docker-entrypoint.sh 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225
  1. #!/bin/bash
  2. function array_by_comma { local IFS=","; echo "$*"; }
  3. # Wait for containers
  4. while ! mariadb-admin status --ssl=false --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  5. echo "Waiting for SQL..."
  6. sleep 2
  7. done
  8. # Do not attempt to write to slave
  9. if [[ ! -z ${REDIS_SLAVEOF_IP} ]]; then
  10. REDIS_HOST=$REDIS_SLAVEOF_IP
  11. REDIS_PORT=$REDIS_SLAVEOF_PORT
  12. else
  13. REDIS_HOST="redis"
  14. REDIS_PORT="6379"
  15. fi
  16. REDIS_CMDLINE="redis-cli -h ${REDIS_HOST} -p ${REDIS_PORT} -a ${REDISPASS}"
  17. until [[ $(${REDIS_CMDLINE} PING) == "PONG" ]]; do
  18. echo "Waiting for Redis..."
  19. sleep 2
  20. done
  21. # Set redis session store
  22. echo -n '
  23. session.save_handler = redis
  24. session.save_path = "tcp://'${REDIS_HOST}':'${REDIS_PORT}'?auth='${REDISPASS}'"
  25. ' > /usr/local/etc/php/conf.d/session_store.ini
  26. # Check mysql_upgrade (master and slave)
  27. CONTAINER_ID=
  28. until [[ ! -z "${CONTAINER_ID}" ]] && [[ "${CONTAINER_ID}" =~ ^[[:alnum:]]*$ ]]; do
  29. CONTAINER_ID=$(curl --silent --insecure https://dockerapi.${COMPOSE_PROJECT_NAME}_mailcow-network/containers/json | jq -r ".[] | {name: .Config.Labels[\"com.docker.compose.service\"], project: .Config.Labels[\"com.docker.compose.project\"], id: .Id}" 2> /dev/null | jq -rc "select( .name | tostring | contains(\"mysql-mailcow\")) | select( .project | tostring | contains(\"${COMPOSE_PROJECT_NAME,,}\")) | .id" 2> /dev/null)
  30. echo "Could not get mysql-mailcow container id... trying again"
  31. sleep 2
  32. done
  33. echo "MySQL @ ${CONTAINER_ID}"
  34. SQL_LOOP_C=0
  35. SQL_CHANGED=0
  36. until [[ ${SQL_UPGRADE_STATUS} == 'success' ]]; do
  37. if [ ${SQL_LOOP_C} -gt 4 ]; then
  38. echo "Tried to upgrade MySQL and failed, giving up after ${SQL_LOOP_C} retries and starting container (oops, not good)"
  39. break
  40. fi
  41. SQL_FULL_UPGRADE_RETURN=$(curl --silent --insecure -XPOST https://dockerapi.${COMPOSE_PROJECT_NAME}_mailcow-network/containers/${CONTAINER_ID}/exec -d '{"cmd":"system", "task":"mysql_upgrade"}' --silent -H 'Content-type: application/json')
  42. SQL_UPGRADE_STATUS=$(echo ${SQL_FULL_UPGRADE_RETURN} | jq -r .type)
  43. SQL_LOOP_C=$((SQL_LOOP_C+1))
  44. echo "SQL upgrade iteration #${SQL_LOOP_C}"
  45. if [[ ${SQL_UPGRADE_STATUS} == 'warning' ]]; then
  46. SQL_CHANGED=1
  47. echo "MySQL applied an upgrade, debug output:"
  48. echo ${SQL_FULL_UPGRADE_RETURN}
  49. sleep 3
  50. while ! mariadb-admin status --ssl=false --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  51. echo "Waiting for SQL to return, please wait"
  52. sleep 2
  53. done
  54. continue
  55. elif [[ ${SQL_UPGRADE_STATUS} == 'success' ]]; then
  56. echo "MySQL is up-to-date - debug output:"
  57. echo ${SQL_FULL_UPGRADE_RETURN}
  58. else
  59. echo "No valid reponse for mysql_upgrade was received, debug output:"
  60. echo ${SQL_FULL_UPGRADE_RETURN}
  61. fi
  62. done
  63. # doing post-installation stuff, if SQL was upgraded (master and slave)
  64. if [ ${SQL_CHANGED} -eq 1 ]; then
  65. POSTFIX=$(curl --silent --insecure https://dockerapi.${COMPOSE_PROJECT_NAME}_mailcow-network/containers/json | jq -r ".[] | {name: .Config.Labels[\"com.docker.compose.service\"], project: .Config.Labels[\"com.docker.compose.project\"], id: .Id}" 2> /dev/null | jq -rc "select( .name | tostring | contains(\"postfix-mailcow\")) | select( .project | tostring | contains(\"${COMPOSE_PROJECT_NAME,,}\")) | .id" 2> /dev/null)
  66. if [[ -z "${POSTFIX}" ]] || ! [[ "${POSTFIX}" =~ ^[[:alnum:]]*$ ]]; then
  67. echo "Could not determine Postfix container ID, skipping Postfix restart."
  68. else
  69. echo "Restarting Postfix"
  70. curl -X POST --silent --insecure https://dockerapi.${COMPOSE_PROJECT_NAME}_mailcow-network/containers/${POSTFIX}/restart | jq -r '.msg'
  71. echo "Sleeping 5 seconds..."
  72. sleep 5
  73. fi
  74. fi
  75. # Check mysql tz import (master and slave)
  76. TZ_CHECK=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT CONVERT_TZ('2019-11-02 23:33:00','Europe/Berlin','UTC') AS time;" -BN 2> /dev/null)
  77. if [[ -z ${TZ_CHECK} ]] || [[ "${TZ_CHECK}" == "NULL" ]]; then
  78. SQL_FULL_TZINFO_IMPORT_RETURN=$(curl --silent --insecure -XPOST https://dockerapi.${COMPOSE_PROJECT_NAME}_mailcow-network/containers/${CONTAINER_ID}/exec -d '{"cmd":"system", "task":"mysql_tzinfo_to_sql"}' --silent -H 'Content-type: application/json')
  79. echo "MySQL mysql_tzinfo_to_sql - debug output:"
  80. echo ${SQL_FULL_TZINFO_IMPORT_RETURN}
  81. fi
  82. if [[ "${MASTER}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  83. echo "We are master, preparing..."
  84. # Set a default release format
  85. if [[ -z $(${REDIS_CMDLINE} --raw GET Q_RELEASE_FORMAT) ]]; then
  86. ${REDIS_CMDLINE} --raw SET Q_RELEASE_FORMAT raw
  87. fi
  88. # Set max age of q items - if unset
  89. if [[ -z $(${REDIS_CMDLINE} --raw GET Q_MAX_AGE) ]]; then
  90. ${REDIS_CMDLINE} --raw SET Q_MAX_AGE 365
  91. fi
  92. # Set default password policy - if unset
  93. if [[ -z $(${REDIS_CMDLINE} --raw HGET PASSWD_POLICY length) ]]; then
  94. ${REDIS_CMDLINE} --raw HSET PASSWD_POLICY length 6
  95. ${REDIS_CMDLINE} --raw HSET PASSWD_POLICY chars 0
  96. ${REDIS_CMDLINE} --raw HSET PASSWD_POLICY special_chars 0
  97. ${REDIS_CMDLINE} --raw HSET PASSWD_POLICY lowerupper 0
  98. ${REDIS_CMDLINE} --raw HSET PASSWD_POLICY numbers 0
  99. fi
  100. # Trigger db init
  101. echo "Running DB init..."
  102. php -c /usr/local/etc/php -f /web/inc/init_db.inc.php
  103. # Recreating domain map
  104. echo "Rebuilding domain map in Redis..."
  105. declare -a DOMAIN_ARR
  106. ${REDIS_CMDLINE} DEL DOMAIN_MAP > /dev/null
  107. while read line
  108. do
  109. DOMAIN_ARR+=("$line")
  110. done < <(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain FROM domain" -Bs)
  111. while read line
  112. do
  113. DOMAIN_ARR+=("$line")
  114. done < <(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT alias_domain FROM alias_domain" -Bs)
  115. if [[ ! -z ${DOMAIN_ARR} ]]; then
  116. for domain in "${DOMAIN_ARR[@]}"; do
  117. ${REDIS_CMDLINE} HSET DOMAIN_MAP ${domain} 1 > /dev/null
  118. done
  119. fi
  120. # Set API options if env vars are not empty
  121. if [[ ${API_ALLOW_FROM} != "invalid" ]] && [[ ! -z ${API_ALLOW_FROM} ]]; then
  122. IFS=',' read -r -a API_ALLOW_FROM_ARR <<< "${API_ALLOW_FROM}"
  123. declare -a VALIDATED_API_ALLOW_FROM_ARR
  124. REGEX_IP6='^([0-9a-fA-F]{0,4}:){1,7}[0-9a-fA-F]{0,4}(/([0-9]|[1-9][0-9]|1[0-1][0-9]|12[0-8]))?$'
  125. REGEX_IP4='^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+(/([0-9]|[1-2][0-9]|3[0-2]))?$'
  126. for IP in "${API_ALLOW_FROM_ARR[@]}"; do
  127. if [[ ${IP} =~ ${REGEX_IP6} ]] || [[ ${IP} =~ ${REGEX_IP4} ]]; then
  128. VALIDATED_API_ALLOW_FROM_ARR+=("${IP}")
  129. fi
  130. done
  131. VALIDATED_IPS=$(array_by_comma ${VALIDATED_API_ALLOW_FROM_ARR[*]})
  132. if [[ ! -z ${VALIDATED_IPS} ]]; then
  133. if [[ ${API_KEY} != "invalid" ]] && [[ ! -z ${API_KEY} ]]; then
  134. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  135. DELETE FROM api WHERE access = 'rw';
  136. INSERT INTO api (api_key, active, allow_from, access) VALUES ("${API_KEY}", "1", "${VALIDATED_IPS}", "rw");
  137. EOF
  138. fi
  139. if [[ ${API_KEY_READ_ONLY} != "invalid" ]] && [[ ! -z ${API_KEY_READ_ONLY} ]]; then
  140. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  141. DELETE FROM api WHERE access = 'ro';
  142. INSERT INTO api (api_key, active, allow_from, access) VALUES ("${API_KEY_READ_ONLY}", "1", "${VALIDATED_IPS}", "ro");
  143. EOF
  144. fi
  145. fi
  146. fi
  147. # Create events (master only, STATUS for event on slave will be SLAVESIDE_DISABLED)
  148. mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} << EOF
  149. DROP EVENT IF EXISTS clean_spamalias;
  150. DELIMITER //
  151. CREATE EVENT clean_spamalias
  152. ON SCHEDULE EVERY 1 DAY DO
  153. BEGIN
  154. DELETE FROM spamalias WHERE validity < UNIX_TIMESTAMP();
  155. END;
  156. //
  157. DELIMITER ;
  158. DROP EVENT IF EXISTS clean_oauth2;
  159. DELIMITER //
  160. CREATE EVENT clean_oauth2
  161. ON SCHEDULE EVERY 1 DAY DO
  162. BEGIN
  163. DELETE FROM oauth_refresh_tokens WHERE expires < NOW();
  164. DELETE FROM oauth_access_tokens WHERE expires < NOW();
  165. DELETE FROM oauth_authorization_codes WHERE expires < NOW();
  166. END;
  167. //
  168. DELIMITER ;
  169. DROP EVENT IF EXISTS clean_sasl_log;
  170. DELIMITER //
  171. CREATE EVENT clean_sasl_log
  172. ON SCHEDULE EVERY 1 DAY DO
  173. BEGIN
  174. DELETE sasl_log.* FROM sasl_log
  175. LEFT JOIN (
  176. SELECT username, service, MAX(datetime) AS lastdate
  177. FROM sasl_log
  178. GROUP BY username, service
  179. ) AS last ON sasl_log.username = last.username AND sasl_log.service = last.service
  180. WHERE datetime < DATE_SUB(NOW(), INTERVAL 31 DAY) AND datetime < lastdate;
  181. DELETE FROM sasl_log
  182. WHERE username NOT IN (SELECT username FROM mailbox) AND
  183. datetime < DATE_SUB(NOW(), INTERVAL 31 DAY);
  184. END;
  185. //
  186. DELIMITER ;
  187. EOF
  188. fi
  189. # Create dummy for custom overrides of mailcow style
  190. [[ ! -f /web/css/build/0081-custom-mailcow.css ]] && echo '/* Autogenerated by mailcow */' > /web/css/build/0081-custom-mailcow.css
  191. # Fix permissions for global filters
  192. chown -R 82:82 /global_sieve/*
  193. # Fix permissions on twig cache folder
  194. chown -R 82:82 /web/templates/cache
  195. # Clear cache
  196. find /web/templates/cache/* -not -name '.gitkeep' -delete
  197. # Run hooks
  198. for file in /hooks/*; do
  199. if [ -x "${file}" ]; then
  200. echo "Running hook ${file}"
  201. "${file}"
  202. fi
  203. done
  204. exec "$@"