generate_config.sh 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461
  1. #!/usr/bin/env bash
  2. set -o pipefail
  3. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  4. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  5. echo "Please update to 5.x or use another distribution."
  6. exit 1
  7. fi
  8. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  9. if grep -q Ubuntu <<< $(uname -a); then
  10. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  11. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  12. exit 1
  13. fi
  14. fi
  15. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  16. # This will also cover sort
  17. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  18. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  19. for bin in openssl curl docker git awk sha1sum; do
  20. if [[ -z $(which ${bin}) ]]; then echo "Cannot find ${bin}, exiting..."; exit 1; fi
  21. done
  22. if docker compose > /dev/null 2>&1; then
  23. if docker compose version --short | grep "^2." > /dev/null 2>&1; then
  24. COMPOSE_VERSION=native
  25. echo -e "\e[31mFound Docker Compose Plugin (native).\e[0m"
  26. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  27. sleep 2
  28. echo -e "\e[33mNotice: You´ll have to update this Compose Version via your Package Manager manually!\e[0m"
  29. else
  30. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  31. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://mailcow.github.io/mailcow-dockerized-docs/i_u_m/i_u_m_install/\e[0m"
  32. exit 1
  33. fi
  34. elif docker-compose > /dev/null 2>&1; then
  35. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  36. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  37. COMPOSE_VERSION=standalone
  38. echo -e "\e[31mFound Docker Compose Standalone.\e[0m"
  39. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  40. sleep 2
  41. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  42. else
  43. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  44. echo -e "\e[31mPlease update/install manually regarding to this doc site: https://mailcow.github.io/mailcow-dockerized-docs/i_u_m/i_u_m_install/\e[0m"
  45. exit 1
  46. fi
  47. fi
  48. else
  49. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  50. echo -e "\e[31mPlease install it regarding to this doc site: https://mailcow.github.io/mailcow-dockerized-docs/i_u_m/i_u_m_install/\e[0m"
  51. exit 1
  52. fi
  53. if [ -f mailcow.conf ]; then
  54. read -r -p "A config file exists and will be overwritten, are you sure you want to continue? [y/N] " response
  55. case $response in
  56. [yY][eE][sS]|[yY])
  57. mv mailcow.conf mailcow.conf_backup
  58. chmod 600 mailcow.conf_backup
  59. ;;
  60. *)
  61. exit 1
  62. ;;
  63. esac
  64. fi
  65. echo "Press enter to confirm the detected value '[value]' where applicable or enter a custom value."
  66. while [ -z "${MAILCOW_HOSTNAME}" ]; do
  67. read -p "Mail server hostname (FQDN) - this is not your mail domain, but your mail servers hostname: " -e MAILCOW_HOSTNAME
  68. DOTS=${MAILCOW_HOSTNAME//[^.]};
  69. if [ ${#DOTS} -lt 2 ] && [ ! -z ${MAILCOW_HOSTNAME} ]; then
  70. echo "${MAILCOW_HOSTNAME} is not a FQDN"
  71. MAILCOW_HOSTNAME=
  72. fi
  73. done
  74. if [ -a /etc/timezone ]; then
  75. DETECTED_TZ=$(cat /etc/timezone)
  76. elif [ -a /etc/localtime ]; then
  77. DETECTED_TZ=$(readlink /etc/localtime|sed -n 's|^.*zoneinfo/||p')
  78. fi
  79. while [ -z "${MAILCOW_TZ}" ]; do
  80. if [ -z "${DETECTED_TZ}" ]; then
  81. read -p "Timezone: " -e MAILCOW_TZ
  82. else
  83. read -p "Timezone [${DETECTED_TZ}]: " -e MAILCOW_TZ
  84. [ -z "${MAILCOW_TZ}" ] && MAILCOW_TZ=${DETECTED_TZ}
  85. fi
  86. done
  87. MEM_TOTAL=$(awk '/MemTotal/ {print $2}' /proc/meminfo)
  88. if [ ${MEM_TOTAL} -le "2621440" ]; then
  89. echo "Installed memory is <= 2.5 GiB. It is recommended to disable ClamAV to prevent out-of-memory situations."
  90. echo "ClamAV can be re-enabled by setting SKIP_CLAMD=n in mailcow.conf."
  91. read -r -p "Do you want to disable ClamAV now? [Y/n] " response
  92. case $response in
  93. [nN][oO]|[nN])
  94. SKIP_CLAMD=n
  95. ;;
  96. *)
  97. SKIP_CLAMD=y
  98. ;;
  99. esac
  100. else
  101. SKIP_CLAMD=n
  102. fi
  103. if [ ${MEM_TOTAL} -le "2097152" ]; then
  104. echo "Disabling Solr on low-memory system."
  105. SKIP_SOLR=y
  106. elif [ ${MEM_TOTAL} -le "3670016" ]; then
  107. echo "Installed memory is <= 3.5 GiB. It is recommended to disable Solr to prevent out-of-memory situations."
  108. echo "Solr is a prone to run OOM and should be monitored. The default Solr heap size is 1024 MiB and should be set in mailcow.conf according to your expected load."
  109. echo "Solr can be re-enabled by setting SKIP_SOLR=n in mailcow.conf but will refuse to start with less than 2 GB total memory."
  110. read -r -p "Do you want to disable Solr now? [Y/n] " response
  111. case $response in
  112. [nN][oO]|[nN])
  113. SKIP_SOLR=n
  114. ;;
  115. *)
  116. SKIP_SOLR=y
  117. ;;
  118. esac
  119. else
  120. SKIP_SOLR=n
  121. fi
  122. echo "Which branch of mailcow do you want to use?"
  123. echo ""
  124. echo "Available Branches:"
  125. echo "- master branch (stable updates) | default, recommended [1]"
  126. echo "- nightly branch (unstable updates, testing) | not-production ready [2]"
  127. sleep 1
  128. read -r -p "Choose the Branch with it´s number [1/2] " branch
  129. case $branch in
  130. [2])
  131. git_branch="nightly"
  132. ;;
  133. *)
  134. git_branch="master"
  135. ;;
  136. esac
  137. git fetch --all
  138. git checkout -f $git_branch
  139. [ ! -f ./data/conf/rspamd/override.d/worker-controller-password.inc ] && echo '# Placeholder' > ./data/conf/rspamd/override.d/worker-controller-password.inc
  140. cat << EOF > mailcow.conf
  141. # ------------------------------
  142. # mailcow web ui configuration
  143. # ------------------------------
  144. # example.org is _not_ a valid hostname, use a fqdn here.
  145. # Default admin user is "admin"
  146. # Default password is "moohoo"
  147. MAILCOW_HOSTNAME=${MAILCOW_HOSTNAME}
  148. # Password hash algorithm
  149. # Only certain password hash algorithm are supported. For a fully list of supported schemes,
  150. # see https://mailcow.github.io/mailcow-dockerized-docs/models/model-passwd/
  151. MAILCOW_PASS_SCHEME=BLF-CRYPT
  152. # ------------------------------
  153. # SQL database configuration
  154. # ------------------------------
  155. DBNAME=mailcow
  156. DBUSER=mailcow
  157. # Please use long, random alphanumeric strings (A-Za-z0-9)
  158. DBPASS=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 | head -c 28)
  159. DBROOT=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 | head -c 28)
  160. # ------------------------------
  161. # HTTP/S Bindings
  162. # ------------------------------
  163. # You should use HTTPS, but in case of SSL offloaded reverse proxies:
  164. # Might be important: This will also change the binding within the container.
  165. # If you use a proxy within Docker, point it to the ports you set below.
  166. # Do _not_ use IP:PORT in HTTP(S)_BIND or HTTP(S)_PORT
  167. # IMPORTANT: Do not use port 8081, 9081 or 65510!
  168. # Example: HTTP_BIND=1.2.3.4
  169. # For IPv4 leave it as it is: HTTP_BIND= & HTTPS_PORT=
  170. # For IPv6 see https://mailcow.github.io/mailcow-dockerized-docs/post_installation/firststeps-ip_bindings/
  171. HTTP_PORT=80
  172. HTTP_BIND=
  173. HTTPS_PORT=443
  174. HTTPS_BIND=
  175. # ------------------------------
  176. # Other bindings
  177. # ------------------------------
  178. # You should leave that alone
  179. # Format: 11.22.33.44:25 or 12.34.56.78:465 etc.
  180. SMTP_PORT=25
  181. SMTPS_PORT=465
  182. SUBMISSION_PORT=587
  183. IMAP_PORT=143
  184. IMAPS_PORT=993
  185. POP_PORT=110
  186. POPS_PORT=995
  187. SIEVE_PORT=4190
  188. DOVEADM_PORT=127.0.0.1:19991
  189. SQL_PORT=127.0.0.1:13306
  190. SOLR_PORT=127.0.0.1:18983
  191. REDIS_PORT=127.0.0.1:7654
  192. # Your timezone
  193. # See https://en.wikipedia.org/wiki/List_of_tz_database_time_zones for a list of timezones
  194. # Use the row named 'TZ database name' + pay attention for 'Notes' row
  195. TZ=${MAILCOW_TZ}
  196. # Fixed project name
  197. # Please use lowercase letters only
  198. COMPOSE_PROJECT_NAME=mailcowdockerized
  199. # Used Docker Compose version
  200. # Switch here between native (compose plugin) and standalone
  201. # For more informations take a look at the mailcow docs regarding the configuration options.
  202. # Normally this should be untouched but if you decided to use either of those you can switch it manually here.
  203. # Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail.
  204. DOCKER_COMPOSE_VERSION=${COMPOSE_VERSION}
  205. # Set this to "allow" to enable the anyone pseudo user. Disabled by default.
  206. # When enabled, ACL can be created, that apply to "All authenticated users"
  207. # This should probably only be activated on mail hosts, that are used exclusivly by one organisation.
  208. # Otherwise a user might share data with too many other users.
  209. ACL_ANYONE=disallow
  210. # Garbage collector cleanup
  211. # Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring
  212. # How long should objects remain in the garbage until they are being deleted? (value in minutes)
  213. # Check interval is hourly
  214. MAILDIR_GC_TIME=7200
  215. # Additional SAN for the certificate
  216. #
  217. # You can use wildcard records to create specific names for every domain you add to mailcow.
  218. # Example: Add domains "example.com" and "example.net" to mailcow, change ADDITIONAL_SAN to a value like:
  219. #ADDITIONAL_SAN=imap.*,smtp.*
  220. # This will expand the certificate to "imap.example.com", "smtp.example.com", "imap.example.net", "smtp.example.net"
  221. # plus every domain you add in the future.
  222. #
  223. # You can also just add static names...
  224. #ADDITIONAL_SAN=srv1.example.net
  225. # ...or combine wildcard and static names:
  226. #ADDITIONAL_SAN=imap.*,srv1.example.com
  227. #
  228. ADDITIONAL_SAN=
  229. # Additional server names for mailcow UI
  230. #
  231. # Specify alternative addresses for the mailcow UI to respond to
  232. # This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.
  233. # If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.
  234. # You can understand this as server_name directive in Nginx.
  235. # Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f
  236. ADDITIONAL_SERVER_NAMES=
  237. # Skip running ACME (acme-mailcow, Let's Encrypt certs) - y/n
  238. SKIP_LETS_ENCRYPT=n
  239. # Create seperate certificates for all domains - y/n
  240. # this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames
  241. # see https://wiki.dovecot.org/SSL/SNIClientSupport
  242. ENABLE_SSL_SNI=n
  243. # Skip IPv4 check in ACME container - y/n
  244. SKIP_IP_CHECK=n
  245. # Skip HTTP verification in ACME container - y/n
  246. SKIP_HTTP_VERIFICATION=n
  247. # Skip ClamAV (clamd-mailcow) anti-virus (Rspamd will auto-detect a missing ClamAV container) - y/n
  248. SKIP_CLAMD=${SKIP_CLAMD}
  249. # Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n
  250. SKIP_SOGO=n
  251. # Skip Solr on low-memory systems or if you do not want to store a readable index of your mails in solr-vol-1.
  252. SKIP_SOLR=${SKIP_SOLR}
  253. # Solr heap size in MB, there is no recommendation, please see Solr docs.
  254. # Solr is a prone to run OOM and should be monitored. Unmonitored Solr setups are not recommended.
  255. SOLR_HEAP=1024
  256. # Allow admins to log into SOGo as email user (without any password)
  257. ALLOW_ADMIN_EMAIL_LOGIN=n
  258. # Enable watchdog (watchdog-mailcow) to restart unhealthy containers
  259. USE_WATCHDOG=y
  260. # Send watchdog notifications by mail (sent from watchdog@MAILCOW_HOSTNAME)
  261. # CAUTION:
  262. # 1. You should use external recipients
  263. # 2. Mails are sent unsigned (no DKIM)
  264. # 3. If you use DMARC, create a separate DMARC policy ("v=DMARC1; p=none;" in _dmarc.MAILCOW_HOSTNAME)
  265. # Multiple rcpts allowed, NO quotation marks, NO spaces
  266. #WATCHDOG_NOTIFY_EMAIL=a@example.com,b@example.com,c@example.com
  267. #WATCHDOG_NOTIFY_EMAIL=
  268. # Notify about banned IP (includes whois lookup)
  269. WATCHDOG_NOTIFY_BAN=n
  270. # Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.
  271. #WATCHDOG_SUBJECT=
  272. # Checks if mailcow is an open relay. Requires a SAL. More checks will follow.
  273. # https://www.servercow.de/mailcow?lang=en
  274. # https://www.servercow.de/mailcow?lang=de
  275. # No data is collected. Opt-in and anonymous.
  276. # Will only work with unmodified mailcow setups.
  277. WATCHDOG_EXTERNAL_CHECKS=n
  278. # Enable watchdog verbose logging
  279. WATCHDOG_VERBOSE=n
  280. # Max log lines per service to keep in Redis logs
  281. LOG_LINES=9999
  282. # Internal IPv4 /24 subnet, format n.n.n (expands to n.n.n.0/24)
  283. # Use private IPv4 addresses only, see https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses
  284. IPV4_NETWORK=172.22.1
  285. # Internal IPv6 subnet in fc00::/7
  286. # Use private IPv6 addresses only, see https://en.wikipedia.org/wiki/Private_network#Private_IPv6_addresses
  287. IPV6_NETWORK=fd4d:6169:6c63:6f77::/64
  288. # Use this IPv4 for outgoing connections (SNAT)
  289. #SNAT_TO_SOURCE=
  290. # Use this IPv6 for outgoing connections (SNAT)
  291. #SNAT6_TO_SOURCE=
  292. # Create or override an API key for the web UI
  293. # You _must_ define API_ALLOW_FROM, which is a comma separated list of IPs
  294. # An API key defined as API_KEY has read-write access
  295. # An API key defined as API_KEY_READ_ONLY has read-only access
  296. # Allowed chars for API_KEY and API_KEY_READ_ONLY: a-z, A-Z, 0-9, -
  297. # You can define API_KEY and/or API_KEY_READ_ONLY
  298. #API_KEY=
  299. #API_KEY_READ_ONLY=
  300. #API_ALLOW_FROM=172.22.1.1,127.0.0.1
  301. # mail_home is ~/Maildir
  302. MAILDIR_SUB=Maildir
  303. # SOGo session timeout in minutes
  304. SOGO_EXPIRE_SESSION=480
  305. # DOVECOT_MASTER_USER and DOVECOT_MASTER_PASS must both be provided. No special chars.
  306. # Empty by default to auto-generate master user and password on start.
  307. # User expands to DOVECOT_MASTER_USER@mailcow.local
  308. # LEAVE EMPTY IF UNSURE
  309. DOVECOT_MASTER_USER=
  310. # LEAVE EMPTY IF UNSURE
  311. DOVECOT_MASTER_PASS=
  312. # Let's Encrypt registration contact information
  313. # Optional: Leave empty for none
  314. # This value is only used on first order!
  315. # Setting it at a later point will require the following steps:
  316. # https://mailcow.github.io/mailcow-dockerized-docs/troubleshooting/debug-reset_tls/
  317. ACME_CONTACT=
  318. # WebAuthn device manufacturer verification
  319. # After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed
  320. # root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates
  321. WEBAUTHN_ONLY_TRUSTED_VENDORS=n
  322. EOF
  323. mkdir -p data/assets/ssl
  324. chmod 600 mailcow.conf
  325. # copy but don't overwrite existing certificate
  326. echo "Generating snake-oil certificate..."
  327. # Making Willich more popular
  328. openssl req -x509 -newkey rsa:4096 -keyout data/assets/ssl-example/key.pem -out data/assets/ssl-example/cert.pem -days 365 -subj "/C=DE/ST=NRW/L=Willich/O=mailcow/OU=mailcow/CN=${MAILCOW_HOSTNAME}" -sha256 -nodes
  329. echo "Copying snake-oil certificate..."
  330. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  331. # Set app_info.inc.php
  332. if [ ${git_branch} == "master" ]; then
  333. mailcow_git_version=$(git describe --tags `git rev-list --tags --max-count=1`)
  334. elif [ ${git_branch} == "nightly" ]; then
  335. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  336. mailcow_last_git_version=""
  337. else
  338. mailcow_git_version=$(git rev-parse --short HEAD)
  339. mailcow_last_git_version=""
  340. fi
  341. mailcow_git_commit=$(git rev-parse origin/${git_branch})
  342. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  343. if [ $? -eq 0 ]; then
  344. echo '<?php' > data/web/inc/app_info.inc.php
  345. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  346. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  347. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  348. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  349. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  350. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  351. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  352. echo ' $MAILCOW_BRANCH="'$git_branch'";' >> data/web/inc/app_info.inc.php
  353. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  354. echo '?>' >> data/web/inc/app_info.inc.php
  355. else
  356. echo '<?php' > data/web/inc/app_info.inc.php
  357. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  358. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  359. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  360. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  361. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  362. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  363. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  364. echo ' $MAILCOW_BRANCH="'$git_branch'";' >> data/web/inc/app_info.inc.php
  365. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  366. echo '?>' >> data/web/inc/app_info.inc.php
  367. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  368. fi