update.sh 34 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811
  1. #!/usr/bin/env bash
  2. # Check permissions
  3. if [ "$(id -u)" -ne "0" ]; then
  4. echo "You need to be root"
  5. exit 1
  6. fi
  7. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  8. # Run pre-update-hook
  9. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  10. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  11. fi
  12. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  13. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  14. echo "Please update to 5.x or use another distribution."
  15. exit 1
  16. fi
  17. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  18. if grep -q Ubuntu <<< $(uname -a); then
  19. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  20. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  21. exit 1
  22. fi
  23. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  24. read -p "Press any key to continue..." < /dev/tty
  25. fi
  26. # Exit on error and pipefail
  27. set -o pipefail
  28. # Setting high dc timeout
  29. export COMPOSE_HTTP_TIMEOUT=600
  30. # Add /opt/bin to PATH
  31. PATH=$PATH:/opt/bin
  32. umask 0022
  33. for bin in curl docker git awk sha1sum; do
  34. if [[ -z $(which ${bin}) ]]; then
  35. echo "Cannot find ${bin}, exiting..."
  36. exit 1;
  37. elif [[ -z $(which docker-compose) ]]; then
  38. echo "Cannot find docker-compose Standalone. Installing..."
  39. sleep 3
  40. if [[ -e /etc/alpine-release ]]; then
  41. echo -e "\e[33mNot installing latest docker-compose, because you are using Alpine Linux without glibc support. Install docker-compose via apk!\e[0m"
  42. exit 1
  43. fi
  44. curl -#L https://github.com/docker/compose/releases/download/v$(curl -Ls https://www.servercow.de/docker-compose/latest.php)/docker-compose-$(uname -s)-$(uname -m) > /usr/local/bin/docker-compose
  45. chmod +x /usr/local/bin/docker-compose
  46. fi
  47. done
  48. export LC_ALL=C
  49. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  50. BRANCH=$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)
  51. check_online_status() {
  52. CHECK_ONLINE_IPS=(1.1.1.1 9.9.9.9 8.8.8.8)
  53. for ip in "${CHECK_ONLINE_IPS[@]}"; do
  54. if timeout 3 ping -c 1 ${ip} > /dev/null; then
  55. return 0
  56. fi
  57. done
  58. return 1
  59. }
  60. prefetch_images() {
  61. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  62. git fetch origin #${BRANCH}
  63. while read image; do
  64. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  65. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  66. continue
  67. fi
  68. fi
  69. RET_C=0
  70. until docker pull ${image}; do
  71. RET_C=$((RET_C + 1))
  72. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  73. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  74. sleep 1
  75. done
  76. done < <(git show origin/${BRANCH}:docker-compose.yml | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  77. }
  78. docker_garbage() {
  79. IMGS_TO_DELETE=()
  80. for container in $(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"); do
  81. REPOSITORY=${container/:*}
  82. TAG=${container/*:}
  83. V_MAIN=${container/*.}
  84. V_SUB=${container/*.}
  85. EXISTING_TAGS=$(docker images | grep ${REPOSITORY} | awk '{ print $2 }')
  86. for existing_tag in ${EXISTING_TAGS[@]}; do
  87. V_MAIN_EXISTING=${existing_tag/*.}
  88. V_SUB_EXISTING=${existing_tag/*.}
  89. # Not an integer
  90. [[ ! $V_MAIN_EXISTING =~ ^[0-9]+$ ]] && continue
  91. [[ ! $V_SUB_EXISTING =~ ^[0-9]+$ ]] && continue
  92. if [[ $V_MAIN_EXISTING == "latest" ]]; then
  93. echo "Found deprecated label \"latest\" for repository $REPOSITORY, it should be deleted."
  94. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  95. elif [[ $V_MAIN_EXISTING -lt $V_MAIN ]]; then
  96. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  97. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  98. elif [[ $V_SUB_EXISTING -lt $V_SUB ]]; then
  99. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  100. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  101. fi
  102. done
  103. done
  104. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  105. echo "Run the following command to delete unused image tags:"
  106. echo
  107. echo " docker rmi ${IMGS_TO_DELETE[*]}"
  108. echo
  109. if [ ! $FORCE ]; then
  110. read -r -p "Do you want to delete old image tags right now? [y/N] " response
  111. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  112. docker rmi ${IMGS_TO_DELETE[*]}
  113. else
  114. echo "OK, skipped."
  115. fi
  116. else
  117. echo "Running image removal without extra confirmation due to force mode."
  118. docker rmi ${IMGS_TO_DELETE[*]}
  119. fi
  120. echo -e "\e[32mFurther cleanup...\e[0m"
  121. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  122. fi
  123. }
  124. in_array() {
  125. local e match="$1"
  126. shift
  127. for e; do [[ "$e" == "$match" ]] && return 0; done
  128. return 1
  129. }
  130. migrate_docker_nat() {
  131. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  132. # Min Docker version
  133. DOCKERV_REQ=20.10.2
  134. # Current Docker version
  135. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  136. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  137. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  138. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  139. echo '!!! This step is recommended !!!'
  140. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  141. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  142. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  143. echo "OK, skipping this step."
  144. return 0
  145. fi
  146. fi
  147. # Sort versions and check if we are running a newer or equal version to req
  148. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  149. # If Dockerd daemon json exists
  150. if [ -s /etc/docker/daemon.json ]; then
  151. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  152. if ! in_array ipv6true "${dockerconfig[@]}" || \
  153. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  154. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  155. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  156. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  157. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  158. echo -e "Please merge the following content and restart the Docker daemon:\n"
  159. echo ${NAT_CONFIG}
  160. return 1
  161. fi
  162. else
  163. echo "Working on IPv6 NAT, please wait..."
  164. echo ${NAT_CONFIG} > /etc/docker/daemon.json
  165. ip6tables -F -t nat
  166. [[ -e /etc/alpine-release ]] && rc-service docker restart || systemctl restart docker.service
  167. if [[ $? -ne 0 ]]; then
  168. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  169. rm /etc/docker/daemon.json
  170. if [[ -e /etc/alpine-release ]]; then
  171. rc-service docker restart
  172. else
  173. systemctl reset-failed docker.service
  174. systemctl restart docker.service
  175. fi
  176. return 1
  177. fi
  178. fi
  179. # Removing legacy container
  180. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  181. if [ -s docker-compose.override.yml ]; then
  182. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  183. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  184. mv docker-compose.override.yml docker-compose.override.yml_backup
  185. fi
  186. fi
  187. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  188. else
  189. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  190. return 0
  191. fi
  192. }
  193. remove_obsolete_nginx_ports() {
  194. # Removing obsolete docker-compose.override.yml
  195. for override in docker-compose.override.yml docker-compose.override.yaml; do
  196. if [ -s $override ] ; then
  197. if cat $override | grep nginx-mailcow > /dev/null 2>&1; then
  198. if cat $override | grep -E '(\[::])' > /dev/null 2>&1; then
  199. if cat $override | grep -w 80:80 > /dev/null 2>&1 && cat $override | grep -w 443:443 > /dev/null 2>&1 ; then
  200. echo -e "\e[33mBacking up ${override} to preserve custom changes...\e[0m"
  201. echo -e "\e[33m!!! Manual Merge needed (if other overrides are set) !!!\e[0m"
  202. sleep 3
  203. cp $override ${override}_backup
  204. sed -i '/nginx-mailcow:$/,/^$/d' $override
  205. echo -e "\e[33mRemoved obsolete NGINX IPv6 Bind from original override File.\e[0m"
  206. if [[ "$(cat $override | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  207. mv $override ${override}_backup
  208. echo -e "\e[31m${override} is empty. Renamed it to ensure mailcow is startable.\e[0m"
  209. fi
  210. fi
  211. fi
  212. fi
  213. fi
  214. done
  215. }
  216. update_compose(){
  217. if [[ ${NO_UPDATE_COMPOSE} == "y" ]]; then
  218. echo -e "\e[33mNot fetching latest docker-compose, please check for updates manually!\e[0m"
  219. return 0
  220. elif [[ -e /etc/alpine-release ]]; then
  221. echo -e "\e[33mNot fetching latest docker-compose, because you are using Alpine Linux without glibc support. Please update docker-compose via apk!\e[0m"
  222. return 0
  223. else
  224. echo -e "\e[32mFetching new docker-compose version...\e[0m"
  225. echo -e "\e[32mTrying to determine GLIBC version...\e[0m"
  226. if ldd --version > /dev/null; then
  227. GLIBC_V=$(ldd --version | grep -E '(GLIBC|GNU libc)' | rev | cut -d ' ' -f1 | rev | cut -d '.' -f2)
  228. if [ ! -z "${GLIBC_V}" ] && [ ${GLIBC_V} -gt 27 ]; then
  229. DC_DL_SUFFIX=
  230. else
  231. DC_DL_SUFFIX=legacy
  232. fi
  233. else
  234. DC_DL_SUFFIX=legacy
  235. fi
  236. sleep 1
  237. if [[ ! -z $(which pip) && $(pip list --local 2>&1 | grep -v DEPRECATION | grep -c docker-compose) == 1 ]]; then
  238. true
  239. #prevent breaking a working docker-compose installed with pip
  240. elif [[ $(curl -sL -w "%{http_code}" https://www.servercow.de/docker-compose/latest.php?vers=${DC_DL_SUFFIX} -o /dev/null) == "200" ]]; then
  241. LATEST_COMPOSE=$(curl -#L https://www.servercow.de/docker-compose/latest.php)
  242. COMPOSE_VERSION=$(docker-compose version --short)
  243. if [[ "$LATEST_COMPOSE" != "$COMPOSE_VERSION" ]]; then
  244. COMPOSE_PATH=$(which docker-compose)
  245. if [[ -w ${COMPOSE_PATH} ]]; then
  246. curl -#L https://github.com/docker/compose/releases/download/v${LATEST_COMPOSE}/docker-compose-$(uname -s)-$(uname -m) > $COMPOSE_PATH
  247. chmod +x $COMPOSE_PATH
  248. else
  249. echo -e "\e[33mWARNING: $COMPOSE_PATH is not writable, but new version $LATEST_COMPOSE is available (installed: $COMPOSE_VERSION)\e[0m"
  250. return 1
  251. fi
  252. fi
  253. else
  254. echo -e "\e[33mCannot determine latest docker-compose version, skipping...\e[0m"
  255. return 1
  256. fi
  257. fi
  258. }
  259. while (($#)); do
  260. case "${1}" in
  261. --check|-c)
  262. echo "Checking remote code for updates..."
  263. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized ${BRANCH} | cut -f1)
  264. if [ $? -ne 0 ]; then
  265. echo "A problem occurred while trying to fetch the latest revision from github."
  266. exit 99
  267. fi
  268. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  269. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  270. git log --date=short --pretty=format:"%ad - %s" $(git rev-parse --short HEAD)..origin/master
  271. exit 0
  272. else
  273. echo "No updates available."
  274. exit 3
  275. fi
  276. ;;
  277. --ours)
  278. MERGE_STRATEGY=ours
  279. ;;
  280. --skip-start)
  281. SKIP_START=y
  282. ;;
  283. --gc)
  284. echo -e "\e[32mCollecting garbage...\e[0m"
  285. docker_garbage
  286. exit 0
  287. ;;
  288. --prefetch)
  289. echo -e "\e[32mPrefetching images...\e[0m"
  290. prefetch_images
  291. exit 0
  292. ;;
  293. -f|--force)
  294. echo -e "\e[32mRunning in forced mode...\e[0m"
  295. FORCE=y
  296. ;;
  297. --no-update-compose)
  298. NO_UPDATE_COMPOSE=y
  299. ;;
  300. --skip-ping-check)
  301. SKIP_PING_CHECK=y
  302. ;;
  303. --help|-h)
  304. echo './update.sh [-c|--check, --ours, --gc, --no-update-compose, --prefetch, --skip-start, --skip-ping-check, -f|--force, -h|--help]
  305. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  306. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  307. --gc - Run garbage collector to delete old image tags
  308. --no-update-compose - Do not update docker-compose
  309. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  310. --skip-start - Do not start mailcow after update
  311. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you´ve blocked any ICMP Connections to your mailcow machine).
  312. -f|--force - Force update, do not ask questions
  313. '
  314. exit 1
  315. esac
  316. shift
  317. done
  318. [[ ! -f mailcow.conf ]] && { echo "mailcow.conf is missing"; exit 1;}
  319. chmod 600 mailcow.conf
  320. source mailcow.conf
  321. DOTS=${MAILCOW_HOSTNAME//[^.]};
  322. if [ ${#DOTS} -lt 2 ]; then
  323. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!"
  324. echo "Please change it to a FQDN and run docker-compose down followed by docker-compose up -d"
  325. exit 1
  326. fi
  327. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  328. # This will also cover sort
  329. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  330. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  331. CONFIG_ARRAY=(
  332. "SKIP_LETS_ENCRYPT"
  333. "SKIP_SOGO"
  334. "USE_WATCHDOG"
  335. "WATCHDOG_NOTIFY_EMAIL"
  336. "WATCHDOG_NOTIFY_BAN"
  337. "WATCHDOG_EXTERNAL_CHECKS"
  338. "WATCHDOG_SUBJECT"
  339. "SKIP_CLAMD"
  340. "SKIP_IP_CHECK"
  341. "ADDITIONAL_SAN"
  342. "DOVEADM_PORT"
  343. "IPV4_NETWORK"
  344. "IPV6_NETWORK"
  345. "LOG_LINES"
  346. "SNAT_TO_SOURCE"
  347. "SNAT6_TO_SOURCE"
  348. "COMPOSE_PROJECT_NAME"
  349. "SQL_PORT"
  350. "API_KEY"
  351. "API_KEY_READ_ONLY"
  352. "API_ALLOW_FROM"
  353. "MAILDIR_GC_TIME"
  354. "MAILDIR_SUB"
  355. "ACL_ANYONE"
  356. "SOLR_HEAP"
  357. "SKIP_SOLR"
  358. "ENABLE_SSL_SNI"
  359. "ALLOW_ADMIN_EMAIL_LOGIN"
  360. "SKIP_HTTP_VERIFICATION"
  361. "SOGO_EXPIRE_SESSION"
  362. "REDIS_PORT"
  363. "DOVECOT_MASTER_USER"
  364. "DOVECOT_MASTER_PASS"
  365. "MAILCOW_PASS_SCHEME"
  366. "ADDITIONAL_SERVER_NAMES"
  367. "ACME_CONTACT"
  368. "WATCHDOG_VERBOSE"
  369. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  370. )
  371. sed -i --follow-symlinks '$a\' mailcow.conf
  372. for option in ${CONFIG_ARRAY[@]}; do
  373. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  374. if ! grep -q ${option} mailcow.conf; then
  375. echo "Adding new option \"${option}\" to mailcow.conf"
  376. echo "${option}=" >> mailcow.conf
  377. fi
  378. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  379. if ! grep -q ${option} mailcow.conf; then
  380. echo "Adding new option \"${option}\" to mailcow.conf"
  381. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  382. fi
  383. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  384. if ! grep -q ${option} mailcow.conf; then
  385. echo "Adding new option \"${option}\" to mailcow.conf"
  386. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  387. fi
  388. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  389. if ! grep -q ${option} mailcow.conf; then
  390. echo "Adding new option \"${option}\" to mailcow.conf"
  391. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  392. fi
  393. elif [[ ${option} == "LOG_LINES" ]]; then
  394. if ! grep -q ${option} mailcow.conf; then
  395. echo "Adding new option \"${option}\" to mailcow.conf"
  396. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  397. echo "LOG_LINES=9999" >> mailcow.conf
  398. fi
  399. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  400. if ! grep -q ${option} mailcow.conf; then
  401. echo "Adding new option \"${option}\" to mailcow.conf"
  402. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  403. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  404. fi
  405. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  406. if ! grep -q ${option} mailcow.conf; then
  407. echo "Adding new option \"${option}\" to mailcow.conf"
  408. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  409. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  410. fi
  411. elif [[ ${option} == "SQL_PORT" ]]; then
  412. if ! grep -q ${option} mailcow.conf; then
  413. echo "Adding new option \"${option}\" to mailcow.conf"
  414. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  415. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  416. fi
  417. elif [[ ${option} == "API_KEY" ]]; then
  418. if ! grep -q ${option} mailcow.conf; then
  419. echo "Adding new option \"${option}\" to mailcow.conf"
  420. echo '# Create or override API key for web UI' >> mailcow.conf
  421. echo "#API_KEY=" >> mailcow.conf
  422. fi
  423. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  424. if ! grep -q ${option} mailcow.conf; then
  425. echo "Adding new option \"${option}\" to mailcow.conf"
  426. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  427. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  428. fi
  429. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  430. if ! grep -q ${option} mailcow.conf; then
  431. echo "Adding new option \"${option}\" to mailcow.conf"
  432. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  433. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  434. echo "#API_ALLOW_FROM=" >> mailcow.conf
  435. fi
  436. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  437. if ! grep -q ${option} mailcow.conf; then
  438. echo "Adding new option \"${option}\" to mailcow.conf"
  439. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  440. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  441. fi
  442. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  443. if ! grep -q ${option} mailcow.conf; then
  444. echo "Adding new option \"${option}\" to mailcow.conf"
  445. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  446. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  447. fi
  448. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  449. if ! grep -q ${option} mailcow.conf; then
  450. echo "Adding new option \"${option}\" to mailcow.conf"
  451. echo '# Garbage collector cleanup' >> mailcow.conf
  452. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  453. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  454. echo '# Check interval is hourly' >> mailcow.conf
  455. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  456. fi
  457. elif [[ ${option} == "ACL_ANYONE" ]]; then
  458. if ! grep -q ${option} mailcow.conf; then
  459. echo "Adding new option \"${option}\" to mailcow.conf"
  460. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  461. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  462. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  463. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  464. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  465. fi
  466. elif [[ ${option} == "SOLR_HEAP" ]]; then
  467. if ! grep -q ${option} mailcow.conf; then
  468. echo "Adding new option \"${option}\" to mailcow.conf"
  469. echo '# Solr heap size, there is no recommendation, please see Solr docs.' >> mailcow.conf
  470. echo '# Solr is a prone to run OOM on large systems and should be monitored. Unmonitored Solr setups are not recommended.' >> mailcow.conf
  471. echo '# Solr will refuse to start with total system memory below or equal to 2 GB.' >> mailcow.conf
  472. echo "SOLR_HEAP=1024" >> mailcow.conf
  473. fi
  474. elif [[ ${option} == "SKIP_SOLR" ]]; then
  475. if ! grep -q ${option} mailcow.conf; then
  476. echo "Adding new option \"${option}\" to mailcow.conf"
  477. echo '# Solr is disabled by default after upgrading from non-Solr to Solr-enabled mailcows.' >> mailcow.conf
  478. echo '# Disable Solr or if you do not want to store a readable index of your mails in solr-vol-1.' >> mailcow.conf
  479. echo "SKIP_SOLR=y" >> mailcow.conf
  480. fi
  481. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  482. if ! grep -q ${option} mailcow.conf; then
  483. echo "Adding new option \"${option}\" to mailcow.conf"
  484. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  485. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  486. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  487. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  488. fi
  489. elif [[ ${option} == "SKIP_SOGO" ]]; then
  490. if ! grep -q ${option} mailcow.conf; then
  491. echo "Adding new option \"${option}\" to mailcow.conf"
  492. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  493. echo "SKIP_SOGO=n" >> mailcow.conf
  494. fi
  495. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  496. if ! grep -q ${option} mailcow.conf; then
  497. echo "Adding new option \"${option}\" to mailcow.conf"
  498. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  499. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  500. echo "MAILDIR_SUB=" >> mailcow.conf
  501. fi
  502. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  503. if ! grep -q ${option} mailcow.conf; then
  504. echo "Adding new option \"${option}\" to mailcow.conf"
  505. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  506. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  507. fi
  508. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  509. if ! grep -q ${option} mailcow.conf; then
  510. echo "Adding new option \"${option}\" to mailcow.conf"
  511. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  512. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  513. fi
  514. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  515. if ! grep -q ${option} mailcow.conf; then
  516. echo "Adding new option \"${option}\" to mailcow.conf"
  517. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  518. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  519. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  520. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  521. fi
  522. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  523. if ! grep -q ${option} mailcow.conf; then
  524. echo "Adding new option \"${option}\" to mailcow.conf"
  525. echo '# SOGo session timeout in minutes' >> mailcow.conf
  526. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  527. fi
  528. elif [[ ${option} == "REDIS_PORT" ]]; then
  529. if ! grep -q ${option} mailcow.conf; then
  530. echo "Adding new option \"${option}\" to mailcow.conf"
  531. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  532. fi
  533. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  534. if ! grep -q ${option} mailcow.conf; then
  535. echo "Adding new option \"${option}\" to mailcow.conf"
  536. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  537. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  538. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  539. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  540. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  541. fi
  542. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  543. if ! grep -q ${option} mailcow.conf; then
  544. echo "Adding new option \"${option}\" to mailcow.conf"
  545. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  546. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  547. fi
  548. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  549. if ! grep -q ${option} mailcow.conf; then
  550. echo "Adding new option \"${option}\" to mailcow.conf"
  551. echo '# Password hash algorithm' >> mailcow.conf
  552. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  553. echo '# see https://mailcow.github.io/mailcow-dockerized-docs/models/model-passwd/' >> mailcow.conf
  554. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  555. fi
  556. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  557. if ! grep -q ${option} mailcow.conf; then
  558. echo '# Additional server names for mailcow UI' >> mailcow.conf
  559. echo '#' >> mailcow.conf
  560. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  561. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  562. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  563. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  564. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  565. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  566. fi
  567. elif [[ ${option} == "ACME_CONTACT" ]]; then
  568. if ! grep -q ${option} mailcow.conf; then
  569. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  570. echo '# Optional: Leave empty for none' >> mailcow.conf
  571. echo '# This value is only used on first order!' >> mailcow.conf
  572. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  573. echo '# https://mailcow.github.io/mailcow-dockerized-docs/troubleshooting/debug-reset_tls/' >> mailcow.conf
  574. echo 'ACME_CONTACT=' >> mailcow.conf
  575. fi
  576. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  577. if ! grep -q ${option} mailcow.conf; then
  578. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  579. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  580. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  581. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  582. fi
  583. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  584. if ! grep -q ${option} mailcow.conf; then
  585. echo '# Enable watchdog verbose logging' >> mailcow.conf
  586. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  587. fi
  588. elif ! grep -q ${option} mailcow.conf; then
  589. echo "Adding new option \"${option}\" to mailcow.conf"
  590. echo "${option}=n" >> mailcow.conf
  591. fi
  592. done
  593. if [[( ${SKIP_PING_CHECK} == "y")]]; then
  594. echo -e "\e[32mSkipping Ping Check...\e[0m"
  595. else
  596. echo -en "Checking internet connection... "
  597. if ! check_online_status; then
  598. echo -e "\e[31mfailed\e[0m"
  599. exit 1
  600. else
  601. echo -e "\e[32mOK\e[0m"
  602. fi
  603. fi
  604. echo -e "\e[32mChecking for newer update script...\e[0m"
  605. SHA1_1=$(sha1sum update.sh)
  606. git fetch origin #${BRANCH}
  607. git checkout origin/${BRANCH} update.sh
  608. SHA1_2=$(sha1sum update.sh)
  609. if [[ ${SHA1_1} != ${SHA1_2} ]]; then
  610. echo "update.sh changed, please run this script again, exiting."
  611. chmod +x update.sh
  612. exit 2
  613. fi
  614. if [[ -f mailcow.conf ]]; then
  615. source mailcow.conf
  616. else
  617. echo -e "\e[31mNo mailcow.conf - is mailcow installed?\e[0m"
  618. exit 1
  619. fi
  620. if [ ! $FORCE ]; then
  621. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  622. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  623. echo "OK, exiting."
  624. exit 0
  625. fi
  626. migrate_docker_nat
  627. fi
  628. update_compose
  629. remove_obsolete_nginx_ports
  630. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  631. sed -i 's/HTTPS_BIND:-:/HTTPS_BIND:-/g' docker-compose.yml
  632. sed -i 's/HTTP_BIND:-:/HTTP_BIND:-/g' docker-compose.yml
  633. if ! docker-compose config -q; then
  634. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  635. exit 1
  636. fi
  637. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  638. MAILCOW_BRIDGE=$(docker-compose config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  639. while read NAT_ID; do
  640. iptables -t nat -D POSTROUTING $NAT_ID
  641. done < <(iptables -L -vn -t nat --line-numbers | grep $IPV4_NETWORK | grep -E 'MASQUERADE.*all' | grep -v ${MAILCOW_BRIDGE} | cut -d' ' -f1)
  642. DIFF_DIRECTORY=update_diffs
  643. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  644. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  645. if ! git diff-index --quiet HEAD; then
  646. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  647. mkdir -p ${DIFF_DIRECTORY}
  648. git diff --stat > ${DIFF_FILE}
  649. git diff >> ${DIFF_FILE}
  650. fi
  651. echo -e "\e[32mPrefetching images...\e[0m"
  652. prefetch_images
  653. echo -e "\e[32mStopping mailcow...\e[0m"
  654. sleep 2
  655. MAILCOW_CONTAINERS=($(docker-compose ps -q))
  656. docker-compose down
  657. echo -e "\e[32mChecking for remaining containers...\e[0m"
  658. sleep 2
  659. for container in "${MAILCOW_CONTAINERS[@]}"; do
  660. docker rm -f "$container" 2> /dev/null
  661. done
  662. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  663. # Silently fixing remote url from andryyy to mailcow
  664. git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  665. echo -e "\e[32mCommitting current status...\e[0m"
  666. [[ -z "$(git config user.name)" ]] && git config user.name moo
  667. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  668. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  669. git add -u
  670. git commit -am "Before update on ${DATE}" > /dev/null
  671. echo -e "\e[32mFetching updated code from remote...\e[0m"
  672. git fetch origin #${BRANCH}
  673. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  674. git config merge.defaultToUpstream true
  675. git merge -X${MERGE_STRATEGY:-theirs} -Xpatience -m "After update on ${DATE}"
  676. # Need to use a variable to not pass return codes of if checks
  677. MERGE_RETURN=$?
  678. if [[ ${MERGE_RETURN} == 128 ]]; then
  679. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  680. exit 1
  681. elif [[ ${MERGE_RETURN} == 1 ]]; then
  682. echo -e "\e[93mPotenial conflict, trying to fix...\e[0m"
  683. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  684. git add -A
  685. git commit -m "After update on ${DATE}" > /dev/null
  686. git checkout .
  687. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  688. elif [[ ${MERGE_RETURN} != 0 ]]; then
  689. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  690. echo
  691. echo "Run docker-compose up -d to restart your stack without updates or try again after fixing the mentioned errors."
  692. exit 1
  693. fi
  694. echo -e "\e[32mFetching new images, if any...\e[0m"
  695. sleep 2
  696. docker-compose pull
  697. # Fix missing SSL, does not overwrite existing files
  698. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  699. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  700. echo -e "Checking IPv6 settings... "
  701. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  702. echo
  703. echo '!! IMPORTANT !!'
  704. echo
  705. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  706. echo 'This setting will only be active after a complete shutdown of mailcow by running "docker-compose down" followed by "docker-compose up -d".'
  707. echo
  708. echo '!! IMPORTANT !!'
  709. echo
  710. read -p "Press any key to continue..." < /dev/tty
  711. fi
  712. # Checking for old project name bug
  713. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  714. # Fix Rspamd maps
  715. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  716. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  717. fi
  718. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  719. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  720. fi
  721. # Fix deprecated metrics.conf
  722. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  723. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  724. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  725. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  726. fi
  727. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  728. fi
  729. # Set app_info.inc.php
  730. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  731. if [ $? -eq 0 ]; then
  732. echo '<?php' > data/web/inc/app_info.inc.php
  733. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  734. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  735. echo '?>' >> data/web/inc/app_info.inc.php
  736. else
  737. echo '<?php' > data/web/inc/app_info.inc.php
  738. echo ' $MAILCOW_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  739. echo ' $MAILCOW_GIT_URL="";' >> data/web/inc/app_info.inc.php
  740. echo '?>' >> data/web/inc/app_info.inc.php
  741. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  742. fi
  743. if [[ ${SKIP_START} == "y" ]]; then
  744. echo -e "\e[33mNot starting mailcow, please run \"docker-compose up -d --remove-orphans\" to start mailcow.\e[0m"
  745. else
  746. echo -e "\e[32mStarting mailcow...\e[0m"
  747. sleep 2
  748. docker-compose up -d --remove-orphans
  749. fi
  750. echo -e "\e[32mCollecting garbage...\e[0m"
  751. docker_garbage
  752. # Run post-update-hook
  753. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  754. bash "${SCRIPT_DIR}/post_update_hook.sh"
  755. fi
  756. # echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  757. # echo
  758. # git reflog --color=always | grep "Before update on "
  759. # echo
  760. # echo "Use \"git reset --hard hash-on-the-left\" and run docker-compose up -d afterwards."