bootstrap-sogo.sh 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161
  1. #!/bin/bash
  2. # Wait for MySQL to warm-up
  3. while ! mariadb-admin status --ssl=false --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  4. echo "Waiting for database to come up..."
  5. sleep 2
  6. done
  7. # Wait until port becomes free and send sig
  8. until ! nc -z sogo-mailcow 20000;
  9. do
  10. killall -TERM sogod
  11. sleep 3
  12. done
  13. # Wait for updated schema
  14. DBV_NOW=$(mariadb --skip-ssl --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions WHERE application = 'db_schema';" -BN)
  15. DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
  16. while [[ "${DBV_NOW}" != "${DBV_NEW}" ]]; do
  17. echo "Waiting for schema update..."
  18. DBV_NOW=$(mariadb --skip-ssl --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT version FROM versions WHERE application = 'db_schema';" -BN)
  19. DBV_NEW=$(grep -oE '\$db_version = .*;' init_db.inc.php | sed 's/$db_version = //g;s/;//g' | cut -d \" -f2)
  20. sleep 5
  21. done
  22. echo "DB schema is ${DBV_NOW}"
  23. if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  24. mariadb --skip-ssl --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "DROP TRIGGER IF EXISTS sogo_update_password"
  25. fi
  26. # cat /dev/urandom seems to hang here occasionally and is not recommended anyway, better use openssl
  27. RAND_PASS=$(openssl rand -base64 16 | tr -dc _A-Z-a-z-0-9)
  28. # Generate plist header with timezone data
  29. mkdir -p /var/lib/sogo/GNUstep/Defaults/
  30. cat <<EOF > /var/lib/sogo/GNUstep/Defaults/sogod.plist
  31. <?xml version="1.0" encoding="UTF-8"?>
  32. <!DOCTYPE plist PUBLIC "-//GNUstep//DTD plist 0.9//EN" "http://www.gnustep.org/plist-0_9.xml">
  33. <plist version="0.9">
  34. <dict>
  35. <key>OCSAclURL</key>
  36. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_acl</string>
  37. <key>SOGoIMAPServer</key>
  38. <string>imap://${IPV4_NETWORK}.250:143/?TLS=YES&amp;tlsVerifyMode=none</string>
  39. <key>SOGoSieveServer</key>
  40. <string>sieve://${IPV4_NETWORK}.250:4190/?TLS=YES&amp;tlsVerifyMode=none</string>
  41. <key>SOGoSMTPServer</key>
  42. <string>smtp://${IPV4_NETWORK}.253:588/?TLS=YES&amp;tlsVerifyMode=none</string>
  43. <key>SOGoTrustProxyAuthentication</key>
  44. <string>YES</string>
  45. <key>SOGoEncryptionKey</key>
  46. <string>${RAND_PASS}</string>
  47. <key>SOGoURLEncryptionEnabled</key>
  48. <string>YES</string>
  49. <key>SOGoURLEncryptionPassphrase</key>
  50. <string>${SOGO_URL_ENCRYPTION_KEY}</string>
  51. <key>OCSAdminURL</key>
  52. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_admin</string>
  53. <key>OCSCacheFolderURL</key>
  54. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_cache_folder</string>
  55. <key>OCSEMailAlarmsFolderURL</key>
  56. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_alarms_folder</string>
  57. <key>OCSFolderInfoURL</key>
  58. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_folder_info</string>
  59. <key>OCSSessionsFolderURL</key>
  60. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_sessions_folder</string>
  61. <key>OCSStoreURL</key>
  62. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_store</string>
  63. <key>SOGoProfileURL</key>
  64. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/sogo_user_profile</string>
  65. <key>SOGoTimeZone</key>
  66. <string>${TZ}</string>
  67. <key>domains</key>
  68. <dict>
  69. EOF
  70. # Generate multi-domain setup
  71. while read -r line gal
  72. do
  73. echo " <key>${line}</key>
  74. <dict>
  75. <key>SOGoMailDomain</key>
  76. <string>${line}</string>
  77. <key>SOGoUserSources</key>
  78. <array>
  79. <dict>
  80. <key>MailFieldNames</key>
  81. <array>
  82. <string>aliases</string>
  83. <string>ad_aliases</string>
  84. <string>ext_acl</string>
  85. </array>
  86. <key>KindFieldName</key>
  87. <string>kind</string>
  88. <key>DomainFieldName</key>
  89. <string>domain</string>
  90. <key>MultipleBookingsFieldName</key>
  91. <string>multiple_bookings</string>
  92. <key>listRequiresDot</key>
  93. <string>NO</string>
  94. <key>canAuthenticate</key>
  95. <string>YES</string>
  96. <key>displayName</key>
  97. <string>GAL ${line}</string>
  98. <key>id</key>
  99. <string>${line}</string>
  100. <key>isAddressBook</key>
  101. <string>${gal}</string>
  102. <key>type</key>
  103. <string>sql</string>
  104. <key>userPasswordAlgorithm</key>
  105. <string>${MAILCOW_PASS_SCHEME}</string>
  106. <key>prependPasswordScheme</key>
  107. <string>YES</string>
  108. <key>viewURL</key>
  109. <string>mysql://${DBUSER}:${DBPASS}@%2Fvar%2Frun%2Fmysqld%2Fmysqld.sock/${DBNAME}/_sogo_static_view</string>
  110. </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  111. # Generate alternative LDAP authentication dict, when SQL authentication fails
  112. # This will nevertheless read attributes from LDAP
  113. /etc/sogo/plist_ldap.sh ${line} ${gal} >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  114. echo " </array>
  115. </dict>" >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  116. done < <(mariadb --skip-ssl --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain, CASE gal WHEN '1' THEN 'YES' ELSE 'NO' END AS gal FROM domain;" -B -N)
  117. # Generate footer
  118. echo ' </dict>
  119. </dict>
  120. </plist>' >> /var/lib/sogo/GNUstep/Defaults/sogod.plist
  121. # Fix permissions
  122. chown sogo:sogo -R /var/lib/sogo/
  123. chmod 600 /var/lib/sogo/GNUstep/Defaults/sogod.plist
  124. # Patch ACLs
  125. #if [[ ${ACL_ANYONE} == 'allow' ]]; then
  126. # #enable any or authenticated targets for ACL
  127. # if patch -R -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
  128. # patch -R /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
  129. # fi
  130. #else
  131. # #disable any or authenticated targets for ACL
  132. # if patch -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff > /dev/null; then
  133. # patch /usr/lib/GNUstep/SOGo/Templates/UIxAclEditor.wox < /acl.diff;
  134. # fi
  135. #fi
  136. if patch -R -sfN --dry-run /usr/lib/GNUstep/SOGo/Templates/UIxTopnavToolbar.wox < /navMailcowBtns.diff > /dev/null; then
  137. patch -R /usr/lib/GNUstep/SOGo/Templates/UIxTopnavToolbar.wox < /navMailcowBtns.diff;
  138. fi
  139. # Rename custom logo, if any
  140. [[ -f /etc/sogo/sogo-full.svg ]] && mv /etc/sogo/sogo-full.svg /etc/sogo/custom-fulllogo.svg
  141. # Rsync web content
  142. echo "Syncing web content with named volume"
  143. rsync -a /usr/lib/GNUstep/SOGo/. /sogo_web/
  144. # Chown backup path
  145. chown -R sogo:sogo /sogo_backup
  146. exec gosu sogo /usr/sbin/sogod