest.php)
  635. COMPOSE_VERSION=$(docker-compose version --short)
  636. if [[ "$LATEST_COMPOSE" != "$COMPOSE_VERSION" ]]; then
  637. COMPOSE_PATH=$(which docker-compose)
  638. if [[ -w ${COMPOSE_PATH} ]]; then
  639. curl -#L https://github.com/docker/compose/releases/download/${LATEST_COMPOSE}/docker-compose-$(uname -s)-$(uname -m) > $COMPOSE_PATH
  640. chmod +x $COMPOSE_PATH
  641. else
  642. echo -e "\e[33mWARNING: $COMPOSE_PATH is not writable, but new version $LATEST_COMPOSE is available (installed: $COMPOSE_VERSION)\e[0m"
  643. fi
  644. fi
  645. else
  646. echo -e "\e[33mCannot determine latest docker-compose version, skipping...\e[0m"
  647. fi
  648. fi
  649. echo -e "\e[32mFetching new images, if any...\e[0m"
  650. sleep 2
  651. docker-compose pull
  652. # Fix missing SSL, does not overwrite existing files
  653. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  654. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  655. echo -e "Checking IPv6 settings... "
  656. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  657. echo
  658. echo '!! IMPORTANT !!'
  659. echo
  660. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  661. echo 'This setting will only be active after a complete shutdown of mailcow by running "docker-compose down" followed by "docker-compose up -d".'
  662. echo
  663. echo '!! IMPORTANT !!'
  664. echo
  665. read -p "Press any key to continue..." < /dev/tty
  666. fi
  667. # Checking for old project name bug
  668. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  669. # Checking old, wrong bindings
  670. sed -i --follow-symlinks 's/HTTP_BIND=0.0.0.0/HTTP_BIND=/g' mailcow.conf
  671. sed -i --follow-symlinks 's/HTTPS_BIND=0.0.0.0/HTTPS_BIND=/g' mailcow.conf
  672. # Fix Rspamd maps
  673. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  674. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  675. fi
  676. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  677. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  678. fi
  679. # Fix deprecated metrics.conf
  680. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  681. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  682. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  683. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  684. fi
  685. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  686. fi
  687. # Set app_info.inc.php
  688. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  689. if [ $? -eq 0 ]; then
  690. echo '<?php' > data/web/inc/app_info.inc.php
  691. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  692. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  693. echo '?>' >> data/web/inc/app_info.inc.php
  694. else
  695. echo '<?php' > data/web/inc/app_info.inc.php
  696. echo ' $MAILCOW_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  697. echo ' $MAILCOW_GIT_URL="";' >> data/web/inc/app_info.inc.php
  698. echo '?>' >> data/web/inc/app_info.inc.php
  699. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  700. fi
  701. if [[ ${SKIP_START} == "y" ]]; then
  702. echo -e "\e[33mNot starting mailcow, please run \"docker-compose up -d --remove-orphans\" to start mailcow.\e[0m"
  703. else
  704. echo -e "\e[32mStarting mailcow...\e[0m"
  705. sleep 2
  706. docker-compose up -d --remove-orphans
  707. fi
  708. echo -e "\e[32mCollecting garbage...\e[0m"
  709. docker_garbage
  710. # Run post-update-hook
  711. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  712. bash "${SCRIPT_DIR}/post_update_hook.sh"
  713. fi
  714. #echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  715. #echo
  716. #git reflog --color=always | grep "Before update on "
  717. #echo
  718. #echo "Use \"git reset --hard hash-on-the-left\" and run docker-compose up -d afterwards."