generate_config.sh 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697
  1. #!/usr/bin/env bash
  2. set -o pipefail
  3. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  4. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  5. echo "Please update to 5.x or use another distribution."
  6. exit 1
  7. fi
  8. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  9. if grep -q Ubuntu <<< "$(uname -a)"; then
  10. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  11. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  12. exit 1
  13. fi
  14. fi
  15. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  16. # This will also cover sort
  17. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  18. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  19. for bin in openssl curl docker git awk sha1sum grep cut; do
  20. if [[ -z $(which ${bin}) ]]; then echo "Cannot find ${bin}, exiting..."; exit 1; fi
  21. done
  22. # Check Docker Version (need at least 24.X)
  23. docker_version=$(docker version --format '{{.Server.Version}}' | cut -d '.' -f 1)
  24. if [[ $docker_version -lt 24 ]]; then
  25. echo -e "\e[31mCannot find Docker with a Version higher or equals 24.0.0\e[0m"
  26. echo -e "\e[33mmailcow needs a newer Docker version to work properly...\e[0m"
  27. echo -e "\e[31mPlease update your Docker installation... exiting\e[0m"
  28. exit 1
  29. fi
  30. if docker compose > /dev/null 2>&1; then
  31. if docker compose version --short | grep -e "^2." -e "^v2." > /dev/null 2>&1; then
  32. COMPOSE_VERSION=native
  33. echo -e "\e[33mFound Docker Compose Plugin (native).\e[0m"
  34. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  35. sleep 2
  36. echo -e "\e[33mNotice: You'll have to update this Compose Version via your Package Manager manually!\e[0m"
  37. else
  38. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  39. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  40. exit 1
  41. fi
  42. elif docker-compose > /dev/null 2>&1; then
  43. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  44. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  45. COMPOSE_VERSION=standalone
  46. echo -e "\e[33mFound Docker Compose Standalone.\e[0m"
  47. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  48. sleep 2
  49. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  50. else
  51. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  52. echo -e "\e[31mPlease update/install manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  53. exit 1
  54. fi
  55. fi
  56. else
  57. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  58. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  59. exit 1
  60. fi
  61. detect_bad_asn() {
  62. echo -e "\e[33mDetecting if your IP is listed on Spamhaus Bad ASN List...\e[0m"
  63. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  64. if [ "$response" -eq 503 ]; then
  65. if [ -z "$SPAMHAUS_DQS_KEY" ]; then
  66. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  67. echo -e "\e[33mmailcow did not detected a value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf!\e[0m"
  68. sleep 2
  69. echo ""
  70. echo -e "\e[33mTo use the Spamhaus DNS Blocklists again, you will need to create a FREE account for their Data Query Service (DQS) at: https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account\e[0m"
  71. echo -e "\e[33mOnce done, enter your DQS API key in mailcow.conf and mailcow will do the rest for you!\e[0m"
  72. echo ""
  73. sleep 2
  74. else
  75. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  76. echo -e "\e[32mmailcow detected a Value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf. Postfix will use DQS with the given API key...\e[0m"
  77. fi
  78. elif [ "$response" -eq 200 ]; then
  79. echo -e "\e[33mCheck completed! Your IP is \e[32mclean\e[0m"
  80. elif [ "$response" -eq 429 ]; then
  81. echo -e "\e[33mCheck completed! \e[31mYour IP seems to be rate limited on the ASN Check service... please try again later!\e[0m"
  82. else
  83. echo -e "\e[31mCheck failed! \e[0mMaybe a DNS or Network problem?\e[0m"
  84. fi
  85. }
  86. ### If generate_config.sh is started with --dev or -d it will not check out nightly or master branch and will keep on the current branch
  87. if [[ ${1} == "--dev" || ${1} == "-d" ]]; then
  88. SKIP_BRANCH=y
  89. else
  90. SKIP_BRANCH=n
  91. fi
  92. if [ -f mailcow.conf ]; then
  93. read -r -p "A config file exists and will be overwritten, are you sure you want to continue? [y/N] " response
  94. case $response in
  95. [yY][eE][sS]|[yY])
  96. mv mailcow.conf mailcow.conf_backup
  97. chmod 600 mailcow.conf_backup
  98. ;;
  99. *)
  100. exit 1
  101. ;;
  102. esac
  103. fi
  104. echo "Press enter to confirm the detected value '[value]' where applicable or enter a custom value."
  105. while [ -z "${MAILCOW_HOSTNAME}" ]; do
  106. read -p "Mail server hostname (FQDN) - this is not your mail domain, but your mail servers hostname: " -e MAILCOW_HOSTNAME
  107. DOTS=${MAILCOW_HOSTNAME//[^.]};
  108. if [ ${#DOTS} -lt 1 ]; then
  109. echo -e "\e[31mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!\e[0m"
  110. sleep 1
  111. echo "Please change it to a FQDN and redeploy the stack with docker(-)compose up -d"
  112. exit 1
  113. elif [[ "${MAILCOW_HOSTNAME: -1}" == "." ]]; then
  114. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is ending with a dot. This is not a valid FQDN!"
  115. exit 1
  116. elif [ ${#DOTS} -eq 1 ]; then
  117. echo -e "\e[33mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) does not contain a Subdomain. This is not fully tested and may cause issues.\e[0m"
  118. echo "Find more information about why this message exists here: https://github.com/mailcow/mailcow-dockerized/issues/1572"
  119. read -r -p "Do you want to proceed anyway? [y/N] " response
  120. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  121. echo "OK. Procceding."
  122. else
  123. echo "OK. Exiting."
  124. exit 1
  125. fi
  126. fi
  127. done
  128. if [ -a /etc/timezone ]; then
  129. DETECTED_TZ=$(cat /etc/timezone)
  130. elif [ -a /etc/localtime ]; then
  131. DETECTED_TZ=$(readlink /etc/localtime|sed -n 's|^.*zoneinfo/||p')
  132. fi
  133. while [ -z "${MAILCOW_TZ}" ]; do
  134. if [ -z "${DETECTED_TZ}" ]; then
  135. read -p "Timezone: " -e MAILCOW_TZ
  136. else
  137. read -p "Timezone [${DETECTED_TZ}]: " -e MAILCOW_TZ
  138. [ -z "${MAILCOW_TZ}" ] && MAILCOW_TZ=${DETECTED_TZ}
  139. fi
  140. done
  141. MEM_TOTAL=$(awk '/MemTotal/ {print $2}' /proc/meminfo)
  142. if [ -z "${SKIP_CLAMD}" ]; then
  143. if [ "${MEM_TOTAL}" -le "2621440" ]; then
  144. echo "Installed memory is <= 2.5 GiB. It is recommended to disable ClamAV to prevent out-of-memory situations."
  145. echo "ClamAV can be re-enabled by setting SKIP_CLAMD=n in mailcow.conf."
  146. read -r -p "Do you want to disable ClamAV now? [Y/n] " response
  147. case $response in
  148. [nN][oO]|[nN])
  149. SKIP_CLAMD=n
  150. ;;
  151. *)
  152. SKIP_CLAMD=y
  153. ;;
  154. esac
  155. else
  156. SKIP_CLAMD=n
  157. fi
  158. fi
  159. if [[ ${SKIP_BRANCH} != y ]]; then
  160. echo "Which branch of mailcow do you want to use?"
  161. echo ""
  162. echo "Available Branches:"
  163. echo "- master branch (stable updates) | default, recommended [1]"
  164. echo "- nightly branch (unstable updates, testing) | not-production ready [2]"
  165. echo "- legacy branch (supported until February 2026) | deprecated, security updates only [3]"
  166. sleep 1
  167. while [ -z "${MAILCOW_BRANCH}" ]; do
  168. read -r -p "Choose the Branch with it's number [1/2/3] " branch
  169. case $branch in
  170. [3])
  171. MAILCOW_BRANCH="legacy"
  172. ;;
  173. [2])
  174. MAILCOW_BRANCH="nightly"
  175. ;;
  176. *)
  177. MAILCOW_BRANCH="master"
  178. ;;
  179. esac
  180. done
  181. git fetch --all
  182. git checkout -f "$MAILCOW_BRANCH"
  183. elif [[ ${SKIP_BRANCH} == y ]]; then
  184. echo -e "\033[33mEnabled Dev Mode.\033[0m"
  185. echo -e "\033[33mNot checking out a different branch!\033[0m"
  186. MAILCOW_BRANCH=$(git rev-parse --short $(git rev-parse @{upstream}))
  187. else
  188. echo -e "\033[31mCould not determine branch input..."
  189. echo -e "\033[31mExiting."
  190. exit 1
  191. fi
  192. if [ ! -z "${MAILCOW_BRANCH}" ]; then
  193. git_branch=${MAILCOW_BRANCH}
  194. fi
  195. # Check IPv6 support on the host
  196. if grep -qs '^1' /proc/sys/net/ipv6/conf/all/disable_ipv6 2>/dev/null \
  197. || ! ip -6 route show default &>/dev/null; then
  198. ENABLE_IPV6_LINE="ENABLE_IPV6=false"
  199. echo "IPv6 not detected on host — disabling IPv6 support."
  200. else
  201. ENABLE_IPV6_LINE="ENABLE_IPV6=true"
  202. echo "IPv6 detected on host — leaving IPv6 support enabled."
  203. fi
  204. # Check Docker daemon IPv6 settings
  205. # We require in /etc/docker/daemon.json:
  206. # "ipv6": true
  207. # "fixed-cidr-v6": "fd00:dead:beef:c0::/80"
  208. # For Docker < 27:
  209. # "ip6tables": true
  210. # "experimental": true
  211. DOCKER_DAEMON_CONFIG="/etc/docker/daemon.json"
  212. MISSING=()
  213. _has_kv() {
  214. grep -Eq "\"$1\"\s*:\s*$2" "$DOCKER_DAEMON_CONFIG" 2>/dev/null
  215. }
  216. if [[ -f "$DOCKER_DAEMON_CONFIG" ]]; then
  217. # ---- JSON validation ----
  218. if command -v jq &>/dev/null; then
  219. if ! jq empty "$DOCKER_DAEMON_CONFIG" 2>/dev/null; then
  220. echo "ERROR: $DOCKER_DAEMON_CONFIG contains invalid JSON."
  221. echo "Please fix the syntax (e.g. missing commas/braces) and rerun this script."
  222. exit 1
  223. fi
  224. else
  225. echo "WARNING: jq not found — cannot validate JSON syntax. Continuing anyway."
  226. fi
  227. # require "ipv6": true
  228. if ! _has_kv ipv6 true; then
  229. MISSING+=("ipv6: true")
  230. fi
  231. # require "fixed-cidr-v6": "fd00:dead:beef:c0::/80"
  232. if ! grep -Eq '"fixed-cidr-v6"\s*:\s*".+"' "$DOCKER_DAEMON_CONFIG"; then
  233. MISSING+=('fixed-cidr-v6: "fd00:dead:beef:c0::/80"')
  234. fi
  235. # determine Docker major version
  236. DOCKER_MAJOR=$(docker version --format '{{.Server.Version}}' 2>/dev/null | cut -d. -f1)
  237. if [[ -n "$DOCKER_MAJOR" && "$DOCKER_MAJOR" -lt 27 ]]; then
  238. # for Docker < 27, also require ip6tables and experimental
  239. if _has_kv ipv6 true && ! _has_kv ip6tables true; then
  240. MISSING+=("ip6tables: true")
  241. fi
  242. if ! _has_kv experimental true; then
  243. MISSING+=("experimental: true")
  244. fi
  245. else
  246. echo "Docker >= 27 detected — no ip6tables/experimental flags required."
  247. fi
  248. if (( ${#MISSING[@]} > 0 )); then
  249. echo "Your Docker daemon.json is missing: ${MISSING[*]}"
  250. read -p "Would you like to update $DOCKER_DAEMON_CONFIG now? [Y/n] " answer
  251. answer=${answer:-Y}
  252. if [[ $answer =~ ^[Yy]$ ]]; then
  253. cp "$DOCKER_DAEMON_CONFIG" "${DOCKER_DAEMON_CONFIG}.bak"
  254. echo "Backed up original to ${DOCKER_DAEMON_CONFIG}.bak"
  255. if command -v jq &>/dev/null; then
  256. TMP=$(mktemp)
  257. # build jq filter
  258. JQ_FILTER='.ipv6 = true | .["fixed-cidr-v6"] = "fd00:dead:beef:c0::/80"'
  259. if [[ -n "$DOCKER_MAJOR" && "$DOCKER_MAJOR" -lt 27 ]]; then
  260. JQ_FILTER+=' | .ip6tables = true | .experimental = true'
  261. fi
  262. jq "$JQ_FILTER" "$DOCKER_DAEMON_CONFIG" > "$TMP" && mv "$TMP" "$DOCKER_DAEMON_CONFIG"
  263. echo "Updated $DOCKER_DAEMON_CONFIG."
  264. echo "Restarting Docker daemon..."
  265. if command -v systemctl &>/dev/null; then
  266. systemctl restart docker
  267. else
  268. service docker restart
  269. fi
  270. echo "Docker restarted. Please rerun this script."
  271. exit 1
  272. else
  273. echo "Please install jq or edit $DOCKER_DAEMON_CONFIG manually (add ipv6:true, fixed-cidr-v6:\"fd00:dead:beef:c0::/80\", plus ip6tables/experimental if Docker<27), then restart Docker and rerun this script."
  274. exit 1
  275. fi
  276. else
  277. ENABLE_IPV6_LINE="ENABLE_IPV6=false"
  278. echo "User declined Docker config update — disabling IPv6 support."
  279. fi
  280. fi
  281. else
  282. echo "Warning: $DOCKER_DAEMON_CONFIG not found — cannot verify Docker IPv6 settings."
  283. fi
  284. [ ! -f ./data/conf/rspamd/override.d/worker-controller-password.inc ] && echo '# Placeholder' > ./data/conf/rspamd/override.d/worker-controller-password.inc
  285. cat << EOF > mailcow.conf
  286. # ------------------------------
  287. # mailcow web ui configuration
  288. # ------------------------------
  289. # example.org is _not_ a valid hostname, use a fqdn here.
  290. # Default admin user is "admin"
  291. # Default password is "moohoo"
  292. MAILCOW_HOSTNAME=${MAILCOW_HOSTNAME}
  293. # Password hash algorithm
  294. # Only certain password hash algorithm are supported. For a fully list of supported schemes,
  295. # see https://docs.mailcow.email/models/model-passwd/
  296. MAILCOW_PASS_SCHEME=BLF-CRYPT
  297. # ------------------------------
  298. # SQL database configuration
  299. # ------------------------------
  300. DBNAME=mailcow
  301. DBUSER=mailcow
  302. # Please use long, random alphanumeric strings (A-Za-z0-9)
  303. DBPASS=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)
  304. DBROOT=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)
  305. # ------------------------------
  306. # REDIS configuration
  307. # ------------------------------
  308. REDISPASS=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)
  309. # ------------------------------
  310. # HTTP/S Bindings
  311. # ------------------------------
  312. # You should use HTTPS, but in case of SSL offloaded reverse proxies:
  313. # Might be important: This will also change the binding within the container.
  314. # If you use a proxy within Docker, point it to the ports you set below.
  315. # Do _not_ use IP:PORT in HTTP(S)_BIND or HTTP(S)_PORT
  316. # IMPORTANT: Do not use port 8081, 9081, 9082 or 65510!
  317. # Example: HTTP_BIND=1.2.3.4
  318. # For IPv4 leave it as it is: HTTP_BIND= & HTTPS_PORT=
  319. # For IPv6 see https://docs.mailcow.email/post_installation/firststeps-ip_bindings/
  320. HTTP_PORT=80
  321. HTTP_BIND=
  322. HTTPS_PORT=443
  323. HTTPS_BIND=
  324. # Redirect HTTP connections to HTTPS - y/n
  325. HTTP_REDIRECT=n
  326. # ------------------------------
  327. # Other bindings
  328. # ------------------------------
  329. # You should leave that alone
  330. # Format: 11.22.33.44:25 or 12.34.56.78:465 etc.
  331. SMTP_PORT=25
  332. SMTPS_PORT=465
  333. SUBMISSION_PORT=587
  334. IMAP_PORT=143
  335. IMAPS_PORT=993
  336. POP_PORT=110
  337. POPS_PORT=995
  338. SIEVE_PORT=4190
  339. DOVEADM_PORT=127.0.0.1:19991
  340. SQL_PORT=127.0.0.1:13306
  341. REDIS_PORT=127.0.0.1:7654
  342. # Your timezone
  343. # See https://en.wikipedia.org/wiki/List_of_tz_database_time_zones for a list of timezones
  344. # Use the column named 'TZ identifier' + pay attention for the column named 'Notes'
  345. TZ=${MAILCOW_TZ}
  346. # Fixed project name
  347. # Please use lowercase letters only
  348. COMPOSE_PROJECT_NAME=mailcowdockerized
  349. # Used Docker Compose version
  350. # Switch here between native (compose plugin) and standalone
  351. # For more informations take a look at the mailcow docs regarding the configuration options.
  352. # Normally this should be untouched but if you decided to use either of those you can switch it manually here.
  353. # Please be aware that at least one of those variants should be installed on your machine or mailcow will fail.
  354. DOCKER_COMPOSE_VERSION=${COMPOSE_VERSION}
  355. # Set this to "allow" to enable the anyone pseudo user. Disabled by default.
  356. # When enabled, ACL can be created, that apply to "All authenticated users"
  357. # This should probably only be activated on mail hosts, that are used exclusivly by one organisation.
  358. # Otherwise a user might share data with too many other users.
  359. ACL_ANYONE=disallow
  360. # Garbage collector cleanup
  361. # Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring
  362. # How long should objects remain in the garbage until they are being deleted? (value in minutes)
  363. # Check interval is hourly
  364. MAILDIR_GC_TIME=7200
  365. # Additional SAN for the certificate
  366. #
  367. # You can use wildcard records to create specific names for every domain you add to mailcow.
  368. # Example: Add domains "example.com" and "example.net" to mailcow, change ADDITIONAL_SAN to a value like:
  369. #ADDITIONAL_SAN=imap.*,smtp.*
  370. # This will expand the certificate to "imap.example.com", "smtp.example.com", "imap.example.net", "smtp.example.net"
  371. # plus every domain you add in the future.
  372. #
  373. # You can also just add static names...
  374. #ADDITIONAL_SAN=srv1.example.net
  375. # ...or combine wildcard and static names:
  376. #ADDITIONAL_SAN=imap.*,srv1.example.com
  377. #
  378. ADDITIONAL_SAN=
  379. # Obtain certificates for autodiscover.* and autoconfig.* domains.
  380. # This can be useful to switch off in case you are in a scenario where a reverse proxy already handles those.
  381. # There are mixed scenarios where ports 80,443 are occupied and you do not want to share certs
  382. # between services. So acme-mailcow obtains for maildomains and all web-things get handled
  383. # in the reverse proxy.
  384. AUTODISCOVER_SAN=y
  385. # Additional server names for mailcow UI
  386. #
  387. # Specify alternative addresses for the mailcow UI to respond to
  388. # This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.
  389. # If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.
  390. # You can understand this as server_name directive in Nginx.
  391. # Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f
  392. ADDITIONAL_SERVER_NAMES=
  393. # Skip running ACME (acme-mailcow, Let's Encrypt certs) - y/n
  394. SKIP_LETS_ENCRYPT=n
  395. # Create seperate certificates for all domains - y/n
  396. # this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames
  397. # see https://doc.dovecot.org/admin_manual/ssl/sni_support
  398. ENABLE_SSL_SNI=n
  399. # Skip IPv4 check in ACME container - y/n
  400. SKIP_IP_CHECK=n
  401. # Skip HTTP verification in ACME container - y/n
  402. SKIP_HTTP_VERIFICATION=n
  403. # Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n
  404. SKIP_UNBOUND_HEALTHCHECK=n
  405. # Skip ClamAV (clamd-mailcow) anti-virus (Rspamd will auto-detect a missing ClamAV container) - y/n
  406. SKIP_CLAMD=${SKIP_CLAMD}
  407. # Skip Olefy (olefy-mailcow) anti-virus for Office documents (Rspamd will auto-detect a missing Olefy container) - y/n
  408. SKIP_OLEFY=n
  409. # Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n
  410. SKIP_SOGO=n
  411. # Skip FTS (Fulltext Search) for Dovecot on low-memory, low-threaded systems or if you simply want to disable it.
  412. # Dovecot inside mailcow use Flatcurve as FTS Backend.
  413. SKIP_FTS=n
  414. # Dovecot Indexing (FTS) Process maximum heap size in MB, there is no recommendation, please see Dovecot docs.
  415. # Flatcurve (Xapian backend) is used as the FTS Indexer. It is supposed to be efficient in CPU and RAM consumption.
  416. # However: Please always monitor your Resource consumption!
  417. FTS_HEAP=128
  418. # Controls how many processes the Dovecot indexing process can spawn at max.
  419. # Too many indexing processes can use a lot of CPU and Disk I/O.
  420. # Please visit: https://doc.dovecot.org/configuration_manual/service_configuration/#indexer-worker for more informations
  421. FTS_PROCS=1
  422. # Allow admins to log into SOGo as email user (without any password)
  423. ALLOW_ADMIN_EMAIL_LOGIN=n
  424. # Enable watchdog (watchdog-mailcow) to restart unhealthy containers
  425. USE_WATCHDOG=y
  426. # Send watchdog notifications by mail (sent from watchdog@MAILCOW_HOSTNAME)
  427. # CAUTION:
  428. # 1. You should use external recipients
  429. # 2. Mails are sent unsigned (no DKIM)
  430. # 3. If you use DMARC, create a separate DMARC policy ("v=DMARC1; p=none;" in _dmarc.MAILCOW_HOSTNAME)
  431. # Multiple rcpts allowed, NO quotation marks, NO spaces
  432. #WATCHDOG_NOTIFY_EMAIL=a@example.com,b@example.com,c@example.com
  433. #WATCHDOG_NOTIFY_EMAIL=
  434. # Send notifications to a webhook URL that receives a POST request with the content type "application/json".
  435. # You can use this to send notifications to services like Discord, Slack and others.
  436. #WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
  437. # JSON body included in the webhook POST request. Needs to be in single quotes.
  438. # Following variables are available: SUBJECT, BODY
  439. #WATCHDOG_NOTIFY_WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  440. # Notify about banned IP (includes whois lookup)
  441. WATCHDOG_NOTIFY_BAN=n
  442. # Send a notification when the watchdog is started.
  443. WATCHDOG_NOTIFY_START=y
  444. # Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.
  445. #WATCHDOG_SUBJECT=
  446. # Checks if mailcow is an open relay. Requires a SAL. More checks will follow.
  447. # https://www.servercow.de/mailcow?lang=en
  448. # https://www.servercow.de/mailcow?lang=de
  449. # No data is collected. Opt-in and anonymous.
  450. # Will only work with unmodified mailcow setups.
  451. WATCHDOG_EXTERNAL_CHECKS=n
  452. # Enable watchdog verbose logging
  453. WATCHDOG_VERBOSE=n
  454. # Max log lines per service to keep in Redis logs
  455. LOG_LINES=9999
  456. # Internal IPv4 /24 subnet, format n.n.n (expands to n.n.n.0/24)
  457. # Use private IPv4 addresses only, see https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses
  458. IPV4_NETWORK=172.22.1
  459. # Internal IPv6 subnet in fc00::/7
  460. # Use private IPv6 addresses only, see https://en.wikipedia.org/wiki/Private_network#Private_IPv6_addresses
  461. IPV6_NETWORK=fd4d:6169:6c63:6f77::/64
  462. # Use this IPv4 for outgoing connections (SNAT)
  463. #SNAT_TO_SOURCE=
  464. # Use this IPv6 for outgoing connections (SNAT)
  465. #SNAT6_TO_SOURCE=
  466. # Create or override an API key for the web UI
  467. # You _must_ define API_ALLOW_FROM, which is a comma separated list of IPs
  468. # An API key defined as API_KEY has read-write access
  469. # An API key defined as API_KEY_READ_ONLY has read-only access
  470. # Allowed chars for API_KEY and API_KEY_READ_ONLY: a-z, A-Z, 0-9, -
  471. # You can define API_KEY and/or API_KEY_READ_ONLY
  472. #API_KEY=
  473. #API_KEY_READ_ONLY=
  474. #API_ALLOW_FROM=172.22.1.1,127.0.0.1
  475. # mail_home is ~/Maildir
  476. MAILDIR_SUB=Maildir
  477. # SOGo session timeout in minutes
  478. SOGO_EXPIRE_SESSION=480
  479. # DOVECOT_MASTER_USER and DOVECOT_MASTER_PASS must both be provided. No special chars.
  480. # Empty by default to auto-generate master user and password on start.
  481. # User expands to DOVECOT_MASTER_USER@mailcow.local
  482. # LEAVE EMPTY IF UNSURE
  483. DOVECOT_MASTER_USER=
  484. # LEAVE EMPTY IF UNSURE
  485. DOVECOT_MASTER_PASS=
  486. # WebAuthn device manufacturer verification
  487. # After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed
  488. # root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates
  489. WEBAUTHN_ONLY_TRUSTED_VENDORS=n
  490. # Spamhaus Data Query Service Key
  491. # Optional: Leave empty for none
  492. # Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.
  493. # If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.
  494. # Otherwise it will work normally.
  495. SPAMHAUS_DQS_KEY=
  496. # IPv6 Controller Section
  497. # This variable controls the usage of IPv6 within mailcow.
  498. # Defaults to true
  499. # WARNING: MAKE SURE TO PROPERLY CONFIGURE IPv6 ON YOUR HOST FIRST BEFORE ENABLING THIS AS FAULTY CONFIGURATIONS CAN LEAD TO OPEN RELAYS!
  500. $ENABLE_IPV6_LINE
  501. # Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n
  502. # CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost
  503. DISABLE_NETFILTER_ISOLATION_RULE=n
  504. EOF
  505. mkdir -p data/assets/ssl
  506. chmod 600 mailcow.conf
  507. # copy but don't overwrite existing certificate
  508. echo "Generating snake-oil certificate..."
  509. # Making Willich more popular
  510. openssl req -x509 -newkey rsa:4096 -keyout data/assets/ssl-example/key.pem -out data/assets/ssl-example/cert.pem -days 365 -subj "/C=DE/ST=NRW/L=Willich/O=mailcow/OU=mailcow/CN=${MAILCOW_HOSTNAME}" -sha256 -nodes
  511. echo "Copying snake-oil certificate..."
  512. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  513. # Set app_info.inc.php
  514. case ${git_branch} in
  515. master)
  516. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  517. ;;
  518. nightly)
  519. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  520. mailcow_last_git_version=""
  521. ;;
  522. legacy)
  523. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  524. mailcow_last_git_version=""
  525. ;;
  526. *)
  527. mailcow_git_version=$(git rev-parse --short HEAD)
  528. mailcow_last_git_version=""
  529. ;;
  530. esac
  531. # if [ ${git_branch} == "master" ]; then
  532. # mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  533. # elif [ ${git_branch} == "nightly" ]; then
  534. # mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  535. # mailcow_last_git_version=""
  536. # else
  537. # mailcow_git_version=$(git rev-parse --short HEAD)
  538. # mailcow_last_git_version=""
  539. # fi
  540. if [[ $SKIP_BRANCH != "y" ]]; then
  541. mailcow_git_commit=$(git rev-parse origin/${git_branch})
  542. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  543. else
  544. mailcow_git_commit=$(git rev-parse ${git_branch})
  545. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  546. git_branch=$(git rev-parse --abbrev-ref HEAD)
  547. fi
  548. if [ $? -eq 0 ]; then
  549. echo '<?php' > data/web/inc/app_info.inc.php
  550. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  551. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  552. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  553. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  554. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  555. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  556. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  557. echo ' $MAILCOW_BRANCH="'$git_branch'";' >> data/web/inc/app_info.inc.php
  558. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  559. echo '?>' >> data/web/inc/app_info.inc.php
  560. else
  561. echo '<?php' > data/web/inc/app_info.inc.php
  562. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  563. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  564. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  565. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  566. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  567. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  568. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  569. echo ' $MAILCOW_BRANCH="'$git_branch'";' >> data/web/inc/app_info.inc.php
  570. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  571. echo '?>' >> data/web/inc/app_info.inc.php
  572. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  573. fi
  574. detect_bad_asn