update.sh 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742
  1. #!/usr/bin/env bash
  2. # Check permissions
  3. if [ "$(id -u)" -ne "0" ]; then
  4. echo "You need to be root"
  5. exit 1
  6. fi
  7. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  8. # Run pre-update-hook
  9. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  10. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  11. fi
  12. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  13. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  14. echo "Please update to 5.x or use another distribution."
  15. exit 1
  16. fi
  17. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  18. if grep -q Ubuntu <<< $(uname -a); then
  19. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  20. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  21. exit 1
  22. fi
  23. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  24. read -p "Press any key to continue..." < /dev/tty
  25. fi
  26. # Exit on error and pipefail
  27. set -o pipefail
  28. # Setting high dc timeout
  29. export COMPOSE_HTTP_TIMEOUT=600
  30. # Add /opt/bin to PATH
  31. PATH=$PATH:/opt/bin
  32. umask 0022
  33. for bin in curl docker git awk sha1sum; do
  34. if [[ -z $(which ${bin}) ]]; then echo "Cannot find ${bin}, exiting..."; exit 1; fi
  35. done
  36. echo "checking docker compose version...";
  37. if docker compose >/dev/null 2>&1; then
  38. echo -e "\e[32mFound Compose v2!\e[0m"
  39. COMPOSE_COMMAND="docker compose"
  40. elif docker-compose version --short | grep -m1 "^1" > /dev/null 2>&1; then
  41. echo -e "\e[33mWARN: Your machine is using Docker-Compose v1!\e[0m"
  42. echo -e "\e[33mmailcow will drop the Docker-Compose v1 Support in December 2022\e[0m"
  43. echo -e "\e[33mPlease consider a upgrade to Docker-Compose v2.\e[0m"
  44. echo
  45. echo
  46. echo -e "\e[33mContinuing...\e[0m"
  47. sleep 3
  48. COMPOSE_COMMAND="docker-compose"
  49. else
  50. echo -e "\e[31mCannot find Docker-Compose v1 or v2 on your System. Please install Docker-Compose v2 and re-run the Script.\e[0m"
  51. exit 1
  52. fi
  53. export LC_ALL=C
  54. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  55. BRANCH=$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)
  56. check_online_status() {
  57. CHECK_ONLINE_IPS=(1.1.1.1 9.9.9.9 8.8.8.8)
  58. for ip in "${CHECK_ONLINE_IPS[@]}"; do
  59. if timeout 3 ping -c 1 ${ip} > /dev/null; then
  60. return 0
  61. fi
  62. done
  63. return 1
  64. }
  65. prefetch_images() {
  66. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  67. git fetch origin #${BRANCH}
  68. while read image; do
  69. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  70. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  71. continue
  72. fi
  73. fi
  74. RET_C=0
  75. until docker pull ${image}; do
  76. RET_C=$((RET_C + 1))
  77. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  78. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  79. sleep 1
  80. done
  81. done < <(git show origin/${BRANCH}:docker-compose.yml | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  82. }
  83. docker_garbage() {
  84. IMGS_TO_DELETE=()
  85. for container in $(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"); do
  86. REPOSITORY=${container/:*}
  87. TAG=${container/*:}
  88. V_MAIN=${container/*.}
  89. V_SUB=${container/*.}
  90. EXISTING_TAGS=$(docker images | grep ${REPOSITORY} | awk '{ print $2 }')
  91. for existing_tag in ${EXISTING_TAGS[@]}; do
  92. V_MAIN_EXISTING=${existing_tag/*.}
  93. V_SUB_EXISTING=${existing_tag/*.}
  94. # Not an integer
  95. [[ ! $V_MAIN_EXISTING =~ ^[0-9]+$ ]] && continue
  96. [[ ! $V_SUB_EXISTING =~ ^[0-9]+$ ]] && continue
  97. if [[ $V_MAIN_EXISTING == "latest" ]]; then
  98. echo "Found deprecated label \"latest\" for repository $REPOSITORY, it should be deleted."
  99. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  100. elif [[ $V_MAIN_EXISTING -lt $V_MAIN ]]; then
  101. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  102. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  103. elif [[ $V_SUB_EXISTING -lt $V_SUB ]]; then
  104. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  105. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  106. fi
  107. done
  108. done
  109. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  110. echo "Run the following command to delete unused image tags:"
  111. echo
  112. echo " docker rmi ${IMGS_TO_DELETE[*]}"
  113. echo
  114. if [ ! $FORCE ]; then
  115. read -r -p "Do you want to delete old image tags right now? [y/N] " response
  116. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  117. docker rmi ${IMGS_TO_DELETE[*]}
  118. else
  119. echo "OK, skipped."
  120. fi
  121. else
  122. echo "Running image removal without extra confirmation due to force mode."
  123. docker rmi ${IMGS_TO_DELETE[*]}
  124. fi
  125. echo -e "\e[32mFurther cleanup...\e[0m"
  126. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  127. fi
  128. }
  129. in_array() {
  130. local e match="$1"
  131. shift
  132. for e; do [[ "$e" == "$match" ]] && return 0; done
  133. return 1
  134. }
  135. migrate_docker_nat() {
  136. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  137. # Min Docker version
  138. DOCKERV_REQ=20.10.2
  139. # Current Docker version
  140. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  141. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  142. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  143. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  144. echo '!!! This step is recommended !!!'
  145. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  146. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  147. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  148. echo "OK, skipping this step."
  149. return 0
  150. fi
  151. fi
  152. # Sort versions and check if we are running a newer or equal version to req
  153. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  154. # If Dockerd daemon json exists
  155. if [ -s /etc/docker/daemon.json ]; then
  156. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  157. if ! in_array ipv6true "${dockerconfig[@]}" || \
  158. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  159. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  160. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  161. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  162. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  163. echo -e "Please merge the following content and restart the Docker daemon:\n"
  164. echo ${NAT_CONFIG}
  165. return 1
  166. fi
  167. else
  168. echo "Working on IPv6 NAT, please wait..."
  169. echo ${NAT_CONFIG} > /etc/docker/daemon.json
  170. ip6tables -F -t nat
  171. [[ -e /etc/alpine-release ]] && rc-service docker restart || systemctl restart docker.service
  172. if [[ $? -ne 0 ]]; then
  173. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  174. rm /etc/docker/daemon.json
  175. if [[ -e /etc/alpine-release ]]; then
  176. rc-service docker restart
  177. else
  178. systemctl reset-failed docker.service
  179. systemctl restart docker.service
  180. fi
  181. return 1
  182. fi
  183. fi
  184. # Removing legacy container
  185. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  186. if [ -s docker-compose.override.yml ]; then
  187. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  188. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  189. mv docker-compose.override.yml docker-compose.override.yml_backup
  190. fi
  191. fi
  192. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  193. else
  194. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  195. return 0
  196. fi
  197. }
  198. while (($#)); do
  199. case "${1}" in
  200. --check|-c)
  201. echo "Checking remote code for updates..."
  202. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized ${BRANCH} | cut -f1)
  203. if [ $? -ne 0 ]; then
  204. echo "A problem occurred while trying to fetch the latest revision from github."
  205. exit 99
  206. fi
  207. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  208. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  209. git log --date=short --pretty=format:"%ad - %s" $(git rev-parse --short HEAD)..origin/master
  210. exit 0
  211. else
  212. echo "No updates available."
  213. exit 3
  214. fi
  215. ;;
  216. --ours)
  217. MERGE_STRATEGY=ours
  218. ;;
  219. --skip-start)
  220. SKIP_START=y
  221. ;;
  222. --gc)
  223. echo -e "\e[32mCollecting garbage...\e[0m"
  224. docker_garbage
  225. exit 0
  226. ;;
  227. --prefetch)
  228. echo -e "\e[32mPrefetching images...\e[0m"
  229. prefetch_images
  230. exit 0
  231. ;;
  232. -f|--force)
  233. echo -e "\e[32mRunning in forced mode...\e[0m"
  234. FORCE=y
  235. ;;
  236. --skip-ping-check)
  237. SKIP_PING_CHECK=y
  238. ;;
  239. --help|-h)
  240. echo './update.sh [-c|--check, --ours, --gc, --no-update-compose, --prefetch, --skip-start, --skip-ping-check, -f|--force, -h|--help]
  241. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  242. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  243. --gc - Run garbage collector to delete old image tags
  244. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  245. --skip-start - Do not start mailcow after update
  246. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you´ve blocked any ICMP Connections to your mailcow machine).
  247. -f|--force - Force update, do not ask questions
  248. '
  249. exit 1
  250. esac
  251. shift
  252. done
  253. [[ ! -f mailcow.conf ]] && { echo "mailcow.conf is missing"; exit 1;}
  254. chmod 600 mailcow.conf
  255. source mailcow.conf
  256. DOTS=${MAILCOW_HOSTNAME//[^.]};
  257. if [ ${#DOTS} -lt 2 ]; then
  258. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!"
  259. echo "Please change it to a FQDN and run ${COMPOSE_COMMAND} down followed by ${COMPOSE_COMMAND} up -d"
  260. exit 1
  261. fi
  262. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  263. # This will also cover sort
  264. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  265. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  266. CONFIG_ARRAY=(
  267. "SKIP_LETS_ENCRYPT"
  268. "SKIP_SOGO"
  269. "USE_WATCHDOG"
  270. "WATCHDOG_NOTIFY_EMAIL"
  271. "WATCHDOG_NOTIFY_BAN"
  272. "WATCHDOG_EXTERNAL_CHECKS"
  273. "WATCHDOG_SUBJECT"
  274. "SKIP_CLAMD"
  275. "SKIP_IP_CHECK"
  276. "ADDITIONAL_SAN"
  277. "DOVEADM_PORT"
  278. "IPV4_NETWORK"
  279. "IPV6_NETWORK"
  280. "LOG_LINES"
  281. "SNAT_TO_SOURCE"
  282. "SNAT6_TO_SOURCE"
  283. "COMPOSE_PROJECT_NAME"
  284. "SQL_PORT"
  285. "API_KEY"
  286. "API_KEY_READ_ONLY"
  287. "API_ALLOW_FROM"
  288. "MAILDIR_GC_TIME"
  289. "MAILDIR_SUB"
  290. "ACL_ANYONE"
  291. "SOLR_HEAP"
  292. "SKIP_SOLR"
  293. "ENABLE_SSL_SNI"
  294. "ALLOW_ADMIN_EMAIL_LOGIN"
  295. "SKIP_HTTP_VERIFICATION"
  296. "SOGO_EXPIRE_SESSION"
  297. "REDIS_PORT"
  298. "DOVECOT_MASTER_USER"
  299. "DOVECOT_MASTER_PASS"
  300. "MAILCOW_PASS_SCHEME"
  301. "ADDITIONAL_SERVER_NAMES"
  302. "ACME_CONTACT"
  303. "WATCHDOG_VERBOSE"
  304. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  305. )
  306. sed -i --follow-symlinks '$a\' mailcow.conf
  307. for option in ${CONFIG_ARRAY[@]}; do
  308. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  309. if ! grep -q ${option} mailcow.conf; then
  310. echo "Adding new option \"${option}\" to mailcow.conf"
  311. echo "${option}=" >> mailcow.conf
  312. fi
  313. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  314. if ! grep -q ${option} mailcow.conf; then
  315. echo "Adding new option \"${option}\" to mailcow.conf"
  316. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  317. fi
  318. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  319. if ! grep -q ${option} mailcow.conf; then
  320. echo "Adding new option \"${option}\" to mailcow.conf"
  321. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  322. fi
  323. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  324. if ! grep -q ${option} mailcow.conf; then
  325. echo "Adding new option \"${option}\" to mailcow.conf"
  326. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  327. fi
  328. elif [[ ${option} == "LOG_LINES" ]]; then
  329. if ! grep -q ${option} mailcow.conf; then
  330. echo "Adding new option \"${option}\" to mailcow.conf"
  331. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  332. echo "LOG_LINES=9999" >> mailcow.conf
  333. fi
  334. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  335. if ! grep -q ${option} mailcow.conf; then
  336. echo "Adding new option \"${option}\" to mailcow.conf"
  337. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  338. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  339. fi
  340. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  341. if ! grep -q ${option} mailcow.conf; then
  342. echo "Adding new option \"${option}\" to mailcow.conf"
  343. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  344. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  345. fi
  346. elif [[ ${option} == "SQL_PORT" ]]; then
  347. if ! grep -q ${option} mailcow.conf; then
  348. echo "Adding new option \"${option}\" to mailcow.conf"
  349. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  350. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  351. fi
  352. elif [[ ${option} == "API_KEY" ]]; then
  353. if ! grep -q ${option} mailcow.conf; then
  354. echo "Adding new option \"${option}\" to mailcow.conf"
  355. echo '# Create or override API key for web UI' >> mailcow.conf
  356. echo "#API_KEY=" >> mailcow.conf
  357. fi
  358. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  359. if ! grep -q ${option} mailcow.conf; then
  360. echo "Adding new option \"${option}\" to mailcow.conf"
  361. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  362. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  363. fi
  364. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  365. if ! grep -q ${option} mailcow.conf; then
  366. echo "Adding new option \"${option}\" to mailcow.conf"
  367. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  368. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  369. echo "#API_ALLOW_FROM=" >> mailcow.conf
  370. fi
  371. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  372. if ! grep -q ${option} mailcow.conf; then
  373. echo "Adding new option \"${option}\" to mailcow.conf"
  374. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  375. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  376. fi
  377. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  378. if ! grep -q ${option} mailcow.conf; then
  379. echo "Adding new option \"${option}\" to mailcow.conf"
  380. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  381. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  382. fi
  383. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  384. if ! grep -q ${option} mailcow.conf; then
  385. echo "Adding new option \"${option}\" to mailcow.conf"
  386. echo '# Garbage collector cleanup' >> mailcow.conf
  387. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  388. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  389. echo '# Check interval is hourly' >> mailcow.conf
  390. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  391. fi
  392. elif [[ ${option} == "ACL_ANYONE" ]]; then
  393. if ! grep -q ${option} mailcow.conf; then
  394. echo "Adding new option \"${option}\" to mailcow.conf"
  395. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  396. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  397. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  398. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  399. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  400. fi
  401. elif [[ ${option} == "SOLR_HEAP" ]]; then
  402. if ! grep -q ${option} mailcow.conf; then
  403. echo "Adding new option \"${option}\" to mailcow.conf"
  404. echo '# Solr heap size, there is no recommendation, please see Solr docs.' >> mailcow.conf
  405. echo '# Solr is a prone to run OOM on large systems and should be monitored. Unmonitored Solr setups are not recommended.' >> mailcow.conf
  406. echo '# Solr will refuse to start with total system memory below or equal to 2 GB.' >> mailcow.conf
  407. echo "SOLR_HEAP=1024" >> mailcow.conf
  408. fi
  409. elif [[ ${option} == "SKIP_SOLR" ]]; then
  410. if ! grep -q ${option} mailcow.conf; then
  411. echo "Adding new option \"${option}\" to mailcow.conf"
  412. echo '# Solr is disabled by default after upgrading from non-Solr to Solr-enabled mailcows.' >> mailcow.conf
  413. echo '# Disable Solr or if you do not want to store a readable index of your mails in solr-vol-1.' >> mailcow.conf
  414. echo "SKIP_SOLR=y" >> mailcow.conf
  415. fi
  416. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  417. if ! grep -q ${option} mailcow.conf; then
  418. echo "Adding new option \"${option}\" to mailcow.conf"
  419. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  420. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  421. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  422. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  423. fi
  424. elif [[ ${option} == "SKIP_SOGO" ]]; then
  425. if ! grep -q ${option} mailcow.conf; then
  426. echo "Adding new option \"${option}\" to mailcow.conf"
  427. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  428. echo "SKIP_SOGO=n" >> mailcow.conf
  429. fi
  430. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  431. if ! grep -q ${option} mailcow.conf; then
  432. echo "Adding new option \"${option}\" to mailcow.conf"
  433. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  434. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  435. echo "MAILDIR_SUB=" >> mailcow.conf
  436. fi
  437. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  438. if ! grep -q ${option} mailcow.conf; then
  439. echo "Adding new option \"${option}\" to mailcow.conf"
  440. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  441. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  442. fi
  443. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  444. if ! grep -q ${option} mailcow.conf; then
  445. echo "Adding new option \"${option}\" to mailcow.conf"
  446. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  447. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  448. fi
  449. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  450. if ! grep -q ${option} mailcow.conf; then
  451. echo "Adding new option \"${option}\" to mailcow.conf"
  452. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  453. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  454. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  455. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  456. fi
  457. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  458. if ! grep -q ${option} mailcow.conf; then
  459. echo "Adding new option \"${option}\" to mailcow.conf"
  460. echo '# SOGo session timeout in minutes' >> mailcow.conf
  461. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  462. fi
  463. elif [[ ${option} == "REDIS_PORT" ]]; then
  464. if ! grep -q ${option} mailcow.conf; then
  465. echo "Adding new option \"${option}\" to mailcow.conf"
  466. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  467. fi
  468. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  469. if ! grep -q ${option} mailcow.conf; then
  470. echo "Adding new option \"${option}\" to mailcow.conf"
  471. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  472. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  473. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  474. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  475. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  476. fi
  477. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  478. if ! grep -q ${option} mailcow.conf; then
  479. echo "Adding new option \"${option}\" to mailcow.conf"
  480. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  481. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  482. fi
  483. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  484. if ! grep -q ${option} mailcow.conf; then
  485. echo "Adding new option \"${option}\" to mailcow.conf"
  486. echo '# Password hash algorithm' >> mailcow.conf
  487. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  488. echo '# see https://mailcow.github.io/mailcow-dockerized-docs/models/model-passwd/' >> mailcow.conf
  489. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  490. fi
  491. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  492. if ! grep -q ${option} mailcow.conf; then
  493. echo '# Additional server names for mailcow UI' >> mailcow.conf
  494. echo '#' >> mailcow.conf
  495. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  496. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  497. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  498. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  499. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  500. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  501. fi
  502. elif [[ ${option} == "ACME_CONTACT" ]]; then
  503. if ! grep -q ${option} mailcow.conf; then
  504. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  505. echo '# Optional: Leave empty for none' >> mailcow.conf
  506. echo '# This value is only used on first order!' >> mailcow.conf
  507. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  508. echo '# https://mailcow.github.io/mailcow-dockerized-docs/troubleshooting/debug-reset_tls/' >> mailcow.conf
  509. echo 'ACME_CONTACT=' >> mailcow.conf
  510. fi
  511. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  512. if ! grep -q ${option} mailcow.conf; then
  513. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  514. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  515. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  516. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  517. fi
  518. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  519. if ! grep -q ${option} mailcow.conf; then
  520. echo '# Enable watchdog verbose logging' >> mailcow.conf
  521. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  522. fi
  523. elif ! grep -q ${option} mailcow.conf; then
  524. echo "Adding new option \"${option}\" to mailcow.conf"
  525. echo "${option}=n" >> mailcow.conf
  526. fi
  527. done
  528. if [[( ${SKIP_PING_CHECK} == "y")]]; then
  529. echo -e "\e[32mSkipping Ping Check...\e[0m"
  530. else
  531. echo -en "Checking internet connection... "
  532. if ! check_online_status; then
  533. echo -e "\e[31mfailed\e[0m"
  534. exit 1
  535. else
  536. echo -e "\e[32mOK\e[0m"
  537. fi
  538. fi
  539. echo -e "\e[32mChecking for newer update script...\e[0m"
  540. SHA1_1=$(sha1sum update.sh)
  541. git fetch origin #${BRANCH}
  542. git checkout origin/${BRANCH} update.sh
  543. SHA1_2=$(sha1sum update.sh)
  544. if [[ ${SHA1_1} != ${SHA1_2} ]]; then
  545. echo "update.sh changed, please run this script again, exiting."
  546. chmod +x update.sh
  547. exit 2
  548. fi
  549. if [[ -f mailcow.conf ]]; then
  550. source mailcow.conf
  551. else
  552. echo -e "\e[31mNo mailcow.conf - is mailcow installed?\e[0m"
  553. exit 1
  554. fi
  555. if [ ! $FORCE ]; then
  556. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  557. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  558. echo "OK, exiting."
  559. exit 0
  560. fi
  561. migrate_docker_nat
  562. fi
  563. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  564. if ! ${COMPOSE_COMMAND} config -q; then
  565. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  566. exit 1
  567. fi
  568. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  569. MAILCOW_BRIDGE=$(${COMPOSE_COMMAND} config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  570. while read NAT_ID; do
  571. iptables -t nat -D POSTROUTING $NAT_ID
  572. done < <(iptables -L -vn -t nat --line-numbers | grep $IPV4_NETWORK | grep -E 'MASQUERADE.*all' | grep -v ${MAILCOW_BRIDGE} | cut -d' ' -f1)
  573. DIFF_DIRECTORY=update_diffs
  574. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  575. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  576. if ! git diff-index --quiet HEAD; then
  577. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  578. mkdir -p ${DIFF_DIRECTORY}
  579. git diff --stat > ${DIFF_FILE}
  580. git diff >> ${DIFF_FILE}
  581. fi
  582. echo -e "\e[32mPrefetching images...\e[0m"
  583. prefetch_images
  584. echo -e "\e[32mStopping mailcow...\e[0m"
  585. sleep 2
  586. MAILCOW_CONTAINERS=($(${COMPOSE_COMMAND} ps -q))
  587. ${COMPOSE_COMMAND} down
  588. echo -e "\e[32mChecking for remaining containers...\e[0m"
  589. sleep 2
  590. for container in "${MAILCOW_CONTAINERS[@]}"; do
  591. docker rm -f "$container" 2> /dev/null
  592. done
  593. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  594. # Silently fixing remote url from andryyy to mailcow
  595. git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  596. echo -e "\e[32mCommitting current status...\e[0m"
  597. [[ -z "$(git config user.name)" ]] && git config user.name moo
  598. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  599. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  600. git add -u
  601. git commit -am "Before update on ${DATE}" > /dev/null
  602. echo -e "\e[32mFetching updated code from remote...\e[0m"
  603. git fetch origin #${BRANCH}
  604. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  605. git config merge.defaultToUpstream true
  606. git merge -X${MERGE_STRATEGY:-theirs} -Xpatience -m "After update on ${DATE}"
  607. # Need to use a variable to not pass return codes of if checks
  608. MERGE_RETURN=$?
  609. if [[ ${MERGE_RETURN} == 128 ]]; then
  610. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  611. exit 1
  612. elif [[ ${MERGE_RETURN} == 1 ]]; then
  613. echo -e "\e[93mPotenial conflict, trying to fix...\e[0m"
  614. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  615. git add -A
  616. git commit -m "After update on ${DATE}" > /dev/null
  617. git checkout .
  618. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  619. elif [[ ${MERGE_RETURN} != 0 ]]; then
  620. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  621. echo
  622. echo "Run ${COMPOSE_COMMAND} up -d to restart your stack without updates or try again after fixing the mentioned errors."
  623. exit 1
  624. fi
  625. echo -e "\e[33mNot fetching latest docker-compose, please check for updates manually!\e[0m"
  626. sleep 3
  627. echo -e "\e[32mFetching new images, if any...\e[0m"
  628. sleep 2
  629. ${COMPOSE_COMMAND} pull
  630. # Fix missing SSL, does not overwrite existing files
  631. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  632. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  633. echo -e "Checking IPv6 settings... "
  634. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  635. echo
  636. echo '!! IMPORTANT !!'
  637. echo
  638. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  639. echo 'This setting will only be active after a complete shutdown of mailcow by running "docker-compose down" followed by "docker-compose up -d".'
  640. echo
  641. echo '!! IMPORTANT !!'
  642. echo
  643. read -p "Press any key to continue..." < /dev/tty
  644. fi
  645. # Checking for old project name bug
  646. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  647. # Fix Rspamd maps
  648. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  649. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  650. fi
  651. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  652. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  653. fi
  654. # Fix deprecated metrics.conf
  655. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  656. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  657. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  658. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  659. fi
  660. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  661. fi
  662. # Set app_info.inc.php
  663. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  664. if [ $? -eq 0 ]; then
  665. echo '<?php' > data/web/inc/app_info.inc.php
  666. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  667. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  668. echo '?>' >> data/web/inc/app_info.inc.php
  669. else
  670. echo '<?php' > data/web/inc/app_info.inc.php
  671. echo ' $MAILCOW_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  672. echo ' $MAILCOW_GIT_URL="";' >> data/web/inc/app_info.inc.php
  673. echo '?>' >> data/web/inc/app_info.inc.php
  674. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  675. fi
  676. if [[ ${SKIP_START} == "y" ]]; then
  677. echo -e "\e[33mNot starting mailcow, please run \"${COMPOSE_COMMAND} up -d --remove-orphans\" to start mailcow.\e[0m"
  678. else
  679. echo -e "\e[32mStarting mailcow...\e[0m"
  680. sleep 2
  681. ${COMPOSE_COMMAND} up -d --remove-orphans
  682. fi
  683. echo -e "\e[32mCollecting garbage...\e[0m"
  684. docker_garbage
  685. # Run post-update-hook
  686. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  687. bash "${SCRIPT_DIR}/post_update_hook.sh"
  688. fi
  689. #echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  690. #echo
  691. #git reflog --color=always | grep "Before update on "
  692. #echo
  693. #echo "Use \"git reset --hard hash-on-the-left\" and run ${COMPOSE_COMMAND} up -d afterwards."