update.sh 46 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003
  1. #!/usr/bin/env bash
  2. ############## Begin Function Section ##############
  3. check_online_status() {
  4. CHECK_ONLINE_DOMAINS=('https://github.com' 'https://hub.docker.com')
  5. for domain in "${CHECK_ONLINE_DOMAINS[@]}"; do
  6. if timeout 6 curl --head --silent --output /dev/null ${domain}; then
  7. return 0
  8. fi
  9. done
  10. return 1
  11. }
  12. prefetch_images() {
  13. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  14. git fetch origin #${BRANCH}
  15. while read image; do
  16. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  17. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  18. continue
  19. fi
  20. fi
  21. RET_C=0
  22. until docker pull ${image}; do
  23. RET_C=$((RET_C + 1))
  24. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  25. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  26. sleep 1
  27. done
  28. done < <(git show origin/${BRANCH}:docker-compose.yml | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  29. }
  30. docker_garbage() {
  31. IMGS_TO_DELETE=()
  32. for container in $(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"); do
  33. REPOSITORY=${container/:*}
  34. TAG=${container/*:}
  35. V_MAIN=${container/*.}
  36. V_SUB=${container/*.}
  37. EXISTING_TAGS=$(docker images | grep ${REPOSITORY} | awk '{ print $2 }')
  38. for existing_tag in ${EXISTING_TAGS[@]}; do
  39. V_MAIN_EXISTING=${existing_tag/*.}
  40. V_SUB_EXISTING=${existing_tag/*.}
  41. # Not an integer
  42. [[ ! $V_MAIN_EXISTING =~ ^[0-9]+$ ]] && continue
  43. [[ ! $V_SUB_EXISTING =~ ^[0-9]+$ ]] && continue
  44. if [[ $V_MAIN_EXISTING == "latest" ]]; then
  45. echo "Found deprecated label \"latest\" for repository $REPOSITORY, it should be deleted."
  46. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  47. elif [[ $V_MAIN_EXISTING -lt $V_MAIN ]]; then
  48. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  49. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  50. elif [[ $V_SUB_EXISTING -lt $V_SUB ]]; then
  51. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  52. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  53. fi
  54. done
  55. done
  56. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  57. echo "Run the following command to delete unused image tags:"
  58. echo
  59. echo " docker rmi ${IMGS_TO_DELETE[*]}"
  60. echo
  61. if [ ! $FORCE ]; then
  62. read -r -p "Do you want to delete old image tags right now? [y/N] " response
  63. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  64. docker rmi ${IMGS_TO_DELETE[*]}
  65. else
  66. echo "OK, skipped."
  67. fi
  68. else
  69. echo "Running image removal without extra confirmation due to force mode."
  70. docker rmi ${IMGS_TO_DELETE[*]}
  71. fi
  72. echo -e "\e[32mFurther cleanup...\e[0m"
  73. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  74. fi
  75. }
  76. in_array() {
  77. local e match="$1"
  78. shift
  79. for e; do [[ "$e" == "$match" ]] && return 0; done
  80. return 1
  81. }
  82. migrate_docker_nat() {
  83. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  84. # Min Docker version
  85. DOCKERV_REQ=20.10.2
  86. # Current Docker version
  87. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  88. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  89. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  90. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  91. echo '!!! This step is recommended !!!'
  92. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  93. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  94. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  95. echo "OK, skipping this step."
  96. return 0
  97. fi
  98. fi
  99. # Sort versions and check if we are running a newer or equal version to req
  100. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  101. # If Dockerd daemon json exists
  102. if [ -s /etc/docker/daemon.json ]; then
  103. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  104. if ! in_array ipv6true "${dockerconfig[@]}" || \
  105. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  106. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  107. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  108. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  109. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  110. echo -e "Please merge the following content and restart the Docker daemon:\n"
  111. echo ${NAT_CONFIG}
  112. return 1
  113. fi
  114. else
  115. echo "Working on IPv6 NAT, please wait..."
  116. echo ${NAT_CONFIG} > /etc/docker/daemon.json
  117. ip6tables -F -t nat
  118. [[ -e /etc/alpine-release ]] && rc-service docker restart || systemctl restart docker.service
  119. if [[ $? -ne 0 ]]; then
  120. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  121. rm /etc/docker/daemon.json
  122. if [[ -e /etc/alpine-release ]]; then
  123. rc-service docker restart
  124. else
  125. systemctl reset-failed docker.service
  126. systemctl restart docker.service
  127. fi
  128. return 1
  129. fi
  130. fi
  131. # Removing legacy container
  132. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  133. if [ -s docker-compose.override.yml ]; then
  134. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  135. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  136. mv docker-compose.override.yml docker-compose.override.yml_backup
  137. fi
  138. fi
  139. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  140. else
  141. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  142. return 0
  143. fi
  144. }
  145. remove_obsolete_nginx_ports() {
  146. # Removing obsolete docker-compose.override.yml
  147. for override in docker-compose.override.yml docker-compose.override.yaml; do
  148. if [ -s $override ] ; then
  149. if cat $override | grep nginx-mailcow > /dev/null 2>&1; then
  150. if cat $override | grep -E '(\[::])' > /dev/null 2>&1; then
  151. if cat $override | grep -w 80:80 > /dev/null 2>&1 && cat $override | grep -w 443:443 > /dev/null 2>&1 ; then
  152. echo -e "\e[33mBacking up ${override} to preserve custom changes...\e[0m"
  153. echo -e "\e[33m!!! Manual Merge needed (if other overrides are set) !!!\e[0m"
  154. sleep 3
  155. cp $override ${override}_backup
  156. sed -i '/nginx-mailcow:$/,/^$/d' $override
  157. echo -e "\e[33mRemoved obsolete NGINX IPv6 Bind from original override File.\e[0m"
  158. if [[ "$(cat $override | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  159. mv $override ${override}_empty
  160. echo -e "\e[31m${override} is empty. Renamed it to ensure mailcow is startable.\e[0m"
  161. fi
  162. fi
  163. fi
  164. fi
  165. fi
  166. done
  167. }
  168. detect_docker_compose_command(){
  169. if ! [[ "${DOCKER_COMPOSE_VERSION}" =~ ^(native|standalone)$ ]]; then
  170. if docker compose > /dev/null 2>&1; then
  171. if docker compose version --short | grep "2." > /dev/null 2>&1; then
  172. DOCKER_COMPOSE_VERSION=native
  173. COMPOSE_COMMAND="docker compose"
  174. echo -e "\e[31mFound Docker Compose Plugin (native).\e[0m"
  175. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  176. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' $SCRIPT_DIR/mailcow.conf
  177. sleep 2
  178. echo -e "\e[33mNotice: You'll have to update this Compose Version via your Package Manager manually!\e[0m"
  179. else
  180. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  181. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://docs.mailcow.email/i_u_m/i_u_m_install/\e[0m"
  182. exit 1
  183. fi
  184. elif docker-compose > /dev/null 2>&1; then
  185. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  186. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  187. DOCKER_COMPOSE_VERSION=standalone
  188. COMPOSE_COMMAND="docker-compose"
  189. echo -e "\e[31mFound Docker Compose Standalone.\e[0m"
  190. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  191. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' $SCRIPT_DIR/mailcow.conf
  192. sleep 2
  193. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  194. else
  195. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  196. echo -e "\e[31mPlease update/install regarding to this doc site: https://docs.mailcow.email/i_u_m/i_u_m_install/\e[0m"
  197. exit 1
  198. fi
  199. fi
  200. else
  201. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  202. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/i_u_m/i_u_m_install/\e[0m"
  203. exit 1
  204. fi
  205. elif [ "${DOCKER_COMPOSE_VERSION}" == "native" ]; then
  206. COMPOSE_COMMAND="docker compose"
  207. # Check if Native Compose works and has not been deleted
  208. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  209. # IF it not exists/work anymore try the other command
  210. COMPOSE_COMMAND="docker-compose"
  211. if ! $COMPOSE_COMMAND > /dev/null 2>&1 || ! $COMPOSE_COMMAND --version | grep "^2." > /dev/null 2>&1; then
  212. # IF it cannot find Standalone in > 2.X, then script stops
  213. echo -e "\e[31mCannot find Docker Compose or the Version is lower then 2.X.X.\e[0m"
  214. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/i_u_m/i_u_m_install/\e[0m"
  215. exit 1
  216. fi
  217. # If it finds the standalone Plugin it will use this instead and change the mailcow.conf Variable accordingly
  218. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  219. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from native to standalone\e[0m"
  220. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' $SCRIPT_DIR/mailcow.conf
  221. sleep 2
  222. fi
  223. elif [ "${DOCKER_COMPOSE_VERSION}" == "standalone" ]; then
  224. COMPOSE_COMMAND="docker-compose"
  225. # Check if Standalone Compose works and has not been deleted
  226. if ! $COMPOSE_COMMAND > /dev/null 2>&1 && ! $COMPOSE_COMMAND --version > /dev/null 2>&1 | grep "^2." > /dev/null 2>&1; then
  227. # IF it not exists/work anymore try the other command
  228. COMPOSE_COMMAND="docker compose"
  229. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  230. # IF it cannot find Native in > 2.X, then script stops
  231. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  232. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/i_u_m/i_u_m_install/\e[0m"
  233. exit 1
  234. fi
  235. # If it finds the native Plugin it will use this instead and change the mailcow.conf Variable accordingly
  236. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  237. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from standalone to native\e[0m"
  238. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' $SCRIPT_DIR/mailcow.conf
  239. sleep 2
  240. fi
  241. fi
  242. }
  243. detect_bad_asn() {
  244. if curl -s http://fuzzy.mailcow.email/asn_list.txt | grep $(whois -h whois.radb.net $(curl -s http://ipv4.mailcow.email) | grep -i origin | tr -s " " | cut -d " " -f2 | head -1) > /dev/null ; then
  245. if [ -z "$SPAMHAUS_DQS_KEY" ]; then
  246. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  247. echo -e "\e[33mmailcow did not detected a value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf!\e[0m"
  248. sleep 2
  249. echo ""
  250. echo -e "\e[33mTo use the Spamhaus DNS Blocklists again, you will need to create a FREE account for their Data Query Service (DQS) at: https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account\e[0m"
  251. echo -e "\e[33mOnce done, enter your DQS API key in mailcow.conf and mailcow will do the rest for you!\e[0m"
  252. echo ""
  253. sleep 2
  254. else
  255. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  256. echo -e "\e[32mmailcow detected a Value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf. Postfix will use DQS with the given API key...\e[0m"
  257. fi
  258. fi
  259. }
  260. ############## End Function Section ##############
  261. # Check permissions
  262. if [ "$(id -u)" -ne "0" ]; then
  263. echo "You need to be root"
  264. exit 1
  265. fi
  266. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  267. # Run pre-update-hook
  268. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  269. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  270. fi
  271. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  272. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  273. echo "Please update to 5.x or use another distribution."
  274. exit 1
  275. fi
  276. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  277. if grep -q Ubuntu <<< $(uname -a); then
  278. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  279. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  280. exit 1
  281. fi
  282. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  283. read -p "Press any key to continue..." < /dev/tty
  284. fi
  285. # Exit on error and pipefail
  286. set -o pipefail
  287. # Setting high dc timeout
  288. export COMPOSE_HTTP_TIMEOUT=600
  289. # Add /opt/bin to PATH
  290. PATH=$PATH:/opt/bin
  291. umask 0022
  292. # Unset COMPOSE_COMMAND and DOCKER_COMPOSE_VERSION Variable to be on the newest state.
  293. unset COMPOSE_COMMAND
  294. unset DOCKER_COMPOSE_VERSION
  295. for bin in curl docker git awk sha1sum grep cut whois; do
  296. if [[ -z $(command -v ${bin}) ]]; then
  297. echo "Cannot find ${bin}, exiting..."
  298. exit 1;
  299. fi
  300. done
  301. export LC_ALL=C
  302. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  303. BRANCH=$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)
  304. while (($#)); do
  305. case "${1}" in
  306. --check|-c)
  307. echo "Checking remote code for updates..."
  308. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized ${BRANCH} | cut -f1)
  309. if [ $? -ne 0 ]; then
  310. echo "A problem occurred while trying to fetch the latest revision from github."
  311. exit 99
  312. fi
  313. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  314. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  315. git log --date=short --pretty=format:"%ad - %s" $(git rev-parse --short HEAD)..origin/master
  316. exit 0
  317. else
  318. echo "No updates available."
  319. exit 3
  320. fi
  321. ;;
  322. --ours)
  323. MERGE_STRATEGY=ours
  324. ;;
  325. --skip-start)
  326. SKIP_START=y
  327. ;;
  328. --skip-ping-check)
  329. SKIP_PING_CHECK=y
  330. ;;
  331. --stable)
  332. CURRENT_BRANCH="$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)"
  333. NEW_BRANCH="master"
  334. ;;
  335. --gc)
  336. echo -e "\e[32mCollecting garbage...\e[0m"
  337. docker_garbage
  338. exit 0
  339. ;;
  340. --nightly)
  341. CURRENT_BRANCH="$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)"
  342. NEW_BRANCH="nightly"
  343. ;;
  344. --prefetch)
  345. echo -e "\e[32mPrefetching images...\e[0m"
  346. prefetch_images
  347. exit 0
  348. ;;
  349. -f|--force)
  350. echo -e "\e[32mRunning in forced mode...\e[0m"
  351. FORCE=y
  352. ;;
  353. -d|--dev)
  354. echo -e "\e[32mRunning in Developer mode...\e[0m"
  355. DEV=y
  356. ;;
  357. --help|-h)
  358. echo './update.sh [-c|--check, --ours, --gc, --nightly, --prefetch, --skip-start, --skip-ping-check, --stable, -f|--force, -d|--dev, -h|--help]
  359. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  360. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  361. --gc - Run garbage collector to delete old image tags
  362. --nightly - Switch your mailcow updates to the unstable (nightly) branch. FOR TESTING PURPOSES ONLY!!!!
  363. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  364. --skip-start - Do not start mailcow after update
  365. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you´ve blocked any ICMP Connections to your mailcow machine)
  366. --stable - Switch your mailcow updates to the stable (master) branch. Default unless you changed it with --nightly.
  367. -f|--force - Force update, do not ask questions
  368. -d|--dev - Enables Developer Mode (No Checkout of update.sh for tests)
  369. '
  370. exit 1
  371. esac
  372. shift
  373. done
  374. chmod 600 mailcow.conf
  375. source mailcow.conf
  376. detect_docker_compose_command
  377. [[ ! -f mailcow.conf ]] && { echo "mailcow.conf is missing! Is mailcow installed?"; exit 1;}
  378. DOTS=${MAILCOW_HOSTNAME//[^.]};
  379. if [ ${#DOTS} -lt 2 ]; then
  380. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!"
  381. echo "Please change it to a FQDN and run $COMPOSE_COMMAND down followed by $COMPOSE_COMMAND up -d"
  382. exit 1
  383. fi
  384. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  385. # This will also cover sort
  386. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  387. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  388. CONFIG_ARRAY=(
  389. "SKIP_LETS_ENCRYPT"
  390. "SKIP_SOGO"
  391. "USE_WATCHDOG"
  392. "WATCHDOG_NOTIFY_EMAIL"
  393. "WATCHDOG_NOTIFY_BAN"
  394. "WATCHDOG_EXTERNAL_CHECKS"
  395. "WATCHDOG_SUBJECT"
  396. "SKIP_CLAMD"
  397. "SKIP_IP_CHECK"
  398. "ADDITIONAL_SAN"
  399. "DOVEADM_PORT"
  400. "IPV4_NETWORK"
  401. "IPV6_NETWORK"
  402. "LOG_LINES"
  403. "SNAT_TO_SOURCE"
  404. "SNAT6_TO_SOURCE"
  405. "COMPOSE_PROJECT_NAME"
  406. "DOCKER_COMPOSE_VERSION"
  407. "SQL_PORT"
  408. "API_KEY"
  409. "API_KEY_READ_ONLY"
  410. "API_ALLOW_FROM"
  411. "MAILDIR_GC_TIME"
  412. "MAILDIR_SUB"
  413. "ACL_ANYONE"
  414. "SOLR_HEAP"
  415. "SKIP_SOLR"
  416. "ENABLE_SSL_SNI"
  417. "ALLOW_ADMIN_EMAIL_LOGIN"
  418. "SKIP_HTTP_VERIFICATION"
  419. "SOGO_EXPIRE_SESSION"
  420. "REDIS_PORT"
  421. "DOVECOT_MASTER_USER"
  422. "DOVECOT_MASTER_PASS"
  423. "MAILCOW_PASS_SCHEME"
  424. "ADDITIONAL_SERVER_NAMES"
  425. "ACME_CONTACT"
  426. "WATCHDOG_VERBOSE"
  427. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  428. "SPAMHAUS_DQS_KEY"
  429. )
  430. detect_bad_asn
  431. sed -i --follow-symlinks '$a\' mailcow.conf
  432. for option in ${CONFIG_ARRAY[@]}; do
  433. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  434. if ! grep -q ${option} mailcow.conf; then
  435. echo "Adding new option \"${option}\" to mailcow.conf"
  436. echo "${option}=" >> mailcow.conf
  437. fi
  438. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  439. if ! grep -q ${option} mailcow.conf; then
  440. echo "Adding new option \"${option}\" to mailcow.conf"
  441. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  442. fi
  443. elif [[ ${option} == "DOCKER_COMPOSE_VERSION" ]]; then
  444. if ! grep -q ${option} mailcow.conf; then
  445. echo "Adding new option \"${option}\" to mailcow.conf"
  446. echo "# Used Docker Compose version" >> mailcow.conf
  447. echo "# Switch here between native (compose plugin) and standalone" >> mailcow.conf
  448. echo "# For more informations take a look at the mailcow docs regarding the configuration options." >> mailcow.conf
  449. echo "# Normally this should be untouched but if you decided to use either of those you can switch it manually here." >> mailcow.conf
  450. echo "# Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail." >> mailcow.conf
  451. echo "" >> mailcow.conf
  452. echo "DOCKER_COMPOSE_VERSION=${DOCKER_COMPOSE_VERSION}" >> mailcow.conf
  453. fi
  454. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  455. if ! grep -q ${option} mailcow.conf; then
  456. echo "Adding new option \"${option}\" to mailcow.conf"
  457. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  458. fi
  459. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  460. if ! grep -q ${option} mailcow.conf; then
  461. echo "Adding new option \"${option}\" to mailcow.conf"
  462. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  463. fi
  464. elif [[ ${option} == "LOG_LINES" ]]; then
  465. if ! grep -q ${option} mailcow.conf; then
  466. echo "Adding new option \"${option}\" to mailcow.conf"
  467. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  468. echo "LOG_LINES=9999" >> mailcow.conf
  469. fi
  470. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  471. if ! grep -q ${option} mailcow.conf; then
  472. echo "Adding new option \"${option}\" to mailcow.conf"
  473. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  474. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  475. fi
  476. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  477. if ! grep -q ${option} mailcow.conf; then
  478. echo "Adding new option \"${option}\" to mailcow.conf"
  479. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  480. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  481. fi
  482. elif [[ ${option} == "SQL_PORT" ]]; then
  483. if ! grep -q ${option} mailcow.conf; then
  484. echo "Adding new option \"${option}\" to mailcow.conf"
  485. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  486. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  487. fi
  488. elif [[ ${option} == "API_KEY" ]]; then
  489. if ! grep -q ${option} mailcow.conf; then
  490. echo "Adding new option \"${option}\" to mailcow.conf"
  491. echo '# Create or override API key for web UI' >> mailcow.conf
  492. echo "#API_KEY=" >> mailcow.conf
  493. fi
  494. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  495. if ! grep -q ${option} mailcow.conf; then
  496. echo "Adding new option \"${option}\" to mailcow.conf"
  497. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  498. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  499. fi
  500. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  501. if ! grep -q ${option} mailcow.conf; then
  502. echo "Adding new option \"${option}\" to mailcow.conf"
  503. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  504. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  505. echo "#API_ALLOW_FROM=" >> mailcow.conf
  506. fi
  507. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  508. if ! grep -q ${option} mailcow.conf; then
  509. echo "Adding new option \"${option}\" to mailcow.conf"
  510. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  511. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  512. fi
  513. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  514. if ! grep -q ${option} mailcow.conf; then
  515. echo "Adding new option \"${option}\" to mailcow.conf"
  516. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  517. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  518. fi
  519. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  520. if ! grep -q ${option} mailcow.conf; then
  521. echo "Adding new option \"${option}\" to mailcow.conf"
  522. echo '# Garbage collector cleanup' >> mailcow.conf
  523. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  524. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  525. echo '# Check interval is hourly' >> mailcow.conf
  526. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  527. fi
  528. elif [[ ${option} == "ACL_ANYONE" ]]; then
  529. if ! grep -q ${option} mailcow.conf; then
  530. echo "Adding new option \"${option}\" to mailcow.conf"
  531. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  532. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  533. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  534. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  535. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  536. fi
  537. elif [[ ${option} == "SOLR_HEAP" ]]; then
  538. if ! grep -q ${option} mailcow.conf; then
  539. echo "Adding new option \"${option}\" to mailcow.conf"
  540. echo '# Solr heap size, there is no recommendation, please see Solr docs.' >> mailcow.conf
  541. echo '# Solr is a prone to run OOM on large systems and should be monitored. Unmonitored Solr setups are not recommended.' >> mailcow.conf
  542. echo '# Solr will refuse to start with total system memory below or equal to 2 GB.' >> mailcow.conf
  543. echo "SOLR_HEAP=1024" >> mailcow.conf
  544. fi
  545. elif [[ ${option} == "SKIP_SOLR" ]]; then
  546. if ! grep -q ${option} mailcow.conf; then
  547. echo "Adding new option \"${option}\" to mailcow.conf"
  548. echo '# Solr is disabled by default after upgrading from non-Solr to Solr-enabled mailcows.' >> mailcow.conf
  549. echo '# Disable Solr or if you do not want to store a readable index of your mails in solr-vol-1.' >> mailcow.conf
  550. echo "SKIP_SOLR=y" >> mailcow.conf
  551. fi
  552. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  553. if ! grep -q ${option} mailcow.conf; then
  554. echo "Adding new option \"${option}\" to mailcow.conf"
  555. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  556. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  557. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  558. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  559. fi
  560. elif [[ ${option} == "SKIP_SOGO" ]]; then
  561. if ! grep -q ${option} mailcow.conf; then
  562. echo "Adding new option \"${option}\" to mailcow.conf"
  563. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  564. echo "SKIP_SOGO=n" >> mailcow.conf
  565. fi
  566. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  567. if ! grep -q ${option} mailcow.conf; then
  568. echo "Adding new option \"${option}\" to mailcow.conf"
  569. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  570. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  571. echo "MAILDIR_SUB=" >> mailcow.conf
  572. fi
  573. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  574. if ! grep -q ${option} mailcow.conf; then
  575. echo "Adding new option \"${option}\" to mailcow.conf"
  576. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  577. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  578. fi
  579. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  580. if ! grep -q ${option} mailcow.conf; then
  581. echo "Adding new option \"${option}\" to mailcow.conf"
  582. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  583. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  584. fi
  585. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  586. if ! grep -q ${option} mailcow.conf; then
  587. echo "Adding new option \"${option}\" to mailcow.conf"
  588. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  589. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  590. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  591. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  592. fi
  593. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  594. if ! grep -q ${option} mailcow.conf; then
  595. echo "Adding new option \"${option}\" to mailcow.conf"
  596. echo '# SOGo session timeout in minutes' >> mailcow.conf
  597. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  598. fi
  599. elif [[ ${option} == "REDIS_PORT" ]]; then
  600. if ! grep -q ${option} mailcow.conf; then
  601. echo "Adding new option \"${option}\" to mailcow.conf"
  602. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  603. fi
  604. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  605. if ! grep -q ${option} mailcow.conf; then
  606. echo "Adding new option \"${option}\" to mailcow.conf"
  607. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  608. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  609. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  610. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  611. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  612. fi
  613. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  614. if ! grep -q ${option} mailcow.conf; then
  615. echo "Adding new option \"${option}\" to mailcow.conf"
  616. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  617. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  618. fi
  619. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  620. if ! grep -q ${option} mailcow.conf; then
  621. echo "Adding new option \"${option}\" to mailcow.conf"
  622. echo '# Password hash algorithm' >> mailcow.conf
  623. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  624. echo '# see https://docs.mailcow.email/models/model-passwd/' >> mailcow.conf
  625. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  626. fi
  627. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  628. if ! grep -q ${option} mailcow.conf; then
  629. echo "Adding new option \"${option}\" to mailcow.conf"
  630. echo '# Additional server names for mailcow UI' >> mailcow.conf
  631. echo '#' >> mailcow.conf
  632. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  633. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  634. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  635. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  636. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  637. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  638. fi
  639. elif [[ ${option} == "ACME_CONTACT" ]]; then
  640. if ! grep -q ${option} mailcow.conf; then
  641. echo "Adding new option \"${option}\" to mailcow.conf"
  642. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  643. echo '# Optional: Leave empty for none' >> mailcow.conf
  644. echo '# This value is only used on first order!' >> mailcow.conf
  645. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  646. echo '# https://docs.mailcow.email/troubleshooting/debug-reset_tls/' >> mailcow.conf
  647. echo 'ACME_CONTACT=' >> mailcow.conf
  648. fi
  649. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  650. if ! grep -q ${option} mailcow.conf; then
  651. echo "Adding new option \"${option}\" to mailcow.conf"
  652. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  653. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  654. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  655. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  656. fi
  657. elif [[ ${option} == "SPAMHAUS_DQS_KEY" ]]; then
  658. if ! grep -q ${option} mailcow.conf; then
  659. echo "Adding new option \"${option}\" to mailcow.conf"
  660. echo "# Spamhaus Data Query Service Key" >> mailcow.conf
  661. echo '# Optional: Leave empty for none' >> mailcow.conf
  662. echo '# Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.' >> mailcow.conf
  663. echo '# If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.' >> mailcow.conf
  664. echo '# Otherwise it will work as usual.' >> mailcow.conf
  665. echo 'SPAMHAUS_DQS_KEY=' >> mailcow.conf
  666. fi
  667. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  668. if ! grep -q ${option} mailcow.conf; then
  669. echo "Adding new option \"${option}\" to mailcow.conf"
  670. echo '# Enable watchdog verbose logging' >> mailcow.conf
  671. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  672. fi
  673. elif ! grep -q ${option} mailcow.conf; then
  674. echo "Adding new option \"${option}\" to mailcow.conf"
  675. echo "${option}=n" >> mailcow.conf
  676. fi
  677. done
  678. if [[( ${SKIP_PING_CHECK} == "y")]]; then
  679. echo -e "\e[32mSkipping Ping Check...\e[0m"
  680. else
  681. echo -en "Checking internet connection... "
  682. if ! check_online_status; then
  683. echo -e "\e[31mfailed\e[0m"
  684. exit 1
  685. else
  686. echo -e "\e[32mOK\e[0m"
  687. fi
  688. fi
  689. if ! [ $NEW_BRANCH ]; then
  690. echo -e "\e[33mDetecting which build your mailcow runs on...\e[0m"
  691. sleep 1
  692. if [ ${BRANCH} == "master" ]; then
  693. echo -e "\e[32mYou are receiving stable updates (master).\e[0m"
  694. echo -e "\e[33mTo change that run the update.sh Script one time with the --nightly parameter to switch to nightly builds.\e[0m"
  695. elif [ ${BRANCH} == "nightly" ]; then
  696. echo -e "\e[31mYou are receiving unstable updates (nightly). These are for testing purposes only!!!\e[0m"
  697. sleep 1
  698. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  699. else
  700. echo -e "\e[33mYou are receiving updates from a unsupported branch.\e[0m"
  701. sleep 1
  702. echo -e "\e[33mThe mailcow stack might still work but it is recommended to switch to the master branch (stable builds).\e[0m"
  703. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  704. fi
  705. elif [ $FORCE ]; then
  706. echo -e "\e[31mYou are running in forced mode!\e[0m"
  707. echo -e "\e[31mA Branch Switch can only be performed manually (monitored).\e[0m"
  708. echo -e "\e[31mPlease rerun the update.sh Script without the --force/-f parameter.\e[0m"
  709. sleep 1
  710. elif [ $NEW_BRANCH == "master" ] && [ $CURRENT_BRANCH != "master" ]; then
  711. echo -e "\e[33mYou are about to switch your mailcow Updates to the stable (master) branch.\e[0m"
  712. sleep 1
  713. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no Data is lost...\e[0m"
  714. sleep 1
  715. echo -e "\e[31mWARNING: Please see on GitHub or ask in the communitys if a switch to master is stable or not.
  716. In some rear cases a Update back to master can destroy your mailcow configuration in case of Database Upgrades etc.
  717. Normally a upgrade back to master should be safe during each full release.
  718. Check GitHub for Database Changes and Update only if there similar to the full release!\e[0m"
  719. read -r -p "Are you sure you that want to continue upgrading to the stable (master) branch? [y/N] " response
  720. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  721. echo "OK. If you prepared yourself for that please run the update.sh Script with the --stable parameter again to trigger this process here."
  722. exit 0
  723. fi
  724. BRANCH=$NEW_BRANCH
  725. DIFF_DIRECTORY=update_diffs
  726. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_master_$(date +"%Y-%m-%d-%H-%M-%S")
  727. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  728. if ! git diff-index --quiet HEAD; then
  729. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  730. mkdir -p ${DIFF_DIRECTORY}
  731. git diff ${BRANCH} --stat > ${DIFF_FILE}
  732. git diff ${BRANCH} >> ${DIFF_FILE}
  733. fi
  734. echo -e "\e[32mSwitching Branch to ${BRANCH}...\e[0m"
  735. git fetch origin
  736. git checkout -f ${BRANCH}
  737. elif [ $NEW_BRANCH == "nightly" ] && [ $CURRENT_BRANCH != "nightly" ]; then
  738. echo -e "\e[33mYou are about to switch your mailcow Updates to the unstable (nightly) branch.\e[0m"
  739. sleep 1
  740. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no Data is lost...\e[0m"
  741. sleep 1
  742. echo -e "\e[31mWARNING: A switch to nightly is possible any time. But a switch back (to master) isn't.\e[0m"
  743. read -r -p "Are you sure you that want to continue upgrading to the unstable (nightly) branch? [y/N] " response
  744. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  745. echo "OK. If you prepared yourself for that please run the update.sh Script with the --nightly parameter again to trigger this process here."
  746. exit 0
  747. fi
  748. BRANCH=$NEW_BRANCH
  749. DIFF_DIRECTORY=update_diffs
  750. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_nightly_$(date +"%Y-%m-%d-%H-%M-%S")
  751. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  752. if ! git diff-index --quiet HEAD; then
  753. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  754. mkdir -p ${DIFF_DIRECTORY}
  755. git diff ${BRANCH} --stat > ${DIFF_FILE}
  756. git diff ${BRANCH} >> ${DIFF_FILE}
  757. fi
  758. git fetch origin
  759. git checkout -f ${BRANCH}
  760. fi
  761. if [ ! $DEV ]; then
  762. echo -e "\e[32mChecking for newer update script...\e[0m"
  763. SHA1_1=$(sha1sum update.sh)
  764. git fetch origin #${BRANCH}
  765. git checkout origin/${BRANCH} update.sh
  766. SHA1_2=$(sha1sum update.sh)
  767. if [[ ${SHA1_1} != ${SHA1_2} ]]; then
  768. echo "update.sh changed, please run this script again, exiting."
  769. chmod +x update.sh
  770. exit 2
  771. fi
  772. fi
  773. if [ ! $FORCE ]; then
  774. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  775. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  776. echo "OK, exiting."
  777. exit 0
  778. fi
  779. migrate_docker_nat
  780. fi
  781. remove_obsolete_nginx_ports
  782. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  783. sed -i 's/HTTPS_BIND:-:/HTTPS_BIND:-/g' docker-compose.yml
  784. sed -i 's/HTTP_BIND:-:/HTTP_BIND:-/g' docker-compose.yml
  785. if ! $COMPOSE_COMMAND config -q; then
  786. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  787. exit 1
  788. fi
  789. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  790. MAILCOW_BRIDGE=$($COMPOSE_COMMAND config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  791. while read NAT_ID; do
  792. iptables -t nat -D POSTROUTING $NAT_ID
  793. done < <(iptables -L -vn -t nat --line-numbers | grep $IPV4_NETWORK | grep -E 'MASQUERADE.*all' | grep -v ${MAILCOW_BRIDGE} | cut -d' ' -f1)
  794. DIFF_DIRECTORY=update_diffs
  795. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  796. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  797. if ! git diff-index --quiet HEAD; then
  798. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  799. mkdir -p ${DIFF_DIRECTORY}
  800. git diff --stat > ${DIFF_FILE}
  801. git diff >> ${DIFF_FILE}
  802. fi
  803. echo -e "\e[32mPrefetching images...\e[0m"
  804. prefetch_images
  805. echo -e "\e[32mStopping mailcow...\e[0m"
  806. sleep 2
  807. MAILCOW_CONTAINERS=($($COMPOSE_COMMAND ps -q))
  808. $COMPOSE_COMMAND down
  809. echo -e "\e[32mChecking for remaining containers...\e[0m"
  810. sleep 2
  811. for container in "${MAILCOW_CONTAINERS[@]}"; do
  812. docker rm -f "$container" 2> /dev/null
  813. done
  814. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  815. # Silently fixing remote url from andryyy to mailcow
  816. git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  817. echo -e "\e[32mCommitting current status...\e[0m"
  818. [[ -z "$(git config user.name)" ]] && git config user.name moo
  819. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  820. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  821. git add -u
  822. git commit -am "Before update on ${DATE}" > /dev/null
  823. echo -e "\e[32mFetching updated code from remote...\e[0m"
  824. git fetch origin #${BRANCH}
  825. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  826. git config merge.defaultToUpstream true
  827. git merge -X${MERGE_STRATEGY:-theirs} -Xpatience -m "After update on ${DATE}"
  828. # Need to use a variable to not pass return codes of if checks
  829. MERGE_RETURN=$?
  830. if [[ ${MERGE_RETURN} == 128 ]]; then
  831. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  832. exit 1
  833. elif [[ ${MERGE_RETURN} == 1 ]]; then
  834. echo -e "\e[93mPotenial conflict, trying to fix...\e[0m"
  835. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  836. git add -A
  837. git commit -m "After update on ${DATE}" > /dev/null
  838. git checkout .
  839. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  840. elif [[ ${MERGE_RETURN} != 0 ]]; then
  841. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  842. echo
  843. echo "Run $COMPOSE_COMMAND up -d to restart your stack without updates or try again after fixing the mentioned errors."
  844. exit 1
  845. fi
  846. echo -e "\e[32mFetching new images, if any...\e[0m"
  847. sleep 2
  848. $COMPOSE_COMMAND pull
  849. # Fix missing SSL, does not overwrite existing files
  850. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  851. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  852. echo -e "Checking IPv6 settings... "
  853. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  854. echo
  855. echo '!! IMPORTANT !!'
  856. echo
  857. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  858. echo "This setting will only be active after a complete shutdown of mailcow by running $COMPOSE_COMMAND down followed by $COMPOSE_COMMAND up -d."
  859. echo
  860. echo '!! IMPORTANT !!'
  861. echo
  862. read -p "Press any key to continue..." < /dev/tty
  863. fi
  864. # Checking for old project name bug
  865. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  866. # Fix Rspamd maps
  867. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  868. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  869. fi
  870. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  871. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  872. fi
  873. # Fix deprecated metrics.conf
  874. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  875. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  876. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  877. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  878. fi
  879. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  880. fi
  881. # Set app_info.inc.php
  882. if [ ${BRANCH} == "master" ]; then
  883. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  884. elif [ ${BRANCH} == "nightly" ]; then
  885. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  886. mailcow_last_git_version=""
  887. else
  888. mailcow_git_version=$(git rev-parse --short HEAD)
  889. mailcow_last_git_version=""
  890. fi
  891. mailcow_git_commit=$(git rev-parse origin/${BRANCH})
  892. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  893. if [ $? -eq 0 ]; then
  894. echo '<?php' > data/web/inc/app_info.inc.php
  895. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  896. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  897. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  898. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  899. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  900. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  901. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  902. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  903. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  904. echo '?>' >> data/web/inc/app_info.inc.php
  905. else
  906. echo '<?php' > data/web/inc/app_info.inc.php
  907. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  908. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  909. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  910. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  911. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  912. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  913. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  914. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  915. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  916. echo '?>' >> data/web/inc/app_info.inc.php
  917. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  918. fi
  919. if [[ ${SKIP_START} == "y" ]]; then
  920. echo -e "\e[33mNot starting mailcow, please run \"$COMPOSE_COMMAND up -d --remove-orphans\" to start mailcow.\e[0m"
  921. else
  922. echo -e "\e[32mStarting mailcow...\e[0m"
  923. sleep 2
  924. $COMPOSE_COMMAND up -d --remove-orphans
  925. fi
  926. echo -e "\e[32mCollecting garbage...\e[0m"
  927. docker_garbage
  928. # Run post-update-hook
  929. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  930. bash "${SCRIPT_DIR}/post_update_hook.sh"
  931. fi
  932. # echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  933. # echo
  934. # git reflog --color=always | grep "Before update on "
  935. # echo
  936. # echo "Use \"git reset --hard hash-on-the-left\" and run $COMPOSE_COMMAND up -d afterwards."