update.sh 50 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104
  1. #!/usr/bin/env bash
  2. ############## Begin Function Section ##############
  3. check_online_status() {
  4. CHECK_ONLINE_DOMAINS=('https://github.com' 'https://hub.docker.com')
  5. for domain in "${CHECK_ONLINE_DOMAINS[@]}"; do
  6. if timeout 6 curl --head --silent --output /dev/null ${domain}; then
  7. return 0
  8. fi
  9. done
  10. return 1
  11. }
  12. prefetch_images() {
  13. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  14. git fetch origin #${BRANCH}
  15. while read image; do
  16. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  17. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  18. continue
  19. fi
  20. fi
  21. RET_C=0
  22. until docker pull ${image}; do
  23. RET_C=$((RET_C + 1))
  24. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  25. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  26. sleep 1
  27. done
  28. done < <(git show origin/${BRANCH}:docker-compose.yml | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  29. }
  30. docker_garbage() {
  31. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  32. IMGS_TO_DELETE=()
  33. declare -A IMAGES_INFO
  34. COMPOSE_IMAGES=($(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"))
  35. for existing_image in $(docker images --format "{{.ID}}:{{.Repository}}:{{.Tag}}" | grep 'mailcow/'); do
  36. ID=$(echo $existing_image | cut -d ':' -f 1)
  37. REPOSITORY=$(echo $existing_image | cut -d ':' -f 2)
  38. TAG=$(echo $existing_image | cut -d ':' -f 3)
  39. if [[ " ${COMPOSE_IMAGES[@]} " =~ " ${REPOSITORY}:${TAG} " ]]; then
  40. continue
  41. else
  42. IMGS_TO_DELETE+=("$ID")
  43. IMAGES_INFO["$ID"]="$REPOSITORY:$TAG"
  44. fi
  45. done
  46. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  47. echo "The following unused mailcow images were found:"
  48. for id in "${IMGS_TO_DELETE[@]}"; do
  49. echo " ${IMAGES_INFO[$id]} ($id)"
  50. done
  51. if [ ! $FORCE ]; then
  52. read -r -p "Do you want to delete them to free up some space? [y/N] " response
  53. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  54. docker rmi ${IMGS_TO_DELETE[*]}
  55. else
  56. echo "OK, skipped."
  57. fi
  58. else
  59. echo "Running in forced mode! Force removing old mailcow images..."
  60. docker rmi ${IMGS_TO_DELETE[*]}
  61. fi
  62. echo -e "\e[32mFurther cleanup...\e[0m"
  63. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  64. fi
  65. }
  66. in_array() {
  67. local e match="$1"
  68. shift
  69. for e; do [[ "$e" == "$match" ]] && return 0; done
  70. return 1
  71. }
  72. migrate_docker_nat() {
  73. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  74. # Min Docker version
  75. DOCKERV_REQ=20.10.2
  76. # Current Docker version
  77. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  78. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  79. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  80. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  81. echo '!!! This step is recommended !!!'
  82. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  83. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  84. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  85. echo "OK, skipping this step."
  86. return 0
  87. fi
  88. fi
  89. # Sort versions and check if we are running a newer or equal version to req
  90. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  91. # If Dockerd daemon json exists
  92. if [ -s /etc/docker/daemon.json ]; then
  93. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  94. if ! in_array ipv6true "${dockerconfig[@]}" || \
  95. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  96. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  97. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  98. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  99. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  100. echo -e "Please merge the following content and restart the Docker daemon:\n"
  101. echo ${NAT_CONFIG}
  102. return 1
  103. fi
  104. else
  105. echo "Working on IPv6 NAT, please wait..."
  106. echo ${NAT_CONFIG} > /etc/docker/daemon.json
  107. ip6tables -F -t nat
  108. [[ -e /etc/rc.conf ]] && rc-service docker restart || systemctl restart docker.service
  109. if [[ $? -ne 0 ]]; then
  110. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  111. rm /etc/docker/daemon.json
  112. if [[ -e /etc/rc.conf ]]; then
  113. rc-service docker restart
  114. else
  115. systemctl reset-failed docker.service
  116. systemctl restart docker.service
  117. fi
  118. return 1
  119. fi
  120. fi
  121. # Removing legacy container
  122. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  123. if [ -s docker-compose.override.yml ]; then
  124. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  125. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  126. mv docker-compose.override.yml docker-compose.override.yml_backup
  127. fi
  128. fi
  129. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  130. else
  131. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  132. return 0
  133. fi
  134. }
  135. remove_obsolete_nginx_ports() {
  136. # Removing obsolete docker-compose.override.yml
  137. for override in docker-compose.override.yml docker-compose.override.yaml; do
  138. if [ -s $override ] ; then
  139. if cat $override | grep nginx-mailcow > /dev/null 2>&1; then
  140. if cat $override | grep -E '(\[::])' > /dev/null 2>&1; then
  141. if cat $override | grep -w 80:80 > /dev/null 2>&1 && cat $override | grep -w 443:443 > /dev/null 2>&1 ; then
  142. echo -e "\e[33mBacking up ${override} to preserve custom changes...\e[0m"
  143. echo -e "\e[33m!!! Manual Merge needed (if other overrides are set) !!!\e[0m"
  144. sleep 3
  145. cp $override ${override}_backup
  146. sed -i '/nginx-mailcow:$/,/^$/d' $override
  147. echo -e "\e[33mRemoved obsolete NGINX IPv6 Bind from original override File.\e[0m"
  148. if [[ "$(cat $override | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  149. mv $override ${override}_empty
  150. echo -e "\e[31m${override} is empty. Renamed it to ensure mailcow is startable.\e[0m"
  151. fi
  152. fi
  153. fi
  154. fi
  155. fi
  156. done
  157. }
  158. detect_docker_compose_command(){
  159. if ! [[ "${DOCKER_COMPOSE_VERSION}" =~ ^(native|standalone)$ ]]; then
  160. if docker compose > /dev/null 2>&1; then
  161. if docker compose version --short | grep -e "^2." -e "^v2." > /dev/null 2>&1; then
  162. DOCKER_COMPOSE_VERSION=native
  163. COMPOSE_COMMAND="docker compose"
  164. echo -e "\e[33mFound Docker Compose Plugin (native).\e[0m"
  165. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  166. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' $SCRIPT_DIR/mailcow.conf
  167. sleep 2
  168. echo -e "\e[33mNotice: You'll have to update this Compose Version via your Package Manager manually!\e[0m"
  169. else
  170. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  171. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  172. exit 1
  173. fi
  174. elif docker-compose > /dev/null 2>&1; then
  175. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  176. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  177. DOCKER_COMPOSE_VERSION=standalone
  178. COMPOSE_COMMAND="docker-compose"
  179. echo -e "\e[33mFound Docker Compose Standalone.\e[0m"
  180. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  181. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' $SCRIPT_DIR/mailcow.conf
  182. sleep 2
  183. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  184. else
  185. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  186. echo -e "\e[31mPlease update/install regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  187. exit 1
  188. fi
  189. fi
  190. else
  191. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  192. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  193. exit 1
  194. fi
  195. elif [ "${DOCKER_COMPOSE_VERSION}" == "native" ]; then
  196. COMPOSE_COMMAND="docker compose"
  197. # Check if Native Compose works and has not been deleted
  198. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  199. # IF it not exists/work anymore try the other command
  200. COMPOSE_COMMAND="docker-compose"
  201. if ! $COMPOSE_COMMAND > /dev/null 2>&1 || ! $COMPOSE_COMMAND --version | grep "^2." > /dev/null 2>&1; then
  202. # IF it cannot find Standalone in > 2.X, then script stops
  203. echo -e "\e[31mCannot find Docker Compose or the Version is lower then 2.X.X.\e[0m"
  204. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  205. exit 1
  206. fi
  207. # If it finds the standalone Plugin it will use this instead and change the mailcow.conf Variable accordingly
  208. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  209. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from native to standalone\e[0m"
  210. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' $SCRIPT_DIR/mailcow.conf
  211. sleep 2
  212. fi
  213. elif [ "${DOCKER_COMPOSE_VERSION}" == "standalone" ]; then
  214. COMPOSE_COMMAND="docker-compose"
  215. # Check if Standalone Compose works and has not been deleted
  216. if ! $COMPOSE_COMMAND > /dev/null 2>&1 && ! $COMPOSE_COMMAND --version > /dev/null 2>&1 | grep "^2." > /dev/null 2>&1; then
  217. # IF it not exists/work anymore try the other command
  218. COMPOSE_COMMAND="docker compose"
  219. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  220. # IF it cannot find Native in > 2.X, then script stops
  221. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  222. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  223. exit 1
  224. fi
  225. # If it finds the native Plugin it will use this instead and change the mailcow.conf Variable accordingly
  226. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  227. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from standalone to native\e[0m"
  228. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' $SCRIPT_DIR/mailcow.conf
  229. sleep 2
  230. fi
  231. fi
  232. }
  233. detect_bad_asn() {
  234. echo -e "\e[33mDetecting if your IP is listed on Spamhaus Bad ASN List...\e[0m"
  235. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  236. if [ "$response" -eq 503 ]; then
  237. if [ -z "$SPAMHAUS_DQS_KEY" ]; then
  238. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  239. echo -e "\e[33mmailcow did not detected a value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf!\e[0m"
  240. sleep 2
  241. echo ""
  242. echo -e "\e[33mTo use the Spamhaus DNS Blocklists again, you will need to create a FREE account for their Data Query Service (DQS) at: https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account\e[0m"
  243. echo -e "\e[33mOnce done, enter your DQS API key in mailcow.conf and mailcow will do the rest for you!\e[0m"
  244. echo ""
  245. sleep 2
  246. else
  247. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  248. echo -e "\e[32mmailcow detected a Value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf. Postfix will use DQS with the given API key...\e[0m"
  249. fi
  250. elif [ "$response" -eq 200 ]; then
  251. echo -e "\e[33mCheck completed! Your IP is \e[32mclean\e[0m"
  252. elif [ "$response" -eq 429 ]; then
  253. echo -e "\e[33mCheck completed! \e[31mYour IP seems to be rate limited on the ASN Check service... please try again later!\e[0m"
  254. else
  255. echo -e "\e[31mCheck failed! \e[0mMaybe a DNS or Network problem?\e[0m"
  256. fi
  257. }
  258. ############## End Function Section ##############
  259. # Check permissions
  260. if [ "$(id -u)" -ne "0" ]; then
  261. echo "You need to be root"
  262. exit 1
  263. fi
  264. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  265. # Run pre-update-hook
  266. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  267. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  268. fi
  269. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  270. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  271. echo "Please update to 5.x or use another distribution."
  272. exit 1
  273. fi
  274. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  275. if grep -q Ubuntu <<< $(uname -a); then
  276. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  277. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  278. exit 1
  279. fi
  280. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  281. read -p "Press any key to continue..." < /dev/tty
  282. fi
  283. # Exit on error and pipefail
  284. set -o pipefail
  285. # Setting high dc timeout
  286. export COMPOSE_HTTP_TIMEOUT=600
  287. # Add /opt/bin to PATH
  288. PATH=$PATH:/opt/bin
  289. umask 0022
  290. # Unset COMPOSE_COMMAND and DOCKER_COMPOSE_VERSION Variable to be on the newest state.
  291. unset COMPOSE_COMMAND
  292. unset DOCKER_COMPOSE_VERSION
  293. for bin in curl docker git awk sha1sum grep cut; do
  294. if [[ -z $(command -v ${bin}) ]]; then
  295. echo "Cannot find ${bin}, exiting..."
  296. exit 1;
  297. fi
  298. done
  299. # Check Docker Version (need at least 24.X)
  300. docker_version=$(docker -v | grep -oP '\d+\.\d+\.\d+' | cut -d '.' -f 1)
  301. if [[ $docker_version -lt 24 ]]; then
  302. echo -e "\e[31mCannot find Docker with a Version higher or equals 24.0.0\e[0m"
  303. echo -e "\e[33mmailcow needs a newer Docker version to work properly... continuing on your own risk!\e[0m"
  304. echo -e "\e[31mPlease update your Docker installation... sleeping 10s\e[0m"
  305. sleep 10
  306. fi
  307. export LC_ALL=C
  308. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  309. BRANCH=$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)
  310. while (($#)); do
  311. case "${1}" in
  312. --check|-c)
  313. echo "Checking remote code for updates..."
  314. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized ${BRANCH} | cut -f1)
  315. if [ $? -ne 0 ]; then
  316. echo "A problem occurred while trying to fetch the latest revision from github."
  317. exit 99
  318. fi
  319. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  320. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  321. git log --date=short --pretty=format:"%ad - %s" $(git rev-parse --short HEAD)..origin/master
  322. exit 0
  323. else
  324. echo "No updates available."
  325. exit 3
  326. fi
  327. ;;
  328. --ours)
  329. MERGE_STRATEGY=ours
  330. ;;
  331. --skip-start)
  332. SKIP_START=y
  333. ;;
  334. --skip-ping-check)
  335. SKIP_PING_CHECK=y
  336. ;;
  337. --stable)
  338. CURRENT_BRANCH="$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)"
  339. NEW_BRANCH="master"
  340. ;;
  341. --gc)
  342. echo -e "\e[32mCollecting garbage...\e[0m"
  343. docker_garbage
  344. exit 0
  345. ;;
  346. --nightly)
  347. CURRENT_BRANCH="$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)"
  348. NEW_BRANCH="nightly"
  349. ;;
  350. --prefetch)
  351. echo -e "\e[32mPrefetching images...\e[0m"
  352. prefetch_images
  353. exit 0
  354. ;;
  355. -f|--force)
  356. echo -e "\e[32mRunning in forced mode...\e[0m"
  357. FORCE=y
  358. ;;
  359. -d|--dev)
  360. echo -e "\e[32mRunning in Developer mode...\e[0m"
  361. DEV=y
  362. ;;
  363. --help|-h)
  364. echo './update.sh [-c|--check, --ours, --gc, --nightly, --prefetch, --skip-start, --skip-ping-check, --stable, -f|--force, -d|--dev, -h|--help]
  365. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  366. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  367. --gc - Run garbage collector to delete old image tags
  368. --nightly - Switch your mailcow updates to the unstable (nightly) branch. FOR TESTING PURPOSES ONLY!!!!
  369. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  370. --skip-start - Do not start mailcow after update
  371. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you´ve blocked any ICMP Connections to your mailcow machine)
  372. --stable - Switch your mailcow updates to the stable (master) branch. Default unless you changed it with --nightly.
  373. -f|--force - Force update, do not ask questions
  374. -d|--dev - Enables Developer Mode (No Checkout of update.sh for tests)
  375. '
  376. exit 1
  377. esac
  378. shift
  379. done
  380. [[ ! -f mailcow.conf ]] && { echo -e "\e[31mmailcow.conf is missing! Is mailcow installed?\e[0m"; exit 1;}
  381. chmod 600 mailcow.conf
  382. source mailcow.conf
  383. detect_docker_compose_command
  384. DOTS=${MAILCOW_HOSTNAME//[^.]};
  385. if [ ${#DOTS} -lt 1 ]; then
  386. echo -e "\e[31mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!\e[0m"
  387. sleep 1
  388. echo "Please change it to a FQDN and redeploy the stack with $COMPOSE_COMMAND up -d"
  389. exit 1
  390. elif [[ "${MAILCOW_HOSTNAME: -1}" == "." ]]; then
  391. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is ending with a dot. This is not a valid FQDN!"
  392. exit 1
  393. elif [ ${#DOTS} -eq 1 ]; then
  394. echo -e "\e[33mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) does not contain a Subdomain. This is not fully tested and may cause issues.\e[0m"
  395. echo "Find more information about why this message exists here: https://github.com/mailcow/mailcow-dockerized/issues/1572"
  396. read -r -p "Do you want to proceed anyway? [y/N] " response
  397. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  398. echo "OK. Proceeding."
  399. else
  400. echo "OK. Exiting."
  401. exit 1
  402. fi
  403. fi
  404. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  405. # This will also cover sort
  406. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  407. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  408. CONFIG_ARRAY=(
  409. "SKIP_LETS_ENCRYPT"
  410. "SKIP_SOGO"
  411. "USE_WATCHDOG"
  412. "WATCHDOG_NOTIFY_EMAIL"
  413. "WATCHDOG_NOTIFY_WEBHOOK"
  414. "WATCHDOG_NOTIFY_WEBHOOK_BODY"
  415. "WATCHDOG_NOTIFY_BAN"
  416. "WATCHDOG_NOTIFY_START"
  417. "WATCHDOG_EXTERNAL_CHECKS"
  418. "WATCHDOG_SUBJECT"
  419. "SKIP_CLAMD"
  420. "SKIP_IP_CHECK"
  421. "ADDITIONAL_SAN"
  422. "AUTODISCOVER_SAN"
  423. "DOVEADM_PORT"
  424. "IPV4_NETWORK"
  425. "IPV6_NETWORK"
  426. "LOG_LINES"
  427. "SNAT_TO_SOURCE"
  428. "SNAT6_TO_SOURCE"
  429. "COMPOSE_PROJECT_NAME"
  430. "DOCKER_COMPOSE_VERSION"
  431. "SQL_PORT"
  432. "API_KEY"
  433. "API_KEY_READ_ONLY"
  434. "API_ALLOW_FROM"
  435. "MAILDIR_GC_TIME"
  436. "MAILDIR_SUB"
  437. "ACL_ANYONE"
  438. "SOLR_HEAP"
  439. "SKIP_SOLR"
  440. "ENABLE_SSL_SNI"
  441. "ALLOW_ADMIN_EMAIL_LOGIN"
  442. "SKIP_HTTP_VERIFICATION"
  443. "SOGO_EXPIRE_SESSION"
  444. "REDIS_PORT"
  445. "DOVECOT_MASTER_USER"
  446. "DOVECOT_MASTER_PASS"
  447. "MAILCOW_PASS_SCHEME"
  448. "ADDITIONAL_SERVER_NAMES"
  449. "ACME_CONTACT"
  450. "WATCHDOG_VERBOSE"
  451. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  452. "SPAMHAUS_DQS_KEY"
  453. "SKIP_UNBOUND_HEALTHCHECK"
  454. "DISABLE_NETFILTER_ISOLATION_RULE"
  455. )
  456. detect_bad_asn
  457. sed -i --follow-symlinks '$a\' mailcow.conf
  458. for option in ${CONFIG_ARRAY[@]}; do
  459. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  460. if ! grep -q ${option} mailcow.conf; then
  461. echo "Adding new option \"${option}\" to mailcow.conf"
  462. echo "${option}=" >> mailcow.conf
  463. fi
  464. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  465. if ! grep -q ${option} mailcow.conf; then
  466. echo "Adding new option \"${option}\" to mailcow.conf"
  467. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  468. fi
  469. elif [[ ${option} == "DOCKER_COMPOSE_VERSION" ]]; then
  470. if ! grep -q ${option} mailcow.conf; then
  471. echo "Adding new option \"${option}\" to mailcow.conf"
  472. echo "# Used Docker Compose version" >> mailcow.conf
  473. echo "# Switch here between native (compose plugin) and standalone" >> mailcow.conf
  474. echo "# For more informations take a look at the mailcow docs regarding the configuration options." >> mailcow.conf
  475. echo "# Normally this should be untouched but if you decided to use either of those you can switch it manually here." >> mailcow.conf
  476. echo "# Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail." >> mailcow.conf
  477. echo "" >> mailcow.conf
  478. echo "DOCKER_COMPOSE_VERSION=${DOCKER_COMPOSE_VERSION}" >> mailcow.conf
  479. fi
  480. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  481. if ! grep -q ${option} mailcow.conf; then
  482. echo "Adding new option \"${option}\" to mailcow.conf"
  483. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  484. fi
  485. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  486. if ! grep -q ${option} mailcow.conf; then
  487. echo "Adding new option \"${option}\" to mailcow.conf"
  488. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  489. fi
  490. elif [[ ${option} == "LOG_LINES" ]]; then
  491. if ! grep -q ${option} mailcow.conf; then
  492. echo "Adding new option \"${option}\" to mailcow.conf"
  493. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  494. echo "LOG_LINES=9999" >> mailcow.conf
  495. fi
  496. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  497. if ! grep -q ${option} mailcow.conf; then
  498. echo "Adding new option \"${option}\" to mailcow.conf"
  499. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  500. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  501. fi
  502. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  503. if ! grep -q ${option} mailcow.conf; then
  504. echo "Adding new option \"${option}\" to mailcow.conf"
  505. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  506. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  507. fi
  508. elif [[ ${option} == "SQL_PORT" ]]; then
  509. if ! grep -q ${option} mailcow.conf; then
  510. echo "Adding new option \"${option}\" to mailcow.conf"
  511. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  512. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  513. fi
  514. elif [[ ${option} == "API_KEY" ]]; then
  515. if ! grep -q ${option} mailcow.conf; then
  516. echo "Adding new option \"${option}\" to mailcow.conf"
  517. echo '# Create or override API key for web UI' >> mailcow.conf
  518. echo "#API_KEY=" >> mailcow.conf
  519. fi
  520. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  521. if ! grep -q ${option} mailcow.conf; then
  522. echo "Adding new option \"${option}\" to mailcow.conf"
  523. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  524. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  525. fi
  526. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  527. if ! grep -q ${option} mailcow.conf; then
  528. echo "Adding new option \"${option}\" to mailcow.conf"
  529. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  530. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  531. echo "#API_ALLOW_FROM=" >> mailcow.conf
  532. fi
  533. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  534. if ! grep -q ${option} mailcow.conf; then
  535. echo "Adding new option \"${option}\" to mailcow.conf"
  536. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  537. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  538. fi
  539. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  540. if ! grep -q ${option} mailcow.conf; then
  541. echo "Adding new option \"${option}\" to mailcow.conf"
  542. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  543. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  544. fi
  545. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  546. if ! grep -q ${option} mailcow.conf; then
  547. echo "Adding new option \"${option}\" to mailcow.conf"
  548. echo '# Garbage collector cleanup' >> mailcow.conf
  549. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  550. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  551. echo '# Check interval is hourly' >> mailcow.conf
  552. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  553. fi
  554. elif [[ ${option} == "ACL_ANYONE" ]]; then
  555. if ! grep -q ${option} mailcow.conf; then
  556. echo "Adding new option \"${option}\" to mailcow.conf"
  557. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  558. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  559. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  560. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  561. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  562. fi
  563. elif [[ ${option} == "SOLR_HEAP" ]]; then
  564. if ! grep -q ${option} mailcow.conf; then
  565. echo "Adding new option \"${option}\" to mailcow.conf"
  566. echo '# Solr heap size, there is no recommendation, please see Solr docs.' >> mailcow.conf
  567. echo '# Solr is a prone to run OOM on large systems and should be monitored. Unmonitored Solr setups are not recommended.' >> mailcow.conf
  568. echo '# Solr will refuse to start with total system memory below or equal to 2 GB.' >> mailcow.conf
  569. echo "SOLR_HEAP=1024" >> mailcow.conf
  570. fi
  571. elif [[ ${option} == "SKIP_SOLR" ]]; then
  572. if ! grep -q ${option} mailcow.conf; then
  573. echo "Adding new option \"${option}\" to mailcow.conf"
  574. echo '# Solr is disabled by default after upgrading from non-Solr to Solr-enabled mailcows.' >> mailcow.conf
  575. echo '# Disable Solr or if you do not want to store a readable index of your mails in solr-vol-1.' >> mailcow.conf
  576. echo "SKIP_SOLR=y" >> mailcow.conf
  577. fi
  578. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  579. if ! grep -q ${option} mailcow.conf; then
  580. echo "Adding new option \"${option}\" to mailcow.conf"
  581. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  582. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  583. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  584. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  585. fi
  586. elif [[ ${option} == "SKIP_SOGO" ]]; then
  587. if ! grep -q ${option} mailcow.conf; then
  588. echo "Adding new option \"${option}\" to mailcow.conf"
  589. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  590. echo "SKIP_SOGO=n" >> mailcow.conf
  591. fi
  592. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  593. if ! grep -q ${option} mailcow.conf; then
  594. echo "Adding new option \"${option}\" to mailcow.conf"
  595. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  596. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  597. echo "MAILDIR_SUB=" >> mailcow.conf
  598. fi
  599. elif [[ ${option} == "WATCHDOG_NOTIFY_WEBHOOK" ]]; then
  600. if ! grep -q ${option} mailcow.conf; then
  601. echo "Adding new option \"${option}\" to mailcow.conf"
  602. echo '# Send notifications to a webhook URL that receives a POST request with the content type "application/json".' >> mailcow.conf
  603. echo '# You can use this to send notifications to services like Discord, Slack and others.' >> mailcow.conf
  604. echo '#WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX' >> mailcow.conf
  605. fi
  606. elif [[ ${option} == "WATCHDOG_NOTIFY_WEBHOOK_BODY" ]]; then
  607. if ! grep -q ${option} mailcow.conf; then
  608. echo "Adding new option \"${option}\" to mailcow.conf"
  609. echo '# JSON body included in the webhook POST request. Needs to be in single quotes.' >> mailcow.conf
  610. echo '# Following variables are available: SUBJECT, BODY' >> mailcow.conf
  611. WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  612. echo "#WATCHDOG_NOTIFY_WEBHOOK_BODY='${WEBHOOK_BODY}'" >> mailcow.conf
  613. fi
  614. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  615. if ! grep -q ${option} mailcow.conf; then
  616. echo "Adding new option \"${option}\" to mailcow.conf"
  617. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  618. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  619. fi
  620. elif [[ ${option} == "WATCHDOG_NOTIFY_START" ]]; then
  621. if ! grep -q ${option} mailcow.conf; then
  622. echo "Adding new option \"${option}\" to mailcow.conf"
  623. echo '# Send a notification when the watchdog is started.' >> mailcow.conf
  624. echo "WATCHDOG_NOTIFY_START=y" >> mailcow.conf
  625. fi
  626. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  627. if ! grep -q ${option} mailcow.conf; then
  628. echo "Adding new option \"${option}\" to mailcow.conf"
  629. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  630. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  631. fi
  632. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  633. if ! grep -q ${option} mailcow.conf; then
  634. echo "Adding new option \"${option}\" to mailcow.conf"
  635. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  636. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  637. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  638. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  639. fi
  640. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  641. if ! grep -q ${option} mailcow.conf; then
  642. echo "Adding new option \"${option}\" to mailcow.conf"
  643. echo '# SOGo session timeout in minutes' >> mailcow.conf
  644. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  645. fi
  646. elif [[ ${option} == "REDIS_PORT" ]]; then
  647. if ! grep -q ${option} mailcow.conf; then
  648. echo "Adding new option \"${option}\" to mailcow.conf"
  649. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  650. fi
  651. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  652. if ! grep -q ${option} mailcow.conf; then
  653. echo "Adding new option \"${option}\" to mailcow.conf"
  654. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  655. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  656. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  657. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  658. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  659. fi
  660. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  661. if ! grep -q ${option} mailcow.conf; then
  662. echo "Adding new option \"${option}\" to mailcow.conf"
  663. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  664. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  665. fi
  666. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  667. if ! grep -q ${option} mailcow.conf; then
  668. echo "Adding new option \"${option}\" to mailcow.conf"
  669. echo '# Password hash algorithm' >> mailcow.conf
  670. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  671. echo '# see https://docs.mailcow.email/models/model-passwd/' >> mailcow.conf
  672. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  673. fi
  674. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  675. if ! grep -q ${option} mailcow.conf; then
  676. echo "Adding new option \"${option}\" to mailcow.conf"
  677. echo '# Additional server names for mailcow UI' >> mailcow.conf
  678. echo '#' >> mailcow.conf
  679. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  680. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  681. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  682. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  683. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  684. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  685. fi
  686. elif [[ ${option} == "AUTODISCOVER_SAN" ]]; then
  687. if ! grep -q ${option} mailcow.conf; then
  688. echo "Adding new option \"${option}\" to mailcow.conf"
  689. echo '# Obtain certificates for autodiscover.* and autoconfig.* domains.' >> mailcow.conf
  690. echo '# This can be useful to switch off in case you are in a scenario where a reverse proxy already handles those.' >> mailcow.conf
  691. echo '# There are mixed scenarios where ports 80,443 are occupied and you do not want to share certs' >> mailcow.conf
  692. echo '# between services. So acme-mailcow obtains for maildomains and all web-things get handled' >> mailcow.conf
  693. echo '# in the reverse proxy.' >> mailcow.conf
  694. echo 'AUTODISCOVER_SAN=y' >> mailcow.conf
  695. fi
  696. elif [[ ${option} == "ACME_CONTACT" ]]; then
  697. if ! grep -q ${option} mailcow.conf; then
  698. echo "Adding new option \"${option}\" to mailcow.conf"
  699. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  700. echo '# Optional: Leave empty for none' >> mailcow.conf
  701. echo '# This value is only used on first order!' >> mailcow.conf
  702. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  703. echo '# https://docs.mailcow.email/troubleshooting/debug-reset_tls/' >> mailcow.conf
  704. echo 'ACME_CONTACT=' >> mailcow.conf
  705. fi
  706. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  707. if ! grep -q ${option} mailcow.conf; then
  708. echo "Adding new option \"${option}\" to mailcow.conf"
  709. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  710. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  711. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  712. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  713. fi
  714. elif [[ ${option} == "SPAMHAUS_DQS_KEY" ]]; then
  715. if ! grep -q ${option} mailcow.conf; then
  716. echo "Adding new option \"${option}\" to mailcow.conf"
  717. echo "# Spamhaus Data Query Service Key" >> mailcow.conf
  718. echo '# Optional: Leave empty for none' >> mailcow.conf
  719. echo '# Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.' >> mailcow.conf
  720. echo '# If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.' >> mailcow.conf
  721. echo '# Otherwise it will work as usual.' >> mailcow.conf
  722. echo 'SPAMHAUS_DQS_KEY=' >> mailcow.conf
  723. fi
  724. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  725. if ! grep -q ${option} mailcow.conf; then
  726. echo "Adding new option \"${option}\" to mailcow.conf"
  727. echo '# Enable watchdog verbose logging' >> mailcow.conf
  728. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  729. fi
  730. elif [[ ${option} == "SKIP_UNBOUND_HEALTHCHECK" ]]; then
  731. if ! grep -q ${option} mailcow.conf; then
  732. echo "Adding new option \"${option}\" to mailcow.conf"
  733. echo '# Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n' >> mailcow.conf
  734. echo 'SKIP_UNBOUND_HEALTHCHECK=n' >> mailcow.conf
  735. fi
  736. elif [[ ${option} == "DISABLE_NETFILTER_ISOLATION_RULE" ]]; then
  737. if ! grep -q ${option} mailcow.conf; then
  738. echo "Adding new option \"${option}\" to mailcow.conf"
  739. echo '# Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n' >> mailcow.conf
  740. echo '# CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost' >> mailcow.conf
  741. echo 'DISABLE_NETFILTER_ISOLATION_RULE=n' >> mailcow.conf
  742. fi
  743. elif ! grep -q ${option} mailcow.conf; then
  744. echo "Adding new option \"${option}\" to mailcow.conf"
  745. echo "${option}=n" >> mailcow.conf
  746. fi
  747. done
  748. if [[( ${SKIP_PING_CHECK} == "y")]]; then
  749. echo -e "\e[32mSkipping Ping Check...\e[0m"
  750. else
  751. echo -en "Checking internet connection... "
  752. if ! check_online_status; then
  753. echo -e "\e[31mfailed\e[0m"
  754. exit 1
  755. else
  756. echo -e "\e[32mOK\e[0m"
  757. fi
  758. fi
  759. if ! [ $NEW_BRANCH ]; then
  760. echo -e "\e[33mDetecting which build your mailcow runs on...\e[0m"
  761. sleep 1
  762. if [ ${BRANCH} == "master" ]; then
  763. echo -e "\e[32mYou are receiving stable updates (master).\e[0m"
  764. echo -e "\e[33mTo change that run the update.sh Script one time with the --nightly parameter to switch to nightly builds.\e[0m"
  765. elif [ ${BRANCH} == "nightly" ]; then
  766. echo -e "\e[31mYou are receiving unstable updates (nightly). These are for testing purposes only!!!\e[0m"
  767. sleep 1
  768. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  769. else
  770. echo -e "\e[33mYou are receiving updates from an unsupported branch.\e[0m"
  771. sleep 1
  772. echo -e "\e[33mThe mailcow stack might still work but it is recommended to switch to the master branch (stable builds).\e[0m"
  773. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  774. fi
  775. elif [ $FORCE ]; then
  776. echo -e "\e[31mYou are running in forced mode!\e[0m"
  777. echo -e "\e[31mA Branch Switch can only be performed manually (monitored).\e[0m"
  778. echo -e "\e[31mPlease rerun the update.sh Script without the --force/-f parameter.\e[0m"
  779. sleep 1
  780. elif [ $NEW_BRANCH == "master" ] && [ $CURRENT_BRANCH != "master" ]; then
  781. echo -e "\e[33mYou are about to switch your mailcow updates to the stable (master) branch.\e[0m"
  782. sleep 1
  783. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no data is lost...\e[0m"
  784. sleep 1
  785. echo -e "\e[31mWARNING: Please see on GitHub or ask in the community if a switch to master is stable or not.
  786. In some rear cases an update back to master can destroy your mailcow configuration such as database upgrade, etc.
  787. Normally an upgrade back to master should be safe during each full release.
  788. Check GitHub for Database changes and update only if there similar to the full release!\e[0m"
  789. read -r -p "Are you sure you that want to continue upgrading to the stable (master) branch? [y/N] " response
  790. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  791. echo "OK. If you prepared yourself for that please run the update.sh Script with the --stable parameter again to trigger this process here."
  792. exit 0
  793. fi
  794. BRANCH=$NEW_BRANCH
  795. DIFF_DIRECTORY=update_diffs
  796. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_master_$(date +"%Y-%m-%d-%H-%M-%S")
  797. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  798. if ! git diff-index --quiet HEAD; then
  799. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  800. mkdir -p ${DIFF_DIRECTORY}
  801. git diff ${BRANCH} --stat > ${DIFF_FILE}
  802. git diff ${BRANCH} >> ${DIFF_FILE}
  803. fi
  804. echo -e "\e[32mSwitching Branch to ${BRANCH}...\e[0m"
  805. git fetch origin
  806. git checkout -f ${BRANCH}
  807. elif [ $NEW_BRANCH == "nightly" ] && [ $CURRENT_BRANCH != "nightly" ]; then
  808. echo -e "\e[33mYou are about to switch your mailcow Updates to the unstable (nightly) branch.\e[0m"
  809. sleep 1
  810. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no Data is lost...\e[0m"
  811. sleep 1
  812. echo -e "\e[31mWARNING: A switch to nightly is possible any time. But a switch back (to master) isn't.\e[0m"
  813. read -r -p "Are you sure you that want to continue upgrading to the unstable (nightly) branch? [y/N] " response
  814. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  815. echo "OK. If you prepared yourself for that please run the update.sh Script with the --nightly parameter again to trigger this process here."
  816. exit 0
  817. fi
  818. BRANCH=$NEW_BRANCH
  819. DIFF_DIRECTORY=update_diffs
  820. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_nightly_$(date +"%Y-%m-%d-%H-%M-%S")
  821. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  822. if ! git diff-index --quiet HEAD; then
  823. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  824. mkdir -p ${DIFF_DIRECTORY}
  825. git diff ${BRANCH} --stat > ${DIFF_FILE}
  826. git diff ${BRANCH} >> ${DIFF_FILE}
  827. fi
  828. git fetch origin
  829. git checkout -f ${BRANCH}
  830. fi
  831. if [ ! $DEV ]; then
  832. echo -e "\e[32mChecking for newer update script...\e[0m"
  833. SHA1_1=$(sha1sum update.sh)
  834. git fetch origin #${BRANCH}
  835. git checkout origin/${BRANCH} update.sh
  836. SHA1_2=$(sha1sum update.sh)
  837. if [[ ${SHA1_1} != ${SHA1_2} ]]; then
  838. echo "update.sh changed, please run this script again, exiting."
  839. chmod +x update.sh
  840. exit 2
  841. fi
  842. fi
  843. if [ ! $FORCE ]; then
  844. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  845. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  846. echo "OK, exiting."
  847. exit 0
  848. fi
  849. migrate_docker_nat
  850. fi
  851. remove_obsolete_nginx_ports
  852. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  853. sed -i 's/HTTPS_BIND:-:/HTTPS_BIND:-/g' docker-compose.yml
  854. sed -i 's/HTTP_BIND:-:/HTTP_BIND:-/g' docker-compose.yml
  855. if ! $COMPOSE_COMMAND config -q; then
  856. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  857. exit 1
  858. fi
  859. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  860. MAILCOW_BRIDGE=$($COMPOSE_COMMAND config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  861. while read NAT_ID; do
  862. iptables -t nat -D POSTROUTING $NAT_ID
  863. done < <(iptables -L -vn -t nat --line-numbers | grep $IPV4_NETWORK | grep -E 'MASQUERADE.*all' | grep -v ${MAILCOW_BRIDGE} | cut -d' ' -f1)
  864. DIFF_DIRECTORY=update_diffs
  865. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  866. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  867. if ! git diff-index --quiet HEAD; then
  868. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  869. mkdir -p ${DIFF_DIRECTORY}
  870. git diff --stat > ${DIFF_FILE}
  871. git diff >> ${DIFF_FILE}
  872. fi
  873. echo -e "\e[32mPrefetching images...\e[0m"
  874. prefetch_images
  875. echo -e "\e[32mStopping mailcow...\e[0m"
  876. sleep 2
  877. MAILCOW_CONTAINERS=($($COMPOSE_COMMAND ps -q))
  878. $COMPOSE_COMMAND down
  879. echo -e "\e[32mChecking for remaining containers...\e[0m"
  880. sleep 2
  881. for container in "${MAILCOW_CONTAINERS[@]}"; do
  882. docker rm -f "$container" 2> /dev/null
  883. done
  884. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  885. # Silently fixing remote url from andryyy to mailcow
  886. # git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  887. DEFAULT_REPO=https://github.com/mailcow/mailcow-dockerized
  888. CURRENT_REPO=$(git config --get remote.origin.url)
  889. if [ "$CURRENT_REPO" != "$DEFAULT_REPO" ]; then
  890. echo "The Repository currently used is not the default Mailcow Repository."
  891. echo "Currently Repository: $CURRENT_REPO"
  892. echo "Default Repository: $DEFAULT_REPO"
  893. if [ ! $FORCE ]; then
  894. read -r -p "Should it be changed back to default? [y/N] " repo_response
  895. if [[ "$repo_response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  896. git remote set-url origin $DEFAULT_REPO
  897. fi
  898. else
  899. echo "Running in forced mode... setting Repo to default!"
  900. git remote set-url origin $DEFAULT_REPO
  901. fi
  902. fi
  903. if [ ! $DEV ]; then
  904. echo -e "\e[32mCommitting current status...\e[0m"
  905. [[ -z "$(git config user.name)" ]] && git config user.name moo
  906. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  907. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  908. git add -u
  909. git commit -am "Before update on ${DATE}" > /dev/null
  910. echo -e "\e[32mFetching updated code from remote...\e[0m"
  911. git fetch origin #${BRANCH}
  912. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  913. git config merge.defaultToUpstream true
  914. git merge -X${MERGE_STRATEGY:-theirs} -Xpatience -m "After update on ${DATE}"
  915. # Need to use a variable to not pass return codes of if checks
  916. MERGE_RETURN=$?
  917. if [[ ${MERGE_RETURN} == 128 ]]; then
  918. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  919. exit 1
  920. elif [[ ${MERGE_RETURN} == 1 ]]; then
  921. echo -e "\e[93mPotential conflict, trying to fix...\e[0m"
  922. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  923. git add -A
  924. git commit -m "After update on ${DATE}" > /dev/null
  925. git checkout .
  926. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  927. elif [[ ${MERGE_RETURN} != 0 ]]; then
  928. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  929. echo
  930. echo "Run $COMPOSE_COMMAND up -d to restart your stack without updates or try again after fixing the mentioned errors."
  931. exit 1
  932. fi
  933. elif [ $DEV ]; then
  934. echo -e "\e[33mDEVELOPER MODE: Not creating a git diff and commiting it to prevent development stuff within a backup diff...\e[0m"
  935. fi
  936. echo -e "\e[32mFetching new images, if any...\e[0m"
  937. sleep 2
  938. $COMPOSE_COMMAND pull
  939. # Fix missing SSL, does not overwrite existing files
  940. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  941. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  942. echo -e "Checking IPv6 settings... "
  943. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  944. echo
  945. echo '!! IMPORTANT !!'
  946. echo
  947. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  948. echo "This setting will only be active after a complete shutdown of mailcow by running $COMPOSE_COMMAND down followed by $COMPOSE_COMMAND up -d."
  949. echo
  950. echo '!! IMPORTANT !!'
  951. echo
  952. read -p "Press any key to continue..." < /dev/tty
  953. fi
  954. # Checking for old project name bug
  955. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  956. # Fix Rspamd maps
  957. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  958. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  959. fi
  960. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  961. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  962. fi
  963. # Fix deprecated metrics.conf
  964. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  965. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  966. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  967. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  968. fi
  969. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  970. fi
  971. # Set app_info.inc.php
  972. if [ ${BRANCH} == "master" ]; then
  973. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  974. elif [ ${BRANCH} == "nightly" ]; then
  975. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  976. mailcow_last_git_version=""
  977. else
  978. mailcow_git_version=$(git rev-parse --short HEAD)
  979. mailcow_last_git_version=""
  980. fi
  981. mailcow_git_commit=$(git rev-parse origin/${BRANCH})
  982. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  983. if [ $? -eq 0 ]; then
  984. echo '<?php' > data/web/inc/app_info.inc.php
  985. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  986. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  987. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  988. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  989. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  990. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  991. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  992. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  993. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  994. echo '?>' >> data/web/inc/app_info.inc.php
  995. else
  996. echo '<?php' > data/web/inc/app_info.inc.php
  997. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  998. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  999. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  1000. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1001. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1002. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  1003. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  1004. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  1005. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  1006. echo '?>' >> data/web/inc/app_info.inc.php
  1007. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  1008. fi
  1009. if [[ ${SKIP_START} == "y" ]]; then
  1010. echo -e "\e[33mNot starting mailcow, please run \"$COMPOSE_COMMAND up -d --remove-orphans\" to start mailcow.\e[0m"
  1011. else
  1012. echo -e "\e[32mStarting mailcow...\e[0m"
  1013. sleep 2
  1014. $COMPOSE_COMMAND up -d --remove-orphans
  1015. fi
  1016. echo -e "\e[32mCollecting garbage...\e[0m"
  1017. docker_garbage
  1018. # Run post-update-hook
  1019. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  1020. bash "${SCRIPT_DIR}/post_update_hook.sh"
  1021. fi
  1022. # echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  1023. # echo
  1024. # git reflog --color=always | grep "Before update on "
  1025. # echo
  1026. # echo "Use \"git reset --hard hash-on-the-left\" and run $COMPOSE_COMMAND up -d afterwards."