update.sh 76 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647
  1. #!/usr/bin/env bash
  2. ############## Begin Function Section ##############
  3. check_online_status() {
  4. CHECK_ONLINE_DOMAINS=('https://github.com' 'https://hub.docker.com')
  5. for domain in "${CHECK_ONLINE_DOMAINS[@]}"; do
  6. if timeout 6 curl --head --silent --output /dev/null ${domain}; then
  7. return 0
  8. fi
  9. done
  10. return 1
  11. }
  12. prefetch_images() {
  13. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  14. git fetch origin #${BRANCH}
  15. while read image; do
  16. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  17. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  18. continue
  19. fi
  20. fi
  21. RET_C=0
  22. until docker pull "${image}"; do
  23. RET_C=$((RET_C + 1))
  24. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  25. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  26. sleep 1
  27. done
  28. done < <(git show "origin/${BRANCH}:docker-compose.yml" | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  29. }
  30. docker_garbage() {
  31. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  32. IMGS_TO_DELETE=()
  33. declare -A IMAGES_INFO
  34. COMPOSE_IMAGES=($(grep -oP "image: \K(ghcr\.io/)?mailcow.+" "${SCRIPT_DIR}/docker-compose.yml"))
  35. for existing_image in $(docker images --format "{{.ID}}:{{.Repository}}:{{.Tag}}" | grep -E '(mailcow/|ghcr\.io/mailcow/)'); do
  36. ID=$(echo "$existing_image" | cut -d ':' -f 1)
  37. REPOSITORY=$(echo "$existing_image" | cut -d ':' -f 2)
  38. TAG=$(echo "$existing_image" | cut -d ':' -f 3)
  39. if [[ "$REPOSITORY" == "mailcow/backup" || "$REPOSITORY" == "ghcr.io/mailcow/backup" ]]; then
  40. if [[ "$TAG" != "<none>" ]]; then
  41. continue
  42. fi
  43. fi
  44. if [[ " ${COMPOSE_IMAGES[@]} " =~ " ${REPOSITORY}:${TAG} " ]]; then
  45. continue
  46. else
  47. IMGS_TO_DELETE+=("$ID")
  48. IMAGES_INFO["$ID"]="$REPOSITORY:$TAG"
  49. fi
  50. done
  51. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  52. echo "The following unused mailcow images were found:"
  53. for id in "${IMGS_TO_DELETE[@]}"; do
  54. echo " ${IMAGES_INFO[$id]} ($id)"
  55. done
  56. if [ -z "$FORCE" ]; then
  57. read -r -p "Do you want to delete them to free up some space? [y/N] " response
  58. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  59. docker rmi ${IMGS_TO_DELETE[*]}
  60. else
  61. echo "OK, skipped."
  62. fi
  63. else
  64. echo "Running in forced mode! Force removing old mailcow images..."
  65. docker rmi ${IMGS_TO_DELETE[*]}
  66. fi
  67. echo -e "\e[32mFurther cleanup...\e[0m"
  68. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  69. fi
  70. }
  71. in_array() {
  72. local e match="$1"
  73. shift
  74. for e; do [[ "$e" == "$match" ]] && return 0; done
  75. return 1
  76. }
  77. migrate_docker_nat() {
  78. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  79. # Min Docker version
  80. DOCKERV_REQ=20.10.2
  81. # Current Docker version
  82. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  83. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  84. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  85. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  86. echo '!!! This step is recommended !!!'
  87. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  88. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  89. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  90. echo "OK, skipping this step."
  91. return 0
  92. fi
  93. fi
  94. # Sort versions and check if we are running a newer or equal version to req
  95. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  96. # If Dockerd daemon json exists
  97. if [ -s /etc/docker/daemon.json ]; then
  98. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  99. if ! in_array ipv6true "${dockerconfig[@]}" || \
  100. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  101. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  102. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  103. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  104. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  105. echo -e "Please merge the following content and restart the Docker daemon:\n"
  106. echo "${NAT_CONFIG}"
  107. return 1
  108. fi
  109. else
  110. echo "Working on IPv6 NAT, please wait..."
  111. echo "${NAT_CONFIG}" > /etc/docker/daemon.json
  112. ip6tables -F -t nat
  113. [[ -e /etc/rc.conf ]] && rc-service docker restart || systemctl restart docker.service
  114. if [[ $? -ne 0 ]]; then
  115. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  116. rm /etc/docker/daemon.json
  117. if [[ -e /etc/rc.conf ]]; then
  118. rc-service docker restart
  119. else
  120. systemctl reset-failed docker.service
  121. systemctl restart docker.service
  122. fi
  123. return 1
  124. fi
  125. fi
  126. # Removing legacy container
  127. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  128. if [ -s docker-compose.override.yml ]; then
  129. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  130. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  131. mv docker-compose.override.yml docker-compose.override.yml_backup
  132. fi
  133. fi
  134. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  135. else
  136. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  137. return 0
  138. fi
  139. }
  140. remove_obsolete_nginx_ports() {
  141. # Removing obsolete docker-compose.override.yml
  142. for override in docker-compose.override.yml docker-compose.override.yaml; do
  143. if [ -s $override ] ; then
  144. if cat $override | grep nginx-mailcow > /dev/null 2>&1; then
  145. if cat $override | grep -E '(\[::])' > /dev/null 2>&1; then
  146. if cat $override | grep -w 80:80 > /dev/null 2>&1 && cat $override | grep -w 443:443 > /dev/null 2>&1 ; then
  147. echo -e "\e[33mBacking up ${override} to preserve custom changes...\e[0m"
  148. echo -e "\e[33m!!! Manual Merge needed (if other overrides are set) !!!\e[0m"
  149. sleep 3
  150. cp $override ${override}_backup
  151. sed -i '/nginx-mailcow:$/,/^$/d' $override
  152. echo -e "\e[33mRemoved obsolete NGINX IPv6 Bind from original override File.\e[0m"
  153. if [[ "$(cat $override | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  154. mv $override ${override}_empty
  155. echo -e "\e[31m${override} is empty. Renamed it to ensure mailcow is startable.\e[0m"
  156. fi
  157. fi
  158. fi
  159. fi
  160. fi
  161. done
  162. }
  163. detect_docker_compose_command(){
  164. if ! [[ "${DOCKER_COMPOSE_VERSION}" =~ ^(native|standalone)$ ]]; then
  165. if docker compose > /dev/null 2>&1; then
  166. if docker compose version --short | grep -e "^2." -e "^v2." > /dev/null 2>&1; then
  167. DOCKER_COMPOSE_VERSION=native
  168. COMPOSE_COMMAND="docker compose"
  169. echo -e "\e[33mFound Docker Compose Plugin (native).\e[0m"
  170. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  171. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' "$SCRIPT_DIR/mailcow.conf"
  172. sleep 2
  173. echo -e "\e[33mNotice: You'll have to update this Compose Version via your Package Manager manually!\e[0m"
  174. else
  175. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  176. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  177. exit 1
  178. fi
  179. elif docker-compose > /dev/null 2>&1; then
  180. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  181. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  182. DOCKER_COMPOSE_VERSION=standalone
  183. COMPOSE_COMMAND="docker-compose"
  184. echo -e "\e[33mFound Docker Compose Standalone.\e[0m"
  185. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  186. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' "$SCRIPT_DIR/mailcow.conf"
  187. sleep 2
  188. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  189. else
  190. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  191. echo -e "\e[31mPlease update/install regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  192. exit 1
  193. fi
  194. fi
  195. else
  196. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  197. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  198. exit 1
  199. fi
  200. elif [ "${DOCKER_COMPOSE_VERSION}" == "native" ]; then
  201. COMPOSE_COMMAND="docker compose"
  202. # Check if Native Compose works and has not been deleted
  203. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  204. # IF it not exists/work anymore try the other command
  205. COMPOSE_COMMAND="docker-compose"
  206. if ! $COMPOSE_COMMAND > /dev/null 2>&1 || ! $COMPOSE_COMMAND --version | grep "^2." > /dev/null 2>&1; then
  207. # IF it cannot find Standalone in > 2.X, then script stops
  208. echo -e "\e[31mCannot find Docker Compose or the Version is lower then 2.X.X.\e[0m"
  209. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  210. exit 1
  211. fi
  212. # If it finds the standalone Plugin it will use this instead and change the mailcow.conf Variable accordingly
  213. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  214. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from native to standalone\e[0m"
  215. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' "$SCRIPT_DIR/mailcow.conf"
  216. sleep 2
  217. fi
  218. elif [ "${DOCKER_COMPOSE_VERSION}" == "standalone" ]; then
  219. COMPOSE_COMMAND="docker-compose"
  220. # Check if Standalone Compose works and has not been deleted
  221. if ! $COMPOSE_COMMAND > /dev/null 2>&1 && ! $COMPOSE_COMMAND --version > /dev/null 2>&1 | grep "^2." > /dev/null 2>&1; then
  222. # IF it not exists/work anymore try the other command
  223. COMPOSE_COMMAND="docker compose"
  224. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  225. # IF it cannot find Native in > 2.X, then script stops
  226. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  227. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  228. exit 1
  229. fi
  230. # If it finds the native Plugin it will use this instead and change the mailcow.conf Variable accordingly
  231. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  232. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from standalone to native\e[0m"
  233. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' "$SCRIPT_DIR/mailcow.conf"
  234. sleep 2
  235. fi
  236. fi
  237. }
  238. detect_bad_asn() {
  239. echo -e "\e[33mDetecting if your IP is listed on Spamhaus Bad ASN List...\e[0m"
  240. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  241. if [ "$response" -eq 503 ]; then
  242. if [ -z "$SPAMHAUS_DQS_KEY" ]; then
  243. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  244. echo -e "\e[33mmailcow did not detected a value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf!\e[0m"
  245. sleep 2
  246. echo ""
  247. echo -e "\e[33mTo use the Spamhaus DNS Blocklists again, you will need to create a FREE account for their Data Query Service (DQS) at: https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account\e[0m"
  248. echo -e "\e[33mOnce done, enter your DQS API key in mailcow.conf and mailcow will do the rest for you!\e[0m"
  249. echo ""
  250. sleep 2
  251. else
  252. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  253. echo -e "\e[32mmailcow detected a Value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf. Postfix will use DQS with the given API key...\e[0m"
  254. fi
  255. elif [ "$response" -eq 200 ]; then
  256. echo -e "\e[33mCheck completed! Your IP is \e[32mclean\e[0m"
  257. elif [ "$response" -eq 429 ]; then
  258. echo -e "\e[33mCheck completed! \e[31mYour IP seems to be rate limited on the ASN Check service... please try again later!\e[0m"
  259. else
  260. echo -e "\e[31mCheck failed! \e[0mMaybe a DNS or Network problem?\e[0m"
  261. fi
  262. }
  263. fix_broken_dnslist_conf() {
  264. # Fixing issue: #6143. To be removed in a later patch
  265. local file="${SCRIPT_DIR}/data/conf/postfix/dns_blocklists.cf"
  266. # Check if the file exists
  267. if [[ ! -f "$file" ]]; then
  268. return 1
  269. fi
  270. # Check if the file contains the autogenerated comment
  271. if grep -q "# Autogenerated by mailcow" "$file"; then
  272. # Ask the user if custom changes were made
  273. echo -e "\e[91mWARNING!!! \e[31mAn old version of dns_blocklists.cf has been detected which may cause a broken postfix upon startup (see: https://github.com/mailcow/mailcow-dockerized/issues/6143)...\e[0m"
  274. echo -e "\e[31mIf you have any custom settings in there you might copy it away and adapt the changes after the file is regenerated...\e[0m"
  275. read -p "Do you want to delete the file now and let mailcow regenerate it properly? [y/n]" response
  276. if [[ "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  277. rm "$file"
  278. echo -e "\e[32mdns_blocklists.cf has been deleted and will be properly regenerated"
  279. return 0
  280. else
  281. echo -e "\e[35mOk, not deleting it! Please make sure you take a look at postfix upon start then..."
  282. return 2
  283. fi
  284. fi
  285. }
  286. adapt_new_options() {
  287. CONFIG_ARRAY=(
  288. "SKIP_LETS_ENCRYPT"
  289. "SKIP_SOGO"
  290. "USE_WATCHDOG"
  291. "WATCHDOG_NOTIFY_EMAIL"
  292. "WATCHDOG_NOTIFY_WEBHOOK"
  293. "WATCHDOG_NOTIFY_WEBHOOK_BODY"
  294. "WATCHDOG_NOTIFY_BAN"
  295. "WATCHDOG_NOTIFY_START"
  296. "WATCHDOG_EXTERNAL_CHECKS"
  297. "WATCHDOG_SUBJECT"
  298. "SKIP_CLAMD"
  299. "SKIP_OLEFY"
  300. "SKIP_IP_CHECK"
  301. "ADDITIONAL_SAN"
  302. "DOVEADM_PORT"
  303. "IPV4_NETWORK"
  304. "IPV6_NETWORK"
  305. "LOG_LINES"
  306. "SNAT_TO_SOURCE"
  307. "SNAT6_TO_SOURCE"
  308. "COMPOSE_PROJECT_NAME"
  309. "DOCKER_COMPOSE_VERSION"
  310. "SQL_PORT"
  311. "API_KEY"
  312. "API_KEY_READ_ONLY"
  313. "API_ALLOW_FROM"
  314. "MAILDIR_GC_TIME"
  315. "MAILDIR_SUB"
  316. "ACL_ANYONE"
  317. "FTS_HEAP"
  318. "FTS_PROCS"
  319. "SKIP_FTS"
  320. "ENABLE_SSL_SNI"
  321. "ALLOW_ADMIN_EMAIL_LOGIN"
  322. "SKIP_HTTP_VERIFICATION"
  323. "SOGO_EXPIRE_SESSION"
  324. "REDIS_PORT"
  325. "DOVECOT_MASTER_USER"
  326. "DOVECOT_MASTER_PASS"
  327. "MAILCOW_PASS_SCHEME"
  328. "ADDITIONAL_SERVER_NAMES"
  329. "WATCHDOG_VERBOSE"
  330. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  331. "SPAMHAUS_DQS_KEY"
  332. "SKIP_UNBOUND_HEALTHCHECK"
  333. "DISABLE_NETFILTER_ISOLATION_RULE"
  334. "HTTP_REDIRECT"
  335. )
  336. sed -i --follow-symlinks '$a\' mailcow.conf
  337. for option in ${CONFIG_ARRAY[@]}; do
  338. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  339. if ! grep -q ${option} mailcow.conf; then
  340. echo "Adding new option \"${option}\" to mailcow.conf"
  341. echo "${option}=" >> mailcow.conf
  342. fi
  343. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  344. if ! grep -q ${option} mailcow.conf; then
  345. echo "Adding new option \"${option}\" to mailcow.conf"
  346. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  347. fi
  348. elif [[ ${option} == "DOCKER_COMPOSE_VERSION" ]]; then
  349. if ! grep -q ${option} mailcow.conf; then
  350. echo "Adding new option \"${option}\" to mailcow.conf"
  351. echo "# Used Docker Compose version" >> mailcow.conf
  352. echo "# Switch here between native (compose plugin) and standalone" >> mailcow.conf
  353. echo "# For more informations take a look at the mailcow docs regarding the configuration options." >> mailcow.conf
  354. echo "# Normally this should be untouched but if you decided to use either of those you can switch it manually here." >> mailcow.conf
  355. echo "# Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail." >> mailcow.conf
  356. echo "" >> mailcow.conf
  357. echo "DOCKER_COMPOSE_VERSION=${DOCKER_COMPOSE_VERSION}" >> mailcow.conf
  358. fi
  359. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  360. if ! grep -q ${option} mailcow.conf; then
  361. echo "Adding new option \"${option}\" to mailcow.conf"
  362. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  363. fi
  364. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  365. if ! grep -q ${option} mailcow.conf; then
  366. echo "Adding new option \"${option}\" to mailcow.conf"
  367. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  368. fi
  369. elif [[ ${option} == "LOG_LINES" ]]; then
  370. if ! grep -q ${option} mailcow.conf; then
  371. echo "Adding new option \"${option}\" to mailcow.conf"
  372. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  373. echo "LOG_LINES=9999" >> mailcow.conf
  374. fi
  375. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  376. if ! grep -q ${option} mailcow.conf; then
  377. echo "Adding new option \"${option}\" to mailcow.conf"
  378. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  379. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  380. fi
  381. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  382. if ! grep -q ${option} mailcow.conf; then
  383. echo "Adding new option \"${option}\" to mailcow.conf"
  384. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  385. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  386. fi
  387. elif [[ ${option} == "SQL_PORT" ]]; then
  388. if ! grep -q ${option} mailcow.conf; then
  389. echo "Adding new option \"${option}\" to mailcow.conf"
  390. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  391. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  392. fi
  393. elif [[ ${option} == "API_KEY" ]]; then
  394. if ! grep -q ${option} mailcow.conf; then
  395. echo "Adding new option \"${option}\" to mailcow.conf"
  396. echo '# Create or override API key for web UI' >> mailcow.conf
  397. echo "#API_KEY=" >> mailcow.conf
  398. fi
  399. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  400. if ! grep -q ${option} mailcow.conf; then
  401. echo "Adding new option \"${option}\" to mailcow.conf"
  402. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  403. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  404. fi
  405. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  406. if ! grep -q ${option} mailcow.conf; then
  407. echo "Adding new option \"${option}\" to mailcow.conf"
  408. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  409. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  410. echo "#API_ALLOW_FROM=" >> mailcow.conf
  411. fi
  412. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  413. if ! grep -q ${option} mailcow.conf; then
  414. echo "Adding new option \"${option}\" to mailcow.conf"
  415. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  416. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  417. fi
  418. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  419. if ! grep -q ${option} mailcow.conf; then
  420. echo "Adding new option \"${option}\" to mailcow.conf"
  421. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  422. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  423. fi
  424. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  425. if ! grep -q ${option} mailcow.conf; then
  426. echo "Adding new option \"${option}\" to mailcow.conf"
  427. echo '# Garbage collector cleanup' >> mailcow.conf
  428. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  429. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  430. echo '# Check interval is hourly' >> mailcow.conf
  431. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  432. fi
  433. elif [[ ${option} == "ACL_ANYONE" ]]; then
  434. if ! grep -q ${option} mailcow.conf; then
  435. echo "Adding new option \"${option}\" to mailcow.conf"
  436. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  437. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  438. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  439. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  440. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  441. fi
  442. elif [[ ${option} == "FTS_HEAP" ]]; then
  443. if ! grep -q ${option} mailcow.conf; then
  444. echo "Adding new option \"${option}\" to mailcow.conf"
  445. echo '# Dovecot Indexing (FTS) Process maximum heap size in MB, there is no recommendation, please see Dovecot docs.' >> mailcow.conf
  446. echo '# Flatcurve is used as FTS Engine. It is supposed to be pretty efficient in CPU and RAM consumption.' >> mailcow.conf
  447. echo '# Please always monitor your Resource consumption!' >> mailcow.conf
  448. echo "FTS_HEAP=128" >> mailcow.conf
  449. fi
  450. elif [[ ${option} == "SKIP_FTS" ]]; then
  451. if ! grep -q ${option} mailcow.conf; then
  452. echo "Adding new option \"${option}\" to mailcow.conf"
  453. echo '# Skip FTS (Fulltext Search) for Dovecot on low-memory, low-threaded systems or if you simply want to disable it.' >> mailcow.conf
  454. echo "# Dovecot inside mailcow use Flatcurve as FTS Backend." >> mailcow.conf
  455. echo "SKIP_FTS=y" >> mailcow.conf
  456. fi
  457. elif [[ ${option} == "FTS_PROCS" ]]; then
  458. if ! grep -q ${option} mailcow.conf; then
  459. echo "Adding new option \"${option}\" to mailcow.conf"
  460. echo '# Controls how many processes the Dovecot indexing process can spawn at max.' >> mailcow.conf
  461. echo '# Too many indexing processes can use a lot of CPU and Disk I/O' >> mailcow.conf
  462. echo '# Please visit: https://doc.dovecot.org/configuration_manual/service_configuration/#indexer-worker for more informations' >> mailcow.conf
  463. echo "FTS_PROCS=1" >> mailcow.conf
  464. fi
  465. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  466. if ! grep -q ${option} mailcow.conf; then
  467. echo "Adding new option \"${option}\" to mailcow.conf"
  468. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  469. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  470. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  471. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  472. fi
  473. elif [[ ${option} == "SKIP_SOGO" ]]; then
  474. if ! grep -q ${option} mailcow.conf; then
  475. echo "Adding new option \"${option}\" to mailcow.conf"
  476. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  477. echo "SKIP_SOGO=n" >> mailcow.conf
  478. fi
  479. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  480. if ! grep -q ${option} mailcow.conf; then
  481. echo "Adding new option \"${option}\" to mailcow.conf"
  482. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  483. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  484. echo "MAILDIR_SUB=" >> mailcow.conf
  485. fi
  486. elif [[ ${option} == "WATCHDOG_NOTIFY_WEBHOOK" ]]; then
  487. if ! grep -q ${option} mailcow.conf; then
  488. echo "Adding new option \"${option}\" to mailcow.conf"
  489. echo '# Send notifications to a webhook URL that receives a POST request with the content type "application/json".' >> mailcow.conf
  490. echo '# You can use this to send notifications to services like Discord, Slack and others.' >> mailcow.conf
  491. echo '#WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX' >> mailcow.conf
  492. fi
  493. elif [[ ${option} == "WATCHDOG_NOTIFY_WEBHOOK_BODY" ]]; then
  494. if ! grep -q ${option} mailcow.conf; then
  495. echo "Adding new option \"${option}\" to mailcow.conf"
  496. echo '# JSON body included in the webhook POST request. Needs to be in single quotes.' >> mailcow.conf
  497. echo '# Following variables are available: SUBJECT, BODY' >> mailcow.conf
  498. WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  499. echo "#WATCHDOG_NOTIFY_WEBHOOK_BODY='${WEBHOOK_BODY}'" >> mailcow.conf
  500. fi
  501. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  502. if ! grep -q ${option} mailcow.conf; then
  503. echo "Adding new option \"${option}\" to mailcow.conf"
  504. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  505. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  506. fi
  507. elif [[ ${option} == "WATCHDOG_NOTIFY_START" ]]; then
  508. if ! grep -q ${option} mailcow.conf; then
  509. echo "Adding new option \"${option}\" to mailcow.conf"
  510. echo '# Send a notification when the watchdog is started.' >> mailcow.conf
  511. echo "WATCHDOG_NOTIFY_START=y" >> mailcow.conf
  512. fi
  513. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  514. if ! grep -q ${option} mailcow.conf; then
  515. echo "Adding new option \"${option}\" to mailcow.conf"
  516. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  517. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  518. fi
  519. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  520. if ! grep -q ${option} mailcow.conf; then
  521. echo "Adding new option \"${option}\" to mailcow.conf"
  522. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  523. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  524. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  525. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  526. fi
  527. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  528. if ! grep -q ${option} mailcow.conf; then
  529. echo "Adding new option \"${option}\" to mailcow.conf"
  530. echo '# SOGo session timeout in minutes' >> mailcow.conf
  531. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  532. fi
  533. elif [[ ${option} == "REDIS_PORT" ]]; then
  534. if ! grep -q ${option} mailcow.conf; then
  535. echo "Adding new option \"${option}\" to mailcow.conf"
  536. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  537. fi
  538. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  539. if ! grep -q ${option} mailcow.conf; then
  540. echo "Adding new option \"${option}\" to mailcow.conf"
  541. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  542. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  543. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  544. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  545. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  546. fi
  547. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  548. if ! grep -q ${option} mailcow.conf; then
  549. echo "Adding new option \"${option}\" to mailcow.conf"
  550. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  551. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  552. fi
  553. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  554. if ! grep -q ${option} mailcow.conf; then
  555. echo "Adding new option \"${option}\" to mailcow.conf"
  556. echo '# Password hash algorithm' >> mailcow.conf
  557. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  558. echo '# see https://docs.mailcow.email/models/model-passwd/' >> mailcow.conf
  559. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  560. fi
  561. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  562. if ! grep -q ${option} mailcow.conf; then
  563. echo "Adding new option \"${option}\" to mailcow.conf"
  564. echo '# Additional server names for mailcow UI' >> mailcow.conf
  565. echo '#' >> mailcow.conf
  566. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  567. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  568. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  569. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  570. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  571. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  572. fi
  573. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  574. if ! grep -q ${option} mailcow.conf; then
  575. echo "Adding new option \"${option}\" to mailcow.conf"
  576. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  577. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  578. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  579. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  580. fi
  581. elif [[ ${option} == "SPAMHAUS_DQS_KEY" ]]; then
  582. if ! grep -q ${option} mailcow.conf; then
  583. echo "Adding new option \"${option}\" to mailcow.conf"
  584. echo "# Spamhaus Data Query Service Key" >> mailcow.conf
  585. echo '# Optional: Leave empty for none' >> mailcow.conf
  586. echo '# Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.' >> mailcow.conf
  587. echo '# If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.' >> mailcow.conf
  588. echo '# Otherwise it will work as usual.' >> mailcow.conf
  589. echo 'SPAMHAUS_DQS_KEY=' >> mailcow.conf
  590. fi
  591. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  592. if ! grep -q ${option} mailcow.conf; then
  593. echo "Adding new option \"${option}\" to mailcow.conf"
  594. echo '# Enable watchdog verbose logging' >> mailcow.conf
  595. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  596. fi
  597. elif [[ ${option} == "SKIP_UNBOUND_HEALTHCHECK" ]]; then
  598. if ! grep -q ${option} mailcow.conf; then
  599. echo "Adding new option \"${option}\" to mailcow.conf"
  600. echo '# Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n' >> mailcow.conf
  601. echo 'SKIP_UNBOUND_HEALTHCHECK=n' >> mailcow.conf
  602. fi
  603. elif [[ ${option} == "DISABLE_NETFILTER_ISOLATION_RULE" ]]; then
  604. if ! grep -q ${option} mailcow.conf; then
  605. echo "Adding new option \"${option}\" to mailcow.conf"
  606. echo '# Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n' >> mailcow.conf
  607. echo '# CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost' >> mailcow.conf
  608. echo 'DISABLE_NETFILTER_ISOLATION_RULE=n' >> mailcow.conf
  609. fi
  610. elif [[ ${option} == "HTTP_REDIRECT" ]]; then
  611. if ! grep -q ${option} mailcow.conf; then
  612. echo "Adding new option \"${option}\" to mailcow.conf"
  613. echo '# Redirect HTTP connections to HTTPS - y/n' >> mailcow.conf
  614. echo 'HTTP_REDIRECT=n' >> mailcow.conf
  615. fi
  616. elif ! grep -q ${option} mailcow.conf; then
  617. echo "Adding new option \"${option}\" to mailcow.conf"
  618. echo "${option}=n" >> mailcow.conf
  619. fi
  620. done
  621. }
  622. migrate_solr_config_options() {
  623. sed -i --follow-symlinks '$a\' mailcow.conf
  624. if grep -q "SOLR_HEAP" mailcow.conf; then
  625. echo "Removing SOLR_HEAP in mailcow.conf"
  626. sed -i '/# Solr heap size in MB\b/d' mailcow.conf
  627. sed -i '/# Solr is a prone to run\b/d' mailcow.conf
  628. sed -i '/SOLR_HEAP\b/d' mailcow.conf
  629. fi
  630. if grep -q "SKIP_SOLR" mailcow.conf; then
  631. echo "Removing SKIP_SOLR in mailcow.conf"
  632. sed -i '/\bSkip Solr on low-memory\b/d' mailcow.conf
  633. sed -i '/\bSolr is disabled by default\b/d' mailcow.conf
  634. sed -i '/\bDisable Solr or\b/d' mailcow.conf
  635. sed -i '/\bSKIP_SOLR\b/d' mailcow.conf
  636. fi
  637. if grep -q "SOLR_PORT" mailcow.conf; then
  638. echo "Removing SOLR_PORT in mailcow.conf"
  639. sed -i '/\bSOLR_PORT\b/d' mailcow.conf
  640. fi
  641. if grep -q "FLATCURVE_EXPERIMENTAL" mailcow.conf; then
  642. echo "Removing FLATCURVE_EXPERIMENTAL in mailcow.conf"
  643. sed -i '/\bFLATCURVE_EXPERIMENTAL\b/d' mailcow.conf
  644. fi
  645. solr_volume=$(docker volume ls -qf name=^${COMPOSE_PROJECT_NAME}_solr-vol-1)
  646. if [[ -n $solr_volume ]]; then
  647. echo -e "\e[34mSolr has been replaced within mailcow since 2025-01.\nThe volume $solr_volume is unused.\e[0m"
  648. sleep 1
  649. if [ ! "$FORCE" ]; then
  650. read -r -p "Remove $solr_volume? [y/N] " response
  651. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  652. echo -e "\e[33mRemoving $solr_volume...\e[0m"
  653. docker volume rm $solr_volume || echo -e "\e[31mFailed to remove. Remove it manually!\e[0m"
  654. echo -e "\e[32mSuccessfully removed $solr_volume!\e[0m"
  655. else
  656. echo -e "Not removing $solr_volume. Run \`docker volume rm $solr_volume\` manually if needed."
  657. fi
  658. else
  659. echo -e "\e[33mForce removing $solr_volume...\e[0m"
  660. docker volume rm $solr_volume || echo -e "\e[31mFailed to remove. Remove it manually!\e[0m"
  661. echo -e "\e[32mSuccessfully removed $solr_volume!\e[0m"
  662. fi
  663. fi
  664. # Delete old fts.conf before forced switch to flatcurve to ensure update is working properly
  665. FTS_CONF_PATH="${SCRIPT_DIR}/data/conf/dovecot/conf.d/fts.conf"
  666. if [[ -f "$FTS_CONF_PATH" ]]; then
  667. if grep -q "Autogenerated by mailcow" "$FTS_CONF_PATH"; then
  668. rm -rf $FTS_CONF_PATH
  669. fi
  670. fi
  671. }
  672. detect_major_update() {
  673. if [ ${BRANCH} == "master" ]; then
  674. # Array with major versions
  675. # Add major versions here
  676. MAJOR_VERSIONS=(
  677. "2025-02"
  678. "2025-03"
  679. )
  680. current_version=""
  681. if [[ -f "${SCRIPT_DIR}/data/web/inc/app_info.inc.php" ]]; then
  682. current_version=$(grep 'MAILCOW_GIT_VERSION' ${SCRIPT_DIR}/data/web/inc/app_info.inc.php | sed -E 's/.*MAILCOW_GIT_VERSION="([^"]+)".*/\1/')
  683. fi
  684. if [[ -z "$current_version" ]]; then
  685. return 1
  686. fi
  687. release_url="https://github.com/mailcow/mailcow-dockerized/releases/tag"
  688. updates_to_apply=()
  689. for version in "${MAJOR_VERSIONS[@]}"; do
  690. if [[ "$current_version" < "$version" ]]; then
  691. updates_to_apply+=("$version")
  692. fi
  693. done
  694. if [[ ${#updates_to_apply[@]} -gt 0 ]]; then
  695. echo -e "\e[33m\nMAJOR UPDATES to be applied:\e[0m"
  696. for update in "${updates_to_apply[@]}"; do
  697. echo "$update - $release_url/$update"
  698. done
  699. echo -e "\nPlease read the release notes before proceeding."
  700. read -p "Do you want to proceed with the update? [y/n] " response
  701. if [[ "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  702. echo "Proceeding with the update..."
  703. else
  704. echo "Update canceled. Exiting."
  705. exit 1
  706. fi
  707. fi
  708. fi
  709. }
  710. remove_obsolete_options() {
  711. OBSOLETE_OPTIONS=(
  712. "ACME_CONTACT"
  713. )
  714. for option in "${OBSOLETE_OPTIONS[@]}"; do
  715. if [[ "$option" == "ACME_CONTACT" ]]; then
  716. sed -i '/^# Lets Encrypt registration contact information/d' mailcow.conf
  717. sed -i "/^# Let's Encrypt registration contact information/d" mailcow.conf
  718. sed -i '/^# Optional: Leave empty for none/d' mailcow.conf
  719. sed -i '/^# This value is only used on first order!/d' mailcow.conf
  720. sed -i '/^# Setting it at a later point will require the following steps:/d' mailcow.conf
  721. sed -i '/^# https:\/\/docs.mailcow.email\/troubleshooting\/debug-reset_tls\//d' mailcow.conf
  722. sed -i '/^ACME_CONTACT=.*/d' mailcow.conf
  723. sed -i '/^#ACME_CONTACT=.*/d' mailcow.conf
  724. else
  725. sed -i "/^${option}=.*/d" mailcow.conf
  726. sed -i "/^#${option}=.*/d" mailcow.conf
  727. fi
  728. done
  729. }
  730. ############## End Function Section ##############
  731. # Check permissions
  732. if [ "$(id -u)" -ne "0" ]; then
  733. echo "You need to be root"
  734. exit 1
  735. fi
  736. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  737. # Run pre-update-hook
  738. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  739. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  740. fi
  741. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  742. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  743. echo "Please update to 5.x or use another distribution."
  744. exit 1
  745. fi
  746. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  747. if grep -q Ubuntu <<< "$(uname -a)"; then
  748. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  749. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  750. exit 1
  751. fi
  752. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  753. read -p "Press any key to continue..." < /dev/tty
  754. fi
  755. # Exit on error and pipefail
  756. set -o pipefail
  757. # Setting high dc timeout
  758. export COMPOSE_HTTP_TIMEOUT=600
  759. # Add /opt/bin to PATH
  760. PATH=$PATH:/opt/bin
  761. umask 0022
  762. # Unset COMPOSE_COMMAND and DOCKER_COMPOSE_VERSION Variable to be on the newest state.
  763. unset COMPOSE_COMMAND
  764. unset DOCKER_COMPOSE_VERSION
  765. for bin in curl docker git awk sha1sum grep cut; do
  766. if [[ -z $(command -v ${bin}) ]]; then
  767. echo "Cannot find ${bin}, exiting..."
  768. exit 1;
  769. fi
  770. done
  771. # Check Docker Version (need at least 24.X)
  772. docker_version=$(docker -v | grep -oP '\d+\.\d+\.\d+' | cut -d '.' -f 1 | head -1)
  773. if [[ $docker_version -lt 24 ]]; then
  774. echo -e "\e[31mCannot find Docker with a Version higher or equals 24.0.0\e[0m"
  775. echo -e "\e[33mmailcow needs a newer Docker version to work properly... continuing on your own risk!\e[0m"
  776. echo -e "\e[31mPlease update your Docker installation... sleeping 10s\e[0m"
  777. sleep 10
  778. fi
  779. export LC_ALL=C
  780. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  781. BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  782. while (($#)); do
  783. case "${1}" in
  784. --check|-c)
  785. echo "Checking remote code for updates..."
  786. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized "${BRANCH}" | cut -f1)
  787. if [ "$?" -ne 0 ]; then
  788. echo "A problem occurred while trying to fetch the latest revision from github."
  789. exit 99
  790. fi
  791. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  792. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  793. git log --date=short --pretty=format:"%ad - %s" "$(git rev-parse --short HEAD)"..origin/master
  794. exit 0
  795. else
  796. echo "No updates available."
  797. exit 3
  798. fi
  799. ;;
  800. --check-tags)
  801. echo "Checking remote tags for updates..."
  802. LATEST_TAG_REV=$(git ls-remote --exit-code --quiet --tags origin | tail -1 | cut -f1)
  803. if [ "$?" -ne 0 ]; then
  804. echo "A problem occurred while trying to fetch the latest tag from github."
  805. exit 99
  806. fi
  807. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_TAG_REV}") ]]; then
  808. echo -e "New tag is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/releases/latest"
  809. exit 0
  810. else
  811. echo "No updates available."
  812. exit 3
  813. fi
  814. ;;
  815. --ours)
  816. MERGE_STRATEGY=ours
  817. ;;
  818. --skip-start)
  819. SKIP_START=y
  820. ;;
  821. --skip-ping-check)
  822. SKIP_PING_CHECK=y
  823. ;;
  824. --stable)
  825. CURRENT_BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  826. NEW_BRANCH="master"
  827. ;;
  828. --gc)
  829. echo -e "\e[32mCollecting garbage...\e[0m"
  830. docker_garbage
  831. exit 0
  832. ;;
  833. --nightly)
  834. CURRENT_BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  835. NEW_BRANCH="nightly"
  836. ;;
  837. --prefetch)
  838. echo -e "\e[32mPrefetching images...\e[0m"
  839. prefetch_images
  840. exit 0
  841. ;;
  842. -f|--force)
  843. echo -e "\e[32mRunning in forced mode...\e[0m"
  844. FORCE=y
  845. ;;
  846. -d|--dev)
  847. echo -e "\e[32mRunning in Developer mode...\e[0m"
  848. DEV=y
  849. ;;
  850. --legacy)
  851. CURRENT_BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  852. NEW_BRANCH="legacy"
  853. ;;
  854. --help|-h)
  855. echo './update.sh [-c|--check, --check-tags, --ours, --gc, --nightly, --prefetch, --skip-start, --skip-ping-check, --stable, --legacy, -f|--force, -d|--dev, -h|--help]
  856. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  857. --check-tags - Check for newer tags and exit (exit codes => 0: newer tag available, 3: no newer tag)
  858. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  859. --gc - Run garbage collector to delete old image tags
  860. --nightly - Switch your mailcow updates to the unstable (nightly) branch. FOR TESTING PURPOSES ONLY!!!!
  861. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  862. --skip-start - Do not start mailcow after update
  863. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you'\''ve blocked any ICMP Connections to your mailcow machine)
  864. --stable - Switch your mailcow updates to the stable (master) branch. Default unless you changed it with --nightly or --legacy.
  865. --legacy - Switch your mailcow updates to the legacy branch. The legacy branch will only receive security updates until February 2026.
  866. -f|--force - Force update, do not ask questions
  867. -d|--dev - Enables Developer Mode (No Checkout of update.sh for tests)
  868. '
  869. exit 0
  870. esac
  871. shift
  872. done
  873. [[ ! -f mailcow.conf ]] && { echo -e "\e[31mmailcow.conf is missing! Is mailcow installed?\e[0m"; exit 1;}
  874. chmod 600 mailcow.conf
  875. source mailcow.conf
  876. detect_docker_compose_command
  877. fix_broken_dnslist_conf
  878. DOTS=${MAILCOW_HOSTNAME//[^.]};
  879. if [ ${#DOTS} -lt 1 ]; then
  880. echo -e "\e[31mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!\e[0m"
  881. sleep 1
  882. echo "Please change it to a FQDN and redeploy the stack with $COMPOSE_COMMAND up -d"
  883. exit 1
  884. elif [[ "${MAILCOW_HOSTNAME: -1}" == "." ]]; then
  885. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is ending with a dot. This is not a valid FQDN!"
  886. exit 1
  887. elif [ ${#DOTS} -eq 1 ]; then
  888. echo -e "\e[33mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) does not contain a Subdomain. This is not fully tested and may cause issues.\e[0m"
  889. echo "Find more information about why this message exists here: https://github.com/mailcow/mailcow-dockerized/issues/1572"
  890. read -r -p "Do you want to proceed anyway? [y/N] " response
  891. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  892. echo "OK. Proceeding."
  893. else
  894. echo "OK. Exiting."
  895. exit 1
  896. fi
  897. fi
  898. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  899. # This will also cover sort
  900. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  901. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  902. CONFIG_ARRAY=(
  903. "SKIP_LETS_ENCRYPT"
  904. "SKIP_SOGO"
  905. "USE_WATCHDOG"
  906. "WATCHDOG_NOTIFY_EMAIL"
  907. "WATCHDOG_NOTIFY_WEBHOOK"
  908. "WATCHDOG_NOTIFY_WEBHOOK_BODY"
  909. "WATCHDOG_NOTIFY_BAN"
  910. "WATCHDOG_NOTIFY_START"
  911. "WATCHDOG_EXTERNAL_CHECKS"
  912. "WATCHDOG_SUBJECT"
  913. "SKIP_CLAMD"
  914. "SKIP_OLEFY"
  915. "SKIP_IP_CHECK"
  916. "ADDITIONAL_SAN"
  917. "AUTODISCOVER_SAN"
  918. "DOVEADM_PORT"
  919. "IPV4_NETWORK"
  920. "IPV6_NETWORK"
  921. "LOG_LINES"
  922. "SNAT_TO_SOURCE"
  923. "SNAT6_TO_SOURCE"
  924. "COMPOSE_PROJECT_NAME"
  925. "DOCKER_COMPOSE_VERSION"
  926. "SQL_PORT"
  927. "API_KEY"
  928. "API_KEY_READ_ONLY"
  929. "API_ALLOW_FROM"
  930. "MAILDIR_GC_TIME"
  931. "MAILDIR_SUB"
  932. "ACL_ANYONE"
  933. "ENABLE_SSL_SNI"
  934. "ALLOW_ADMIN_EMAIL_LOGIN"
  935. "SKIP_HTTP_VERIFICATION"
  936. "SOGO_EXPIRE_SESSION"
  937. "REDIS_PORT"
  938. "DOVECOT_MASTER_USER"
  939. "DOVECOT_MASTER_PASS"
  940. "MAILCOW_PASS_SCHEME"
  941. "ADDITIONAL_SERVER_NAMES"
  942. "WATCHDOG_VERBOSE"
  943. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  944. "SPAMHAUS_DQS_KEY"
  945. "SKIP_UNBOUND_HEALTHCHECK"
  946. "DISABLE_NETFILTER_ISOLATION_RULE"
  947. "REDISPASS"
  948. )
  949. detect_bad_asn
  950. sed -i --follow-symlinks '$a\' mailcow.conf
  951. for option in "${CONFIG_ARRAY[@]}"; do
  952. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  953. if ! grep -q "${option}" mailcow.conf; then
  954. echo "Adding new option \"${option}\" to mailcow.conf"
  955. echo "${option}=" >> mailcow.conf
  956. fi
  957. elif [[ "${option}" == "COMPOSE_PROJECT_NAME" ]]; then
  958. if ! grep -q "${option}" mailcow.conf; then
  959. echo "Adding new option \"${option}\" to mailcow.conf"
  960. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  961. fi
  962. elif [[ "${option}" == "DOCKER_COMPOSE_VERSION" ]]; then
  963. if ! grep -q "${option}" mailcow.conf; then
  964. echo "Adding new option \"${option}\" to mailcow.conf"
  965. echo "# Used Docker Compose version" >> mailcow.conf
  966. echo "# Switch here between native (compose plugin) and standalone" >> mailcow.conf
  967. echo "# For more informations take a look at the mailcow docs regarding the configuration options." >> mailcow.conf
  968. echo "# Normally this should be untouched but if you decided to use either of those you can switch it manually here." >> mailcow.conf
  969. echo "# Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail." >> mailcow.conf
  970. echo "" >> mailcow.conf
  971. echo "DOCKER_COMPOSE_VERSION=${DOCKER_COMPOSE_VERSION}" >> mailcow.conf
  972. fi
  973. elif [[ "${option}" == "DOVEADM_PORT" ]]; then
  974. if ! grep -q "${option}" mailcow.conf; then
  975. echo "Adding new option \"${option}\" to mailcow.conf"
  976. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  977. fi
  978. elif [[ "${option}" == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  979. if ! grep -q "${option}" mailcow.conf; then
  980. echo "Adding new option \"${option}\" to mailcow.conf"
  981. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  982. fi
  983. elif [[ "${option}" == "LOG_LINES" ]]; then
  984. if ! grep -q "${option}" mailcow.conf; then
  985. echo "Adding new option \"${option}\" to mailcow.conf"
  986. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  987. echo "LOG_LINES=9999" >> mailcow.conf
  988. fi
  989. elif [[ "${option}" == "IPV4_NETWORK" ]]; then
  990. if ! grep -q "${option}" mailcow.conf; then
  991. echo "Adding new option \"${option}\" to mailcow.conf"
  992. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  993. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  994. fi
  995. elif [[ "${option}" == "IPV6_NETWORK" ]]; then
  996. if ! grep -q "${option}" mailcow.conf; then
  997. echo "Adding new option \"${option}\" to mailcow.conf"
  998. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  999. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  1000. fi
  1001. elif [[ "${option}" == "SQL_PORT" ]]; then
  1002. if ! grep -q "${option}" mailcow.conf; then
  1003. echo "Adding new option \"${option}\" to mailcow.conf"
  1004. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  1005. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  1006. fi
  1007. elif [[ "${option}" == "API_KEY" ]]; then
  1008. if ! grep -q "${option}" mailcow.conf; then
  1009. echo "Adding new option \"${option}\" to mailcow.conf"
  1010. echo '# Create or override API key for web UI' >> mailcow.conf
  1011. echo "#API_KEY=" >> mailcow.conf
  1012. fi
  1013. elif [[ "${option}" == "API_KEY_READ_ONLY" ]]; then
  1014. if ! grep -q "${option}" mailcow.conf; then
  1015. echo "Adding new option \"${option}\" to mailcow.conf"
  1016. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  1017. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  1018. fi
  1019. elif [[ "${option}" == "API_ALLOW_FROM" ]]; then
  1020. if ! grep -q "${option}" mailcow.conf; then
  1021. echo "Adding new option \"${option}\" to mailcow.conf"
  1022. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  1023. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  1024. echo "#API_ALLOW_FROM=" >> mailcow.conf
  1025. fi
  1026. elif [[ "${option}" == "SNAT_TO_SOURCE" ]]; then
  1027. if ! grep -q "${option}" mailcow.conf; then
  1028. echo "Adding new option \"${option}\" to mailcow.conf"
  1029. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  1030. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  1031. fi
  1032. elif [[ "${option}" == "SNAT6_TO_SOURCE" ]]; then
  1033. if ! grep -q "${option}" mailcow.conf; then
  1034. echo "Adding new option \"${option}\" to mailcow.conf"
  1035. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  1036. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  1037. fi
  1038. elif [[ "${option}" == "MAILDIR_GC_TIME" ]]; then
  1039. if ! grep -q "${option}" mailcow.conf; then
  1040. echo "Adding new option \"${option}\" to mailcow.conf"
  1041. echo '# Garbage collector cleanup' >> mailcow.conf
  1042. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  1043. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  1044. echo '# Check interval is hourly' >> mailcow.conf
  1045. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  1046. fi
  1047. elif [[ "${option}" == "ACL_ANYONE" ]]; then
  1048. if ! grep -q "${option}" mailcow.conf; then
  1049. echo "Adding new option \"${option}\" to mailcow.conf"
  1050. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  1051. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  1052. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  1053. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  1054. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  1055. fi
  1056. elif [[ "${option}" == "ENABLE_SSL_SNI" ]]; then
  1057. if ! grep -q "${option}" mailcow.conf; then
  1058. echo "Adding new option \"${option}\" to mailcow.conf"
  1059. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  1060. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  1061. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  1062. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  1063. fi
  1064. elif [[ "${option}" == "SKIP_SOGO" ]]; then
  1065. if ! grep -q "${option}" mailcow.conf; then
  1066. echo "Adding new option \"${option}\" to mailcow.conf"
  1067. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  1068. echo "SKIP_SOGO=n" >> mailcow.conf
  1069. fi
  1070. elif [[ "${option}" == "MAILDIR_SUB" ]]; then
  1071. if ! grep -q "${option}" mailcow.conf; then
  1072. echo "Adding new option \"${option}\" to mailcow.conf"
  1073. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  1074. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  1075. echo "MAILDIR_SUB=" >> mailcow.conf
  1076. fi
  1077. elif [[ "${option}" == "WATCHDOG_NOTIFY_WEBHOOK" ]]; then
  1078. if ! grep -q "${option}" mailcow.conf; then
  1079. echo "Adding new option \"${option}\" to mailcow.conf"
  1080. echo '# Send notifications to a webhook URL that receives a POST request with the content type "application/json".' >> mailcow.conf
  1081. echo '# You can use this to send notifications to services like Discord, Slack and others.' >> mailcow.conf
  1082. echo '#WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX' >> mailcow.conf
  1083. fi
  1084. elif [[ "${option}" == "WATCHDOG_NOTIFY_WEBHOOK_BODY" ]]; then
  1085. if ! grep -q "${option}" mailcow.conf; then
  1086. echo "Adding new option \"${option}\" to mailcow.conf"
  1087. echo '# JSON body included in the webhook POST request. Needs to be in single quotes.' >> mailcow.conf
  1088. echo '# Following variables are available: SUBJECT, BODY' >> mailcow.conf
  1089. WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  1090. echo "#WATCHDOG_NOTIFY_WEBHOOK_BODY='${WEBHOOK_BODY}'" >> mailcow.conf
  1091. fi
  1092. elif [[ "${option}" == "WATCHDOG_NOTIFY_BAN" ]]; then
  1093. if ! grep -q "${option}" mailcow.conf; then
  1094. echo "Adding new option \"${option}\" to mailcow.conf"
  1095. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  1096. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  1097. fi
  1098. elif [[ "${option}" == "WATCHDOG_NOTIFY_START" ]]; then
  1099. if ! grep -q "${option}" mailcow.conf; then
  1100. echo "Adding new option \"${option}\" to mailcow.conf"
  1101. echo '# Send a notification when the watchdog is started.' >> mailcow.conf
  1102. echo "WATCHDOG_NOTIFY_START=y" >> mailcow.conf
  1103. fi
  1104. elif [[ "${option}" == "WATCHDOG_SUBJECT" ]]; then
  1105. if ! grep -q "${option}" mailcow.conf; then
  1106. echo "Adding new option \"${option}\" to mailcow.conf"
  1107. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  1108. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  1109. fi
  1110. elif [[ "${option}" == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  1111. if ! grep -q "${option}" mailcow.conf; then
  1112. echo "Adding new option \"${option}\" to mailcow.conf"
  1113. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  1114. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  1115. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  1116. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  1117. fi
  1118. elif [[ "${option}" == "SOGO_EXPIRE_SESSION" ]]; then
  1119. if ! grep -q "${option}" mailcow.conf; then
  1120. echo "Adding new option \"${option}\" to mailcow.conf"
  1121. echo '# SOGo session timeout in minutes' >> mailcow.conf
  1122. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  1123. fi
  1124. elif [[ "${option}" == "REDIS_PORT" ]]; then
  1125. if ! grep -q "${option}" mailcow.conf; then
  1126. echo "Adding new option \"${option}\" to mailcow.conf"
  1127. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  1128. fi
  1129. elif [[ "${option}" == "DOVECOT_MASTER_USER" ]]; then
  1130. if ! grep -q "${option}" mailcow.conf; then
  1131. echo "Adding new option \"${option}\" to mailcow.conf"
  1132. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  1133. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  1134. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  1135. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  1136. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  1137. fi
  1138. elif [[ "${option}" == "DOVECOT_MASTER_PASS" ]]; then
  1139. if ! grep -q "${option}" mailcow.conf; then
  1140. echo "Adding new option \"${option}\" to mailcow.conf"
  1141. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  1142. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  1143. fi
  1144. elif [[ "${option}" == "MAILCOW_PASS_SCHEME" ]]; then
  1145. if ! grep -q "${option}" mailcow.conf; then
  1146. echo "Adding new option \"${option}\" to mailcow.conf"
  1147. echo '# Password hash algorithm' >> mailcow.conf
  1148. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  1149. echo '# see https://docs.mailcow.email/models/model-passwd/' >> mailcow.conf
  1150. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  1151. fi
  1152. elif [[ "${option}" == "ADDITIONAL_SERVER_NAMES" ]]; then
  1153. if ! grep -q "${option}" mailcow.conf; then
  1154. echo "Adding new option \"${option}\" to mailcow.conf"
  1155. echo '# Additional server names for mailcow UI' >> mailcow.conf
  1156. echo '#' >> mailcow.conf
  1157. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  1158. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  1159. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  1160. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  1161. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  1162. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  1163. fi
  1164. elif [[ "${option}" == "AUTODISCOVER_SAN" ]]; then
  1165. if ! grep -q "${option}" mailcow.conf; then
  1166. echo "Adding new option \"${option}\" to mailcow.conf"
  1167. echo '# Obtain certificates for autodiscover.* and autoconfig.* domains.' >> mailcow.conf
  1168. echo '# This can be useful to switch off in case you are in a scenario where a reverse proxy already handles those.' >> mailcow.conf
  1169. echo '# There are mixed scenarios where ports 80,443 are occupied and you do not want to share certs' >> mailcow.conf
  1170. echo '# between services. So acme-mailcow obtains for maildomains and all web-things get handled' >> mailcow.conf
  1171. echo '# in the reverse proxy.' >> mailcow.conf
  1172. echo 'AUTODISCOVER_SAN=y' >> mailcow.conf
  1173. fi
  1174. elif [[ "${option}" == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  1175. if ! grep -q "${option}" mailcow.conf; then
  1176. echo "Adding new option \"${option}\" to mailcow.conf"
  1177. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  1178. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  1179. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  1180. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  1181. fi
  1182. elif [[ "${option}" == "SPAMHAUS_DQS_KEY" ]]; then
  1183. if ! grep -q "${option}" mailcow.conf; then
  1184. echo "Adding new option \"${option}\" to mailcow.conf"
  1185. echo "# Spamhaus Data Query Service Key" >> mailcow.conf
  1186. echo '# Optional: Leave empty for none' >> mailcow.conf
  1187. echo '# Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.' >> mailcow.conf
  1188. echo '# If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.' >> mailcow.conf
  1189. echo '# Otherwise it will work as usual.' >> mailcow.conf
  1190. echo 'SPAMHAUS_DQS_KEY=' >> mailcow.conf
  1191. fi
  1192. elif [[ "${option}" == "WATCHDOG_VERBOSE" ]]; then
  1193. if ! grep -q "${option}" mailcow.conf; then
  1194. echo "Adding new option \"${option}\" to mailcow.conf"
  1195. echo '# Enable watchdog verbose logging' >> mailcow.conf
  1196. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  1197. fi
  1198. elif [[ "${option}" == "SKIP_UNBOUND_HEALTHCHECK" ]]; then
  1199. if ! grep -q "${option}" mailcow.conf; then
  1200. echo "Adding new option \"${option}\" to mailcow.conf"
  1201. echo '# Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n' >> mailcow.conf
  1202. echo 'SKIP_UNBOUND_HEALTHCHECK=n' >> mailcow.conf
  1203. fi
  1204. elif [[ "${option}" == "DISABLE_NETFILTER_ISOLATION_RULE" ]]; then
  1205. if ! grep -q "${option}" mailcow.conf; then
  1206. echo "Adding new option \"${option}\" to mailcow.conf"
  1207. echo '# Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n' >> mailcow.conf
  1208. echo '# CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost' >> mailcow.conf
  1209. echo 'DISABLE_NETFILTER_ISOLATION_RULE=n' >> mailcow.conf
  1210. fi
  1211. elif [[ "${option}" == "SKIP_CLAMD" ]]; then
  1212. if ! grep -q "${option}" mailcow.conf; then
  1213. echo "Adding new option \"${option}\" to mailcow.conf"
  1214. echo '# Skip ClamAV (clamd-mailcow) anti-virus (Rspamd will auto-detect a missing ClamAV container) - y/n' >> mailcow.conf
  1215. echo 'SKIP_CLAMD=n' >> mailcow.conf
  1216. fi
  1217. elif [[ "${option}" == "SKIP_OLEFY" ]]; then
  1218. if ! grep -q "${option}" mailcow.conf; then
  1219. echo "Adding new option \"${option}\" to mailcow.conf"
  1220. echo '# Skip Olefy (olefy-mailcow) anti-virus for Office documents (Rspamd will auto-detect a missing Olefy container) - y/n' >> mailcow.conf
  1221. echo 'SKIP_OLEFY=n' >> mailcow.conf
  1222. fi
  1223. elif [[ "${option}" == "REDISPASS" ]]; then
  1224. if ! grep -q "${option}" mailcow.conf; then
  1225. echo "Adding new option \"${option}\" to mailcow.conf"
  1226. echo -e '\n# ------------------------------' >> mailcow.conf
  1227. echo '# REDIS configuration' >> mailcow.conf
  1228. echo -e '# ------------------------------\n' >> mailcow.conf
  1229. echo "REDISPASS=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)" >> mailcow.conf
  1230. fi
  1231. elif ! grep -q "${option}" mailcow.conf; then
  1232. echo "Adding new option \"${option}\" to mailcow.conf"
  1233. echo "${option}=n" >> mailcow.conf
  1234. fi
  1235. done
  1236. if [[ ("${SKIP_PING_CHECK}" == "y") ]]; then
  1237. echo -e "\e[32mSkipping Ping Check...\e[0m"
  1238. else
  1239. echo -en "Checking internet connection... "
  1240. if ! check_online_status; then
  1241. echo -e "\e[31mfailed\e[0m"
  1242. exit 1
  1243. else
  1244. echo -e "\e[32mOK\e[0m"
  1245. fi
  1246. fi
  1247. if ! [ "$NEW_BRANCH" ]; then
  1248. echo -e "\e[33mDetecting which build your mailcow runs on...\e[0m"
  1249. sleep 1
  1250. if [ "${BRANCH}" == "master" ]; then
  1251. echo -e "\e[32mYou are receiving stable updates (master).\e[0m"
  1252. echo -e "\e[33mTo change that run the update.sh Script one time with the --nightly parameter to switch to nightly builds.\e[0m"
  1253. elif [ "${BRANCH}" == "nightly" ]; then
  1254. echo -e "\e[31mYou are receiving unstable updates (nightly). These are for testing purposes only!!!\e[0m"
  1255. sleep 1
  1256. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  1257. elif [ "${BRANCH}" == "legacy" ]; then
  1258. echo -e "\e[31mYou are receiving legacy updates. The legacy branch will only receive security updates until February 2026.\e[0m"
  1259. sleep 1
  1260. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  1261. else
  1262. echo -e "\e[33mYou are receiving updates from an unsupported branch.\e[0m"
  1263. sleep 1
  1264. echo -e "\e[33mThe mailcow stack might still work but it is recommended to switch to the master branch (stable builds).\e[0m"
  1265. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  1266. fi
  1267. elif [ "$FORCE" ]; then
  1268. echo -e "\e[31mYou are running in forced mode!\e[0m"
  1269. echo -e "\e[31mA Branch Switch can only be performed manually (monitored).\e[0m"
  1270. echo -e "\e[31mPlease rerun the update.sh Script without the --force/-f parameter.\e[0m"
  1271. sleep 1
  1272. elif [ "$NEW_BRANCH" == "master" ] && [ "$CURRENT_BRANCH" != "master" ]; then
  1273. echo -e "\e[33mYou are about to switch your mailcow updates to the stable (master) branch.\e[0m"
  1274. sleep 1
  1275. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no data is lost...\e[0m"
  1276. sleep 1
  1277. echo -e "\e[31mWARNING: Please see on GitHub or ask in the community if a switch to master is stable or not.
  1278. In some rear cases an update back to master can destroy your mailcow configuration such as database upgrade, etc.
  1279. Normally an upgrade back to master should be safe during each full release.
  1280. Check GitHub for Database changes and update only if there similar to the full release!\e[0m"
  1281. read -r -p "Are you sure you that want to continue upgrading to the stable (master) branch? [y/N] " response
  1282. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1283. echo "OK. If you prepared yourself for that please run the update.sh Script with the --stable parameter again to trigger this process here."
  1284. exit 0
  1285. fi
  1286. BRANCH="$NEW_BRANCH"
  1287. DIFF_DIRECTORY=update_diffs
  1288. DIFF_FILE="${DIFF_DIRECTORY}/diff_before_upgrade_to_master_$(date +"%Y-%m-%d-%H-%M-%S")"
  1289. mv diff_before_upgrade* "${DIFF_DIRECTORY}/" 2> /dev/null
  1290. if ! git diff-index --quiet HEAD; then
  1291. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1292. mkdir -p "${DIFF_DIRECTORY}"
  1293. git diff "${BRANCH}" --stat > "${DIFF_FILE}"
  1294. git diff "${BRANCH}" >> "${DIFF_FILE}"
  1295. fi
  1296. echo -e "\e[32mSwitching Branch to ${BRANCH}...\e[0m"
  1297. git fetch origin
  1298. git checkout -f "${BRANCH}"
  1299. elif [ "$NEW_BRANCH" == "nightly" ] && [ "$CURRENT_BRANCH" != "nightly" ]; then
  1300. echo -e "\e[33mYou are about to switch your mailcow Updates to the unstable (nightly) branch.\e[0m"
  1301. sleep 1
  1302. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no Data is lost...\e[0m"
  1303. sleep 1
  1304. echo -e "\e[31mWARNING: A switch to nightly is possible any time. But a switch back (to master) isn't.\e[0m"
  1305. read -r -p "Are you sure you that want to continue upgrading to the unstable (nightly) branch? [y/N] " response
  1306. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1307. echo "OK. If you prepared yourself for that please run the update.sh Script with the --nightly parameter again to trigger this process here."
  1308. exit 0
  1309. fi
  1310. BRANCH=$NEW_BRANCH
  1311. DIFF_DIRECTORY=update_diffs
  1312. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_nightly_$(date +"%Y-%m-%d-%H-%M-%S")
  1313. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  1314. if ! git diff-index --quiet HEAD; then
  1315. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1316. mkdir -p ${DIFF_DIRECTORY}
  1317. git diff "${BRANCH}" --stat > "${DIFF_FILE}"
  1318. git diff "${BRANCH}" >> "${DIFF_FILE}"
  1319. fi
  1320. git fetch origin
  1321. git checkout -f "${BRANCH}"
  1322. elif [ "$NEW_BRANCH" == "legacy" ] && [ "$CURRENT_BRANCH" != "legacy" ]; then
  1323. echo -e "\e[33mYou are about to switch your mailcow Updates to the legacy branch.\e[0m"
  1324. sleep 1
  1325. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no Data is lost...\e[0m"
  1326. sleep 1
  1327. echo -e "\e[31mWARNING: A switch to stable or nightly is possible any time.\e[0m"
  1328. read -r -p "Are you sure you want to continue upgrading to the legacy branch? [y/N] " response
  1329. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1330. echo "OK. If you prepared yourself for that please run the update.sh Script with the --legacy parameter again to trigger this process here."
  1331. exit 0
  1332. fi
  1333. BRANCH=$NEW_BRANCH
  1334. DIFF_DIRECTORY=update_diffs
  1335. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_legacy_$(date +"%Y-%m-%d-%H-%M-%S")
  1336. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  1337. if ! git diff-index --quiet HEAD; then
  1338. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1339. mkdir -p ${DIFF_DIRECTORY}
  1340. git diff "${BRANCH}" --stat > "${DIFF_FILE}"
  1341. git diff "${BRANCH}" >> "${DIFF_FILE}"
  1342. fi
  1343. git fetch origin
  1344. git checkout -f "${BRANCH}"
  1345. fi
  1346. if [ ! "$DEV" ]; then
  1347. echo -e "\e[32mChecking for newer update script...\e[0m"
  1348. SHA1_1="$(sha1sum update.sh)"
  1349. git fetch origin #${BRANCH}
  1350. git checkout "origin/${BRANCH}" update.sh
  1351. SHA1_2=$(sha1sum update.sh)
  1352. if [[ "${SHA1_1}" != "${SHA1_2}" ]]; then
  1353. echo "update.sh changed, please run this script again, exiting."
  1354. chmod +x update.sh
  1355. exit 2
  1356. fi
  1357. fi
  1358. if [ ! "$FORCE" ]; then
  1359. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  1360. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1361. echo "OK, exiting."
  1362. exit 0
  1363. fi
  1364. detect_major_update
  1365. migrate_docker_nat
  1366. fi
  1367. remove_obsolete_nginx_ports
  1368. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  1369. sed -i 's/HTTPS_BIND:-:/HTTPS_BIND:-/g' docker-compose.yml
  1370. sed -i 's/HTTP_BIND:-:/HTTP_BIND:-/g' docker-compose.yml
  1371. if ! $COMPOSE_COMMAND config -q; then
  1372. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  1373. exit 1
  1374. fi
  1375. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  1376. MAILCOW_BRIDGE=$($COMPOSE_COMMAND config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  1377. while read NAT_ID; do
  1378. iptables -t nat -D POSTROUTING "$NAT_ID"
  1379. done < <(iptables -L -vn -t nat --line-numbers | grep "$IPV4_NETWORK" | grep -E 'MASQUERADE.*all' | grep -v "${MAILCOW_BRIDGE}" | cut -d' ' -f1)
  1380. DIFF_DIRECTORY=update_diffs
  1381. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  1382. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  1383. if ! git diff-index --quiet HEAD; then
  1384. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1385. mkdir -p ${DIFF_DIRECTORY}
  1386. git diff --stat > "${DIFF_FILE}"
  1387. git diff >> "${DIFF_FILE}"
  1388. fi
  1389. echo -e "\e[32mPrefetching images...\e[0m"
  1390. prefetch_images
  1391. echo -e "\e[32mStopping mailcow...\e[0m"
  1392. sleep 2
  1393. MAILCOW_CONTAINERS=($($COMPOSE_COMMAND ps -q))
  1394. $COMPOSE_COMMAND down
  1395. echo -e "\e[32mChecking for remaining containers...\e[0m"
  1396. sleep 2
  1397. for container in "${MAILCOW_CONTAINERS[@]}"; do
  1398. docker rm -f "$container" 2> /dev/null
  1399. done
  1400. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  1401. migrate_solr_config_options
  1402. adapt_new_options
  1403. remove_obsolete_options
  1404. # Silently fixing remote url from andryyy to mailcow
  1405. # git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  1406. DEFAULT_REPO="https://github.com/mailcow/mailcow-dockerized"
  1407. CURRENT_REPO=$(git config --get remote.origin.url)
  1408. if [ "$CURRENT_REPO" != "$DEFAULT_REPO" ]; then
  1409. echo "The Repository currently used is not the default Mailcow Repository."
  1410. echo "Currently Repository: $CURRENT_REPO"
  1411. echo "Default Repository: $DEFAULT_REPO"
  1412. if [ ! "$FORCE" ]; then
  1413. read -r -p "Should it be changed back to default? [y/N] " repo_response
  1414. if [[ "$repo_response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1415. git remote set-url origin $DEFAULT_REPO
  1416. fi
  1417. else
  1418. echo "Running in forced mode... setting Repo to default!"
  1419. git remote set-url origin $DEFAULT_REPO
  1420. fi
  1421. fi
  1422. if [ ! "$DEV" ]; then
  1423. echo -e "\e[32mCommitting current status...\e[0m"
  1424. [[ -z "$(git config user.name)" ]] && git config user.name moo
  1425. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  1426. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  1427. git add -u
  1428. git commit -am "Before update on ${DATE}" > /dev/null
  1429. echo -e "\e[32mFetching updated code from remote...\e[0m"
  1430. git fetch origin #${BRANCH}
  1431. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  1432. git config merge.defaultToUpstream true
  1433. git merge -X"${MERGE_STRATEGY:-theirs}" -Xpatience -m "After update on ${DATE}"
  1434. # Need to use a variable to not pass return codes of if checks
  1435. MERGE_RETURN=$?
  1436. if [[ ${MERGE_RETURN} == 128 ]]; then
  1437. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  1438. exit 1
  1439. elif [[ ${MERGE_RETURN} == 1 ]]; then
  1440. echo -e "\e[93mPotential conflict, trying to fix...\e[0m"
  1441. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  1442. git add -A
  1443. git commit -m "After update on ${DATE}" > /dev/null
  1444. git checkout .
  1445. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  1446. elif [[ ${MERGE_RETURN} != 0 ]]; then
  1447. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  1448. echo
  1449. echo "Run $COMPOSE_COMMAND up -d to restart your stack without updates or try again after fixing the mentioned errors."
  1450. exit 1
  1451. fi
  1452. elif [ "$DEV" ]; then
  1453. echo -e "\e[33mDEVELOPER MODE: Not creating a git diff and commiting it to prevent development stuff within a backup diff...\e[0m"
  1454. fi
  1455. echo -e "\e[32mFetching new images, if any...\e[0m"
  1456. sleep 2
  1457. $COMPOSE_COMMAND pull
  1458. # Fix missing SSL, does not overwrite existing files
  1459. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  1460. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  1461. echo -e "Checking IPv6 settings... "
  1462. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  1463. echo
  1464. echo '!! IMPORTANT !!'
  1465. echo
  1466. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  1467. echo "This setting will only be active after a complete shutdown of mailcow by running $COMPOSE_COMMAND down followed by $COMPOSE_COMMAND up -d."
  1468. echo
  1469. echo '!! IMPORTANT !!'
  1470. echo
  1471. read -p "Press any key to continue..." < /dev/tty
  1472. fi
  1473. # Checking for old project name bug
  1474. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  1475. # Fix Rspamd maps
  1476. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  1477. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  1478. fi
  1479. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  1480. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  1481. fi
  1482. # Fix deprecated metrics.conf
  1483. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  1484. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  1485. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  1486. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  1487. fi
  1488. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  1489. fi
  1490. # Set app_info.inc.php
  1491. if [ ${BRANCH} == "master" ]; then
  1492. mailcow_git_version=$(git describe --tags $(git rev-list --tags --max-count=1))
  1493. elif [ ${BRANCH} == "nightly" ]; then
  1494. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  1495. mailcow_last_git_version=""
  1496. else
  1497. mailcow_git_version=$(git rev-parse --short HEAD)
  1498. mailcow_last_git_version=""
  1499. fi
  1500. mailcow_git_commit=$(git rev-parse "origin/${BRANCH}")
  1501. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  1502. if [ $? -eq 0 ]; then
  1503. echo '<?php' > data/web/inc/app_info.inc.php
  1504. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  1505. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  1506. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  1507. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1508. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1509. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  1510. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  1511. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  1512. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  1513. echo '?>' >> data/web/inc/app_info.inc.php
  1514. else
  1515. echo '<?php' > data/web/inc/app_info.inc.php
  1516. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  1517. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  1518. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  1519. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1520. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1521. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  1522. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  1523. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  1524. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  1525. echo '?>' >> data/web/inc/app_info.inc.php
  1526. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  1527. fi
  1528. if [[ ${SKIP_START} == "y" ]]; then
  1529. echo -e "\e[33mNot starting mailcow, please run \"$COMPOSE_COMMAND up -d --remove-orphans\" to start mailcow.\e[0m"
  1530. else
  1531. echo -e "\e[32mStarting mailcow...\e[0m"
  1532. sleep 2
  1533. $COMPOSE_COMMAND up -d --remove-orphans
  1534. fi
  1535. echo -e "\e[32mCollecting garbage...\e[0m"
  1536. docker_garbage
  1537. # Run post-update-hook
  1538. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  1539. bash "${SCRIPT_DIR}/post_update_hook.sh"
  1540. fi
  1541. # echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  1542. # echo
  1543. # git reflog --color=always | grep "Before update on "
  1544. # echo
  1545. # echo "Use \"git reset --hard hash-on-the-left\" and run $COMPOSE_COMMAND up -d afterwards."