update.sh 32 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745
  1. #!/usr/bin/env bash
  2. # Check permissions
  3. if [ "$(id -u)" -ne "0" ]; then
  4. echo "You need to be root"
  5. exit 1
  6. fi
  7. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  8. # Run pre-update-hook
  9. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  10. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  11. fi
  12. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  13. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  14. echo "Please update to 5.x or use another distribution."
  15. exit 1
  16. fi
  17. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  18. if grep -q Ubuntu <<< $(uname -a); then
  19. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  20. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  21. exit 1
  22. fi
  23. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  24. read -p "Press any key to continue..." < /dev/tty
  25. fi
  26. # Exit on error and pipefail
  27. set -o pipefail
  28. # Setting high dc timeout
  29. export COMPOSE_HTTP_TIMEOUT=600
  30. # Add /opt/bin to PATH
  31. PATH=$PATH:/opt/bin
  32. umask 0022
  33. for bin in curl docker git awk sha1sum; do
  34. if [[ -z $(which ${bin}) ]]; then echo "Cannot find ${bin}, exiting..."; exit 1; fi
  35. done
  36. echo "checking docker compose version...";
  37. if docker compose >/dev/null 2>&1; then
  38. echo -e "\e[32mFound Compose v2!\e[0m"
  39. COMPOSE_COMMAND="docker compose"
  40. elif docker-compose version --short | grep -m1 "^2" > /dev/null 2>&1; then
  41. echo -e "\e[32mFound Compose v2!\e[0m"
  42. COMPOSE_COMMAND="docker-compose"
  43. elif docker-compose version --short | grep -m1 "^1" > /dev/null 2>&1; then
  44. echo -e "\e[33mWARN: Your machine is using Docker-Compose v1!\e[0m"
  45. echo -e "\e[33mmailcow will drop the Docker-Compose v1 Support in December 2022\e[0m"
  46. echo -e "\e[33mPlease consider a upgrade to Docker-Compose v2.\e[0m"
  47. echo
  48. echo
  49. echo -e "\e[33mContinuing...\e[0m"
  50. sleep 3
  51. COMPOSE_COMMAND="docker-compose"
  52. else
  53. echo -e "\e[31mCannot find Docker-Compose v1 or v2 on your System. Please install Docker-Compose v2 and re-run the Script.\e[0m"
  54. exit 1
  55. fi
  56. export LC_ALL=C
  57. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  58. BRANCH=$(cd ${SCRIPT_DIR}; git rev-parse --abbrev-ref HEAD)
  59. check_online_status() {
  60. CHECK_ONLINE_IPS=(1.1.1.1 9.9.9.9 8.8.8.8)
  61. for ip in "${CHECK_ONLINE_IPS[@]}"; do
  62. if timeout 3 ping -c 1 ${ip} > /dev/null; then
  63. return 0
  64. fi
  65. done
  66. return 1
  67. }
  68. prefetch_images() {
  69. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  70. git fetch origin #${BRANCH}
  71. while read image; do
  72. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  73. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  74. continue
  75. fi
  76. fi
  77. RET_C=0
  78. until docker pull ${image}; do
  79. RET_C=$((RET_C + 1))
  80. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  81. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  82. sleep 1
  83. done
  84. done < <(git show origin/${BRANCH}:docker-compose.yml | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  85. }
  86. docker_garbage() {
  87. IMGS_TO_DELETE=()
  88. for container in $(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"); do
  89. REPOSITORY=${container/:*}
  90. TAG=${container/*:}
  91. V_MAIN=${container/*.}
  92. V_SUB=${container/*.}
  93. EXISTING_TAGS=$(docker images | grep ${REPOSITORY} | awk '{ print $2 }')
  94. for existing_tag in ${EXISTING_TAGS[@]}; do
  95. V_MAIN_EXISTING=${existing_tag/*.}
  96. V_SUB_EXISTING=${existing_tag/*.}
  97. # Not an integer
  98. [[ ! $V_MAIN_EXISTING =~ ^[0-9]+$ ]] && continue
  99. [[ ! $V_SUB_EXISTING =~ ^[0-9]+$ ]] && continue
  100. if [[ $V_MAIN_EXISTING == "latest" ]]; then
  101. echo "Found deprecated label \"latest\" for repository $REPOSITORY, it should be deleted."
  102. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  103. elif [[ $V_MAIN_EXISTING -lt $V_MAIN ]]; then
  104. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  105. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  106. elif [[ $V_SUB_EXISTING -lt $V_SUB ]]; then
  107. echo "Found tag $existing_tag for $REPOSITORY, which is older than the current tag $TAG and should be deleted."
  108. IMGS_TO_DELETE+=($REPOSITORY:$existing_tag)
  109. fi
  110. done
  111. done
  112. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  113. echo "Run the following command to delete unused image tags:"
  114. echo
  115. echo " docker rmi ${IMGS_TO_DELETE[*]}"
  116. echo
  117. if [ ! $FORCE ]; then
  118. read -r -p "Do you want to delete old image tags right now? [y/N] " response
  119. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  120. docker rmi ${IMGS_TO_DELETE[*]}
  121. else
  122. echo "OK, skipped."
  123. fi
  124. else
  125. echo "Running image removal without extra confirmation due to force mode."
  126. docker rmi ${IMGS_TO_DELETE[*]}
  127. fi
  128. echo -e "\e[32mFurther cleanup...\e[0m"
  129. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  130. fi
  131. }
  132. in_array() {
  133. local e match="$1"
  134. shift
  135. for e; do [[ "$e" == "$match" ]] && return 0; done
  136. return 1
  137. }
  138. migrate_docker_nat() {
  139. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  140. # Min Docker version
  141. DOCKERV_REQ=20.10.2
  142. # Current Docker version
  143. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  144. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  145. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  146. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  147. echo '!!! This step is recommended !!!'
  148. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  149. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  150. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  151. echo "OK, skipping this step."
  152. return 0
  153. fi
  154. fi
  155. # Sort versions and check if we are running a newer or equal version to req
  156. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  157. # If Dockerd daemon json exists
  158. if [ -s /etc/docker/daemon.json ]; then
  159. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  160. if ! in_array ipv6true "${dockerconfig[@]}" || \
  161. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  162. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  163. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  164. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  165. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  166. echo -e "Please merge the following content and restart the Docker daemon:\n"
  167. echo ${NAT_CONFIG}
  168. return 1
  169. fi
  170. else
  171. echo "Working on IPv6 NAT, please wait..."
  172. echo ${NAT_CONFIG} > /etc/docker/daemon.json
  173. ip6tables -F -t nat
  174. [[ -e /etc/alpine-release ]] && rc-service docker restart || systemctl restart docker.service
  175. if [[ $? -ne 0 ]]; then
  176. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  177. rm /etc/docker/daemon.json
  178. if [[ -e /etc/alpine-release ]]; then
  179. rc-service docker restart
  180. else
  181. systemctl reset-failed docker.service
  182. systemctl restart docker.service
  183. fi
  184. return 1
  185. fi
  186. fi
  187. # Removing legacy container
  188. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  189. if [ -s docker-compose.override.yml ]; then
  190. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  191. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  192. mv docker-compose.override.yml docker-compose.override.yml_backup
  193. fi
  194. fi
  195. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  196. else
  197. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  198. return 0
  199. fi
  200. }
  201. while (($#)); do
  202. case "${1}" in
  203. --check|-c)
  204. echo "Checking remote code for updates..."
  205. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized ${BRANCH} | cut -f1)
  206. if [ $? -ne 0 ]; then
  207. echo "A problem occurred while trying to fetch the latest revision from github."
  208. exit 99
  209. fi
  210. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  211. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  212. git log --date=short --pretty=format:"%ad - %s" $(git rev-parse --short HEAD)..origin/master
  213. exit 0
  214. else
  215. echo "No updates available."
  216. exit 3
  217. fi
  218. ;;
  219. --ours)
  220. MERGE_STRATEGY=ours
  221. ;;
  222. --skip-start)
  223. SKIP_START=y
  224. ;;
  225. --gc)
  226. echo -e "\e[32mCollecting garbage...\e[0m"
  227. docker_garbage
  228. exit 0
  229. ;;
  230. --prefetch)
  231. echo -e "\e[32mPrefetching images...\e[0m"
  232. prefetch_images
  233. exit 0
  234. ;;
  235. -f|--force)
  236. echo -e "\e[32mRunning in forced mode...\e[0m"
  237. FORCE=y
  238. ;;
  239. --skip-ping-check)
  240. SKIP_PING_CHECK=y
  241. ;;
  242. --help|-h)
  243. echo './update.sh [-c|--check, --ours, --gc, --no-update-compose, --prefetch, --skip-start, --skip-ping-check, -f|--force, -h|--help]
  244. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  245. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  246. --gc - Run garbage collector to delete old image tags
  247. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  248. --skip-start - Do not start mailcow after update
  249. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you´ve blocked any ICMP Connections to your mailcow machine).
  250. -f|--force - Force update, do not ask questions
  251. '
  252. exit 1
  253. esac
  254. shift
  255. done
  256. [[ ! -f mailcow.conf ]] && { echo "mailcow.conf is missing"; exit 1;}
  257. chmod 600 mailcow.conf
  258. source mailcow.conf
  259. DOTS=${MAILCOW_HOSTNAME//[^.]};
  260. if [ ${#DOTS} -lt 2 ]; then
  261. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!"
  262. echo "Please change it to a FQDN and run ${COMPOSE_COMMAND} down followed by ${COMPOSE_COMMAND} up -d"
  263. exit 1
  264. fi
  265. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  266. # This will also cover sort
  267. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  268. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  269. CONFIG_ARRAY=(
  270. "SKIP_LETS_ENCRYPT"
  271. "SKIP_SOGO"
  272. "USE_WATCHDOG"
  273. "WATCHDOG_NOTIFY_EMAIL"
  274. "WATCHDOG_NOTIFY_BAN"
  275. "WATCHDOG_EXTERNAL_CHECKS"
  276. "WATCHDOG_SUBJECT"
  277. "SKIP_CLAMD"
  278. "SKIP_IP_CHECK"
  279. "ADDITIONAL_SAN"
  280. "DOVEADM_PORT"
  281. "IPV4_NETWORK"
  282. "IPV6_NETWORK"
  283. "LOG_LINES"
  284. "SNAT_TO_SOURCE"
  285. "SNAT6_TO_SOURCE"
  286. "COMPOSE_PROJECT_NAME"
  287. "SQL_PORT"
  288. "API_KEY"
  289. "API_KEY_READ_ONLY"
  290. "API_ALLOW_FROM"
  291. "MAILDIR_GC_TIME"
  292. "MAILDIR_SUB"
  293. "ACL_ANYONE"
  294. "SOLR_HEAP"
  295. "SKIP_SOLR"
  296. "ENABLE_SSL_SNI"
  297. "ALLOW_ADMIN_EMAIL_LOGIN"
  298. "SKIP_HTTP_VERIFICATION"
  299. "SOGO_EXPIRE_SESSION"
  300. "REDIS_PORT"
  301. "DOVECOT_MASTER_USER"
  302. "DOVECOT_MASTER_PASS"
  303. "MAILCOW_PASS_SCHEME"
  304. "ADDITIONAL_SERVER_NAMES"
  305. "ACME_CONTACT"
  306. "WATCHDOG_VERBOSE"
  307. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  308. )
  309. sed -i --follow-symlinks '$a\' mailcow.conf
  310. for option in ${CONFIG_ARRAY[@]}; do
  311. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  312. if ! grep -q ${option} mailcow.conf; then
  313. echo "Adding new option \"${option}\" to mailcow.conf"
  314. echo "${option}=" >> mailcow.conf
  315. fi
  316. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  317. if ! grep -q ${option} mailcow.conf; then
  318. echo "Adding new option \"${option}\" to mailcow.conf"
  319. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  320. fi
  321. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  322. if ! grep -q ${option} mailcow.conf; then
  323. echo "Adding new option \"${option}\" to mailcow.conf"
  324. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  325. fi
  326. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  327. if ! grep -q ${option} mailcow.conf; then
  328. echo "Adding new option \"${option}\" to mailcow.conf"
  329. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  330. fi
  331. elif [[ ${option} == "LOG_LINES" ]]; then
  332. if ! grep -q ${option} mailcow.conf; then
  333. echo "Adding new option \"${option}\" to mailcow.conf"
  334. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  335. echo "LOG_LINES=9999" >> mailcow.conf
  336. fi
  337. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  338. if ! grep -q ${option} mailcow.conf; then
  339. echo "Adding new option \"${option}\" to mailcow.conf"
  340. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  341. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  342. fi
  343. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  344. if ! grep -q ${option} mailcow.conf; then
  345. echo "Adding new option \"${option}\" to mailcow.conf"
  346. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  347. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  348. fi
  349. elif [[ ${option} == "SQL_PORT" ]]; then
  350. if ! grep -q ${option} mailcow.conf; then
  351. echo "Adding new option \"${option}\" to mailcow.conf"
  352. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  353. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  354. fi
  355. elif [[ ${option} == "API_KEY" ]]; then
  356. if ! grep -q ${option} mailcow.conf; then
  357. echo "Adding new option \"${option}\" to mailcow.conf"
  358. echo '# Create or override API key for web UI' >> mailcow.conf
  359. echo "#API_KEY=" >> mailcow.conf
  360. fi
  361. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  362. if ! grep -q ${option} mailcow.conf; then
  363. echo "Adding new option \"${option}\" to mailcow.conf"
  364. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  365. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  366. fi
  367. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  368. if ! grep -q ${option} mailcow.conf; then
  369. echo "Adding new option \"${option}\" to mailcow.conf"
  370. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  371. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  372. echo "#API_ALLOW_FROM=" >> mailcow.conf
  373. fi
  374. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  375. if ! grep -q ${option} mailcow.conf; then
  376. echo "Adding new option \"${option}\" to mailcow.conf"
  377. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  378. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  379. fi
  380. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  381. if ! grep -q ${option} mailcow.conf; then
  382. echo "Adding new option \"${option}\" to mailcow.conf"
  383. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  384. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  385. fi
  386. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  387. if ! grep -q ${option} mailcow.conf; then
  388. echo "Adding new option \"${option}\" to mailcow.conf"
  389. echo '# Garbage collector cleanup' >> mailcow.conf
  390. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  391. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  392. echo '# Check interval is hourly' >> mailcow.conf
  393. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  394. fi
  395. elif [[ ${option} == "ACL_ANYONE" ]]; then
  396. if ! grep -q ${option} mailcow.conf; then
  397. echo "Adding new option \"${option}\" to mailcow.conf"
  398. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  399. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  400. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  401. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  402. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  403. fi
  404. elif [[ ${option} == "SOLR_HEAP" ]]; then
  405. if ! grep -q ${option} mailcow.conf; then
  406. echo "Adding new option \"${option}\" to mailcow.conf"
  407. echo '# Solr heap size, there is no recommendation, please see Solr docs.' >> mailcow.conf
  408. echo '# Solr is a prone to run OOM on large systems and should be monitored. Unmonitored Solr setups are not recommended.' >> mailcow.conf
  409. echo '# Solr will refuse to start with total system memory below or equal to 2 GB.' >> mailcow.conf
  410. echo "SOLR_HEAP=1024" >> mailcow.conf
  411. fi
  412. elif [[ ${option} == "SKIP_SOLR" ]]; then
  413. if ! grep -q ${option} mailcow.conf; then
  414. echo "Adding new option \"${option}\" to mailcow.conf"
  415. echo '# Solr is disabled by default after upgrading from non-Solr to Solr-enabled mailcows.' >> mailcow.conf
  416. echo '# Disable Solr or if you do not want to store a readable index of your mails in solr-vol-1.' >> mailcow.conf
  417. echo "SKIP_SOLR=y" >> mailcow.conf
  418. fi
  419. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  420. if ! grep -q ${option} mailcow.conf; then
  421. echo "Adding new option \"${option}\" to mailcow.conf"
  422. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  423. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  424. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  425. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  426. fi
  427. elif [[ ${option} == "SKIP_SOGO" ]]; then
  428. if ! grep -q ${option} mailcow.conf; then
  429. echo "Adding new option \"${option}\" to mailcow.conf"
  430. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  431. echo "SKIP_SOGO=n" >> mailcow.conf
  432. fi
  433. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  434. if ! grep -q ${option} mailcow.conf; then
  435. echo "Adding new option \"${option}\" to mailcow.conf"
  436. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  437. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  438. echo "MAILDIR_SUB=" >> mailcow.conf
  439. fi
  440. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  441. if ! grep -q ${option} mailcow.conf; then
  442. echo "Adding new option \"${option}\" to mailcow.conf"
  443. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  444. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  445. fi
  446. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  447. if ! grep -q ${option} mailcow.conf; then
  448. echo "Adding new option \"${option}\" to mailcow.conf"
  449. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  450. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  451. fi
  452. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  453. if ! grep -q ${option} mailcow.conf; then
  454. echo "Adding new option \"${option}\" to mailcow.conf"
  455. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  456. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  457. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  458. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  459. fi
  460. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  461. if ! grep -q ${option} mailcow.conf; then
  462. echo "Adding new option \"${option}\" to mailcow.conf"
  463. echo '# SOGo session timeout in minutes' >> mailcow.conf
  464. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  465. fi
  466. elif [[ ${option} == "REDIS_PORT" ]]; then
  467. if ! grep -q ${option} mailcow.conf; then
  468. echo "Adding new option \"${option}\" to mailcow.conf"
  469. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  470. fi
  471. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  472. if ! grep -q ${option} mailcow.conf; then
  473. echo "Adding new option \"${option}\" to mailcow.conf"
  474. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  475. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  476. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  477. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  478. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  479. fi
  480. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  481. if ! grep -q ${option} mailcow.conf; then
  482. echo "Adding new option \"${option}\" to mailcow.conf"
  483. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  484. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  485. fi
  486. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  487. if ! grep -q ${option} mailcow.conf; then
  488. echo "Adding new option \"${option}\" to mailcow.conf"
  489. echo '# Password hash algorithm' >> mailcow.conf
  490. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  491. echo '# see https://mailcow.github.io/mailcow-dockerized-docs/models/model-passwd/' >> mailcow.conf
  492. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  493. fi
  494. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  495. if ! grep -q ${option} mailcow.conf; then
  496. echo '# Additional server names for mailcow UI' >> mailcow.conf
  497. echo '#' >> mailcow.conf
  498. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  499. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  500. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  501. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  502. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  503. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  504. fi
  505. elif [[ ${option} == "ACME_CONTACT" ]]; then
  506. if ! grep -q ${option} mailcow.conf; then
  507. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  508. echo '# Optional: Leave empty for none' >> mailcow.conf
  509. echo '# This value is only used on first order!' >> mailcow.conf
  510. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  511. echo '# https://mailcow.github.io/mailcow-dockerized-docs/troubleshooting/debug-reset_tls/' >> mailcow.conf
  512. echo 'ACME_CONTACT=' >> mailcow.conf
  513. fi
  514. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  515. if ! grep -q ${option} mailcow.conf; then
  516. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  517. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  518. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  519. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  520. fi
  521. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  522. if ! grep -q ${option} mailcow.conf; then
  523. echo '# Enable watchdog verbose logging' >> mailcow.conf
  524. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  525. fi
  526. elif ! grep -q ${option} mailcow.conf; then
  527. echo "Adding new option \"${option}\" to mailcow.conf"
  528. echo "${option}=n" >> mailcow.conf
  529. fi
  530. done
  531. if [[( ${SKIP_PING_CHECK} == "y")]]; then
  532. echo -e "\e[32mSkipping Ping Check...\e[0m"
  533. else
  534. echo -en "Checking internet connection... "
  535. if ! check_online_status; then
  536. echo -e "\e[31mfailed\e[0m"
  537. exit 1
  538. else
  539. echo -e "\e[32mOK\e[0m"
  540. fi
  541. fi
  542. echo -e "\e[32mChecking for newer update script...\e[0m"
  543. SHA1_1=$(sha1sum update.sh)
  544. git fetch origin #${BRANCH}
  545. git checkout origin/${BRANCH} update.sh
  546. SHA1_2=$(sha1sum update.sh)
  547. if [[ ${SHA1_1} != ${SHA1_2} ]]; then
  548. echo "update.sh changed, please run this script again, exiting."
  549. chmod +x update.sh
  550. exit 2
  551. fi
  552. if [[ -f mailcow.conf ]]; then
  553. source mailcow.conf
  554. else
  555. echo -e "\e[31mNo mailcow.conf - is mailcow installed?\e[0m"
  556. exit 1
  557. fi
  558. if [ ! $FORCE ]; then
  559. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  560. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  561. echo "OK, exiting."
  562. exit 0
  563. fi
  564. migrate_docker_nat
  565. fi
  566. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  567. if ! ${COMPOSE_COMMAND} config -q; then
  568. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  569. exit 1
  570. fi
  571. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  572. MAILCOW_BRIDGE=$(${COMPOSE_COMMAND} config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  573. while read NAT_ID; do
  574. iptables -t nat -D POSTROUTING $NAT_ID
  575. done < <(iptables -L -vn -t nat --line-numbers | grep $IPV4_NETWORK | grep -E 'MASQUERADE.*all' | grep -v ${MAILCOW_BRIDGE} | cut -d' ' -f1)
  576. DIFF_DIRECTORY=update_diffs
  577. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  578. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  579. if ! git diff-index --quiet HEAD; then
  580. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  581. mkdir -p ${DIFF_DIRECTORY}
  582. git diff --stat > ${DIFF_FILE}
  583. git diff >> ${DIFF_FILE}
  584. fi
  585. echo -e "\e[32mPrefetching images...\e[0m"
  586. prefetch_images
  587. echo -e "\e[32mStopping mailcow...\e[0m"
  588. sleep 2
  589. MAILCOW_CONTAINERS=($(${COMPOSE_COMMAND} ps -q))
  590. ${COMPOSE_COMMAND} down
  591. echo -e "\e[32mChecking for remaining containers...\e[0m"
  592. sleep 2
  593. for container in "${MAILCOW_CONTAINERS[@]}"; do
  594. docker rm -f "$container" 2> /dev/null
  595. done
  596. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  597. # Silently fixing remote url from andryyy to mailcow
  598. git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  599. echo -e "\e[32mCommitting current status...\e[0m"
  600. [[ -z "$(git config user.name)" ]] && git config user.name moo
  601. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  602. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  603. git add -u
  604. git commit -am "Before update on ${DATE}" > /dev/null
  605. echo -e "\e[32mFetching updated code from remote...\e[0m"
  606. git fetch origin #${BRANCH}
  607. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  608. git config merge.defaultToUpstream true
  609. git merge -X${MERGE_STRATEGY:-theirs} -Xpatience -m "After update on ${DATE}"
  610. # Need to use a variable to not pass return codes of if checks
  611. MERGE_RETURN=$?
  612. if [[ ${MERGE_RETURN} == 128 ]]; then
  613. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  614. exit 1
  615. elif [[ ${MERGE_RETURN} == 1 ]]; then
  616. echo -e "\e[93mPotenial conflict, trying to fix...\e[0m"
  617. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  618. git add -A
  619. git commit -m "After update on ${DATE}" > /dev/null
  620. git checkout .
  621. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  622. elif [[ ${MERGE_RETURN} != 0 ]]; then
  623. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  624. echo
  625. echo "Run ${COMPOSE_COMMAND} up -d to restart your stack without updates or try again after fixing the mentioned errors."
  626. exit 1
  627. fi
  628. echo -e "\e[33mNot fetching latest docker-compose, please check for updates manually!\e[0m"
  629. sleep 3
  630. echo -e "\e[32mFetching new images, if any...\e[0m"
  631. sleep 2
  632. ${COMPOSE_COMMAND} pull
  633. # Fix missing SSL, does not overwrite existing files
  634. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  635. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  636. echo -e "Checking IPv6 settings... "
  637. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  638. echo
  639. echo '!! IMPORTANT !!'
  640. echo
  641. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  642. echo 'This setting will only be active after a complete shutdown of mailcow by running "docker-compose down" followed by "docker-compose up -d".'
  643. echo
  644. echo '!! IMPORTANT !!'
  645. echo
  646. read -p "Press any key to continue..." < /dev/tty
  647. fi
  648. # Checking for old project name bug
  649. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  650. # Fix Rspamd maps
  651. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  652. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  653. fi
  654. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  655. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  656. fi
  657. # Fix deprecated metrics.conf
  658. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  659. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  660. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  661. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  662. fi
  663. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  664. fi
  665. # Set app_info.inc.php
  666. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  667. if [ $? -eq 0 ]; then
  668. echo '<?php' > data/web/inc/app_info.inc.php
  669. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  670. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  671. echo '?>' >> data/web/inc/app_info.inc.php
  672. else
  673. echo '<?php' > data/web/inc/app_info.inc.php
  674. echo ' $MAILCOW_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  675. echo ' $MAILCOW_GIT_URL="";' >> data/web/inc/app_info.inc.php
  676. echo '?>' >> data/web/inc/app_info.inc.php
  677. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  678. fi
  679. if [[ ${SKIP_START} == "y" ]]; then
  680. echo -e "\e[33mNot starting mailcow, please run \"${COMPOSE_COMMAND} up -d --remove-orphans\" to start mailcow.\e[0m"
  681. else
  682. echo -e "\e[32mStarting mailcow...\e[0m"
  683. sleep 2
  684. ${COMPOSE_COMMAND} up -d --remove-orphans
  685. fi
  686. echo -e "\e[32mCollecting garbage...\e[0m"
  687. docker_garbage
  688. # Run post-update-hook
  689. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  690. bash "${SCRIPT_DIR}/post_update_hook.sh"
  691. fi
  692. #echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  693. #echo
  694. #git reflog --color=always | grep "Before update on "
  695. #echo
  696. #echo "Use \"git reset --hard hash-on-the-left\" and run ${COMPOSE_COMMAND} up -d afterwards."