Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
130 commits
Select commit Hold shift + click to select a range
3522f3e
kitterman.com redirects to TLS by default
Knight1 Aug 5, 2018
73f880f
[Web] Workaround for missing function when using API (fixes #1640)
Aug 5, 2018
ff0b924
[ClamAV] Add whitelist file for ClamAV, fixes #1607
Aug 5, 2018
66d1bc1
[Nginx] Set client_max_body_size = 0
Aug 5, 2018
0273f95
[Compose] New images for ClamAV (+mount whitelist file) and ACME
Aug 5, 2018
d83537c
[ClamAV] Add whitelist template for ClamAV
Aug 5, 2018
6bd818c
[ACME] Remove third-party IP tools
Aug 6, 2018
02e567f
[Dovecot] Set CONTROL path for shared namespace and remove index
Aug 8, 2018
d5e81b9
[Dovecot] Set from address for sieve generated addresses, fixes #1662
Aug 13, 2018
a11cce6
[Web] Fixes for BCC map input fields
Aug 13, 2018
1791383
[Web] Fix duplicate success message after editing a domain as domain …
Aug 14, 2018
2c58323
[Web] Fix database init
Aug 15, 2018
f81dad1
[Compose] Update Postfix image
Aug 15, 2018
6498fb0
[Web] Change alias to TEXT field
Aug 16, 2018
66ee11c
[SOGo] Disable display of ACL "any/authenticated" by default
Aug 17, 2018
407d921
[Compose] New SOGo image
Aug 17, 2018
6cee038
[Dovecot] IMPORTANT: Disables 'any' and 'all authenticated' ACL setti…
Aug 17, 2018
3fd99e4
[Web] Important fix: Ignore untrusted headers
Aug 17, 2018
e021f4c
Merge pull request #1633 from Knight1/patch-1
andryyy Aug 18, 2018
819e948
Update lang.nl.php
Geitenijs Aug 18, 2018
57277a2
Merge pull request #1690 from DynamicThijs/patch-1
andryyy Aug 18, 2018
1403260
Fix length of remote column in logs table
mkuron Aug 19, 2018
bbbdb13
[Web] Fix length of remote column in logs table for IPv6
andryyy Aug 19, 2018
d64a894
[Web] Add multiple DKIM at once (+ button to auto-fill missing keys)
Aug 21, 2018
d28fd40
[Web] Allow to set rate limit in add_domain modal
Aug 21, 2018
1dea230
[Web] Fix setting a rate limit when adding a domain
Aug 21, 2018
5b4b184
[Web] Fixes to mailcow logo (stickers are coming!)
Aug 23, 2018
4b09b5b
Update functions.mailbox.inc.php
andryyy Aug 26, 2018
5e56a46
[dovecot] Enhancement to allow to use auth_default_realm
sriccio Aug 28, 2018
775b69f
Merge pull request #1721 from sriccio/master
andryyy Aug 28, 2018
e5b830a
[Dovecot] Fix shared namespace
Aug 31, 2018
8a88514
[SOGo] Declare /usr/lib/GNUstep/SOGo as volume
Sep 7, 2018
afc18fd
[Rspamd] Update bad asn, move KEEP_SPAM to a custom lua function
Sep 9, 2018
ad902f0
[SOGo] Remove HTTP server on port 9192
Sep 9, 2018
ea4a26e
[Nginx] Use SOGo web resources from local mount
Sep 9, 2018
c9554ca
[Compose] Update watchdog image
Sep 9, 2018
c8a1cbd
Merge branch 'temp-master'
Sep 9, 2018
1a5ec76
[Compose] Update watchdog image
Sep 9, 2018
29aeb5b
[Watchdog] Fix SOGo check, fixes #1750
Sep 9, 2018
ce60423
[Web] Add missing data-acl for sync jobs
Sep 10, 2018
a5488d4
[Web] Fix init db on fresh installations
Sep 10, 2018
1499094
[PHP-FPM] Increase PHP memory limit for "web" to 512M
Sep 11, 2018
1b5409f
[Rspamd] Check if ip is valid (KEEP_SPAM symbol), fixes #1759
Sep 12, 2018
c7cef32
[Rspamd] Controller worker count == 1, fixes #1716
Sep 12, 2018
8056ed2
[Compose] Update dockerapi-mailcow, base image is now Alpine 3.8, fix…
Sep 14, 2018
5db40bf
[Web] Implement MD5-CRYPT verification, fixes #1665
Sep 20, 2018
b5df239
[Rspamd] Update to 1.8.0
andryyy Sep 25, 2018
cd24831
[Rspamd] Fix settings map location, fixes #1796
andryyy Sep 25, 2018
96c985a
[Rspamd] Move settings file to RSPAMD_CONF root, delete old lua scripts
Sep 26, 2018
0fb43f4
[Docker API] Use TLS encryption for communication with "on-the-fly" c…
Sep 29, 2018
73b1035
[Rspamd] Ignore sa-rules-heinlein file, remove from index
Sep 29, 2018
4396be2
[Rspamd] Place socket in _rspamd home and fix permissions
Sep 30, 2018
8439dae
[Rspamd] Revert adding worker-controller-password...
Sep 30, 2018
b008211
[Rspamd] Controller password placeholder
Sep 30, 2018
cdca603
[Unbound] Fix logging, fixes #585
Sep 30, 2018
6cbe7a0
[Compose] Update Unbound image and set tty true
Sep 30, 2018
71ec81d
[Update] Add MAILDIR_GC_TIME
Sep 30, 2018
d7ca557
[Rspamd] Ignore custom files, but keep bad asn map
Sep 30, 2018
a054182
[Rspamd] Add desc to high spam networks
Sep 30, 2018
b8ebdc3
[Postfix] Increase default message size limit to 100 MiB
Oct 1, 2018
ca1e950
[Dovecot] Do not query gid and uid
Oct 2, 2018
62b27ae
[Dovecot] Check garbage hourly
Oct 2, 2018
fc9c0c8
[Compose] Fix conflict
Oct 2, 2018
2af2f78
[Dovecot] Remove fixed uid and gid
Oct 2, 2018
668a092
[Web] Fix deletion of domain, fixes #1818
Oct 2, 2018
b61f971
[Update] Add MAILDIR_GC_TIME to config file, fixes #1821
Oct 2, 2018
7c4416b
[Compose] Update dockerapi-mailcow
Oct 3, 2018
f0dfee7
[Web] Add MAILBOX_DEFAULT_ATTRIBUTES variable to define default mailb…
Oct 3, 2018
d8148be
[Docker API] Do not print warning when maildr does not exist
Oct 3, 2018
76530b7
[Web] Use json_encode for mail attrs when creating a mailbox
Oct 3, 2018
a7b51a9
[Web] Fix user page actions
Oct 3, 2018
67adca4
Don't print 'Collecting garbage...' twice
MAGICCC Oct 3, 2018
38e6de4
Merge pull request #1825 from mailcow/MAGICCC-patch-1
andryyy Oct 3, 2018
d00f474
[Web] Fix address rewriting actions, fixes #1829
Oct 3, 2018
794ec7b
Merge branch 'master' of https://github.com/mailcow/mailcow-dockerized
Oct 3, 2018
2ef73e2
Update Dutch lang file
Geitenijs Oct 3, 2018
cf28727
[Dovecot] Add timeouts to sa-rules script, remove with -f flag to ret…
Oct 3, 2018
2c71c68
[Compose] New dovecot-mailcow image
Oct 3, 2018
b2067cb
[SOGo] SOGoMaximumSyncWindowSize = 99
Oct 4, 2018
2f18eb5
[Nginx] Avoid php extensions, use rewrite
Oct 4, 2018
f6b2a6a
[Postfix] Enable/create smtp_tls_policy_maps
Oct 4, 2018
c6aa361
[Postfix] Enable/create smtp_tls_policy_maps
Oct 4, 2018
f5799fa
[Web] Feature: TLS policy maps
Oct 4, 2018
5397273
[Web] Fix domain admin edit function
Oct 4, 2018
174ef1a
[Compose] New Postfix image
Oct 4, 2018
45bfa44
Add portainer and docker-compose.override.yml to .gitignore
Knight1 Oct 5, 2018
c08149a
[SOGo] EAS changes, larger timeout
Oct 5, 2018
1893dae
[Web] Fix JS pathes, fixes #1845
Oct 5, 2018
deade73
Try Travis
Knight1 Oct 6, 2018
d88fa00
Trigger build
Knight1 Oct 6, 2018
725824a
Disable oom_kill_disable inside Travis
Knight1 Oct 6, 2018
ea76de3
Fix?
Knight1 Oct 6, 2018
d735b93
Merge pull request #1840 from Knight1/patch-6
andryyy Oct 6, 2018
52085cc
Merge pull request #1 from mailcow/master
ntimo Oct 6, 2018
355b3f4
added Gitea and Gogs folder two .gitignore
ntimo Oct 6, 2018
e304860
[Web] Fix empty domain dropdown in race condition, fixes #1849 as wor…
Oct 6, 2018
9f52cd9
[Docker API] Fix sieve list for users, fixes #1849
Oct 6, 2018
152f6f3
Merge branch 'master' of https://github.com/mailcow/mailcow-dockerized
Oct 6, 2018
125ce8e
[web] fix relayhost test
mkuron Oct 7, 2018
3d57063
Merge pull request #1858 from mailcow/relayhost-test
andryyy Oct 7, 2018
ad63552
[Dovecot] Check file size of mail crypt key pair, fixes #1859
Oct 7, 2018
699c9a7
Merge branch 'master' of https://github.com/mailcow/mailcow-dockerized
Oct 7, 2018
34ddde8
[Web] New /get/dkim/{domain} method to retrieve DKIM keys
gromez Oct 9, 2018
7936a6c
Merge pull request #1868 from gromez/api-dkim-details
andryyy Oct 9, 2018
90aaae0
Merge pull request #1853 from ntimo/master
andryyy Oct 9, 2018
4179cc7
Merge pull request #1830 from DynamicThijs/patch-1
andryyy Oct 9, 2018
ce135bb
[ACME] Log acme-client output base64 encoded, use mysqladmin status i…
Oct 11, 2018
aa39be7
[SOGo] Use mysqladmin status instead of ping to determine readiness
Oct 11, 2018
c0b590f
[PHP-FPM] Move max_execution_time and max_input_time to general PHP c…
Oct 11, 2018
32f7ae1
[Rspamd] Prefix quarantine error_log messages with "QUARANTINE"
Oct 11, 2018
9f0be1d
[Web] Fix require_once to always include document root
Oct 11, 2018
53832d8
[Helper] Fix mailcow reset admin to work in multi-admin environment
Oct 11, 2018
143f6f0
[Config] Add allowed chars for API key
Oct 11, 2018
ee51425
[Compose] New images: Unbound, PHP-FPM, SOGo, Dovecot, ACME
Oct 11, 2018
3db6af5
[Unbound] Trust all addresses - do not expose Unbound!
Oct 12, 2018
1fce562
[Dovecot] Set imap_max_line_length = 2 M
Oct 12, 2018
23e6e52
[Postfix] Proper permissions for sql config files
Oct 12, 2018
5ce15ea
[Web] Some language updates for sys mails
Oct 12, 2018
04b3d7a
[Compose] Update Postfix and Dovecot images
Oct 12, 2018
c80fe40
[Unbound] Do not allow from all (dangerous for setups with incorrect …
Oct 12, 2018
4459b77
Merge branch 'master' of https://github.com/mailcow/mailcow-dockerized
Oct 12, 2018
93917f8
[Unbound] Upgrade to Alpine 3.8, fixes #1882
Oct 13, 2018
3086d5a
Install stale bot
Oct 13, 2018
83fbc82
Merge pull request #2 from mailcow/master
ntimo Oct 13, 2018
180c062
Added .github folder to .gitignore
Oct 13, 2018
a26acde
Merge pull request #1888 from ntimo/master
andryyy Oct 13, 2018
df4f9b5
Add issue template
Oct 13, 2018
96622dc
Merge branch 'master' of https://github.com/mailcow/mailcow-dockerized
Oct 13, 2018
74692a1
Update issue template
Oct 13, 2018
73b3e0c
Merge pull request #2 from mailcow/master
Knight1 Oct 13, 2018
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 29 additions & 0 deletions .github/ISSUE_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
**Notice (you can delete this paragraph)**
Please understand that we use GitHub as **bug tracker and for feature requests only**.
For general (community) support and other discussion, you are welcome to visit us @ Freenode, #mailcow
Answering may take from a few seconds to hours, please be patient. :-)
Immediate commercial support is available via mailcow@incidents.servercow.de

**Describe the bug**
A clear and concise description of what the bug is.

**To Reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**System**
- OS: [e.g. iOS]
- Browser: [e.g. chrome, safari]
- Other clients involved:

**Additional context**
Add any other context about the problem here.
18 changes: 18 additions & 0 deletions .github/stale.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Number of days of inactivity before an issue becomes stale
daysUntilStale: 60
# Number of days of inactivity before a stale issue is closed
daysUntilClose: 7
# Issues with these labels will never be considered stale
exemptLabels:
- pinned
- security
- enhancement
# Label to use when marking an issue as stale
staleLabel: dunno
# Comment to post when marking an issue as stale. Set to `false` to disable
markComment: >
This issue has been automatically marked as stale because it has not had
recent activity. It will be closed if no further activity occurs. Thank you
for your contributions.
# Comment to post when closing a stale issue. Set to `false` to disable
closeComment: false
6 changes: 6 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,9 @@ data/conf/nginx/*.conf
data/conf/nginx/*.custom
data/conf/nginx/*.bak
data/conf/dovecot/extra.conf
data/conf/rspamd/custom/*
data/conf/portainer/
data/gitea/
data/gogs/
.github/
docker-compose.override.yml
10 changes: 2 additions & 8 deletions .travis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,9 @@ sudo: required
services:
- docker
script:
- sed -i '/oom_kill_disable/d' docker-compose.yml
- echo 'Europe/Berlin' | MAILCOW_HOSTNAME=build.mailcow ./generate_config.sh
- docker-compose pull --ignore-pull-failures --parallel
- docker-compose build
- docker login --username=$DOCKER_HUB_USERNAME --password=$DOCKER_HUB_PASSWORD
- docker-compose push
branches:
only:
- master_disabled
env:
global:
- secure: MpxpTwD7f0CNEVLitSpVmocK7O9r+BwFE1deEHK4AlQo/oc9cOlhGe1EL3mx9zbglPmjlDg/8kMUGv6vSirIabfBo9Szjps76bHckFr9lr2Ykkg0e29oC8pgPpSXD1eY/1ZIN/FvIkxpUFLETo1okS/j9q/A0DCGFmti0n3EoMORsgRz9CpNAiEh0zpSd6+euPAGHuczuCrDuO84my9bIOCjA/+aPunHNeXiuM8yIM2SxCSyGtIKT0+jvquIvLF58VxivysXBlRfhDn8fhB09nXA2Ru/derYQACfcmNSn9Pd4bDpebPJW5B9H/XA8xjb58uKinUlncbAMB/QnxoT75j9YRWJZRSQ+34XNYP6ZgK9soZ2TC6djQyEKTUu45Kp/1s+poSn42m9jytJJTmmK0KxsZTRcC8JD5nrjIMZWPUNNTwC5L4+I7ZRWg2WooK3LNyq1Ng8Hn6W77wSgsvAJw2HD3Lx58AprGUhHuBeaIZRuSN9aKwZrl9vKQJLqPnOp/nF2EC6kot5HYYtcotGtETXPUDih21gWD5ZM2BqVqYfQQnJnNMgeYmMdj6QQuTFqhuNJf7hXRIRkTnD3j1gDOLKQZazW0+N2JE8XWDFwi6fKScDsxT85lJti9HmzHa7+k4RVHmUYuDgRoPuzUgjWHvPsiz3/Z8WQ9JYpH84S8w=
- secure: fWzZisT6nGDNL4lf6tXB07eFG2drgBakHxzdF/NFVvzuP861RFR6omuL+ED0PgXrEHDJBxaBLv52je8irmUXrAH1CNr7T8DWiZo/h5h609Uzr+38T1NnIu4krL0Wo6/CDwlLKnzqTq9yBIZLQSHVJmo8AOpo1JPIi2ajodqj9ZfmAxDQTQl+G6zvQjtqIkYHsHY7A44Rto0f14ykn7w2S82Jn6Ry89VNI5V1WEO3sMpM/XekNP/HokNcRIuntL/0+kuLvTJ5akGoTjBQxSnSW95opzPeGky74HRU2obExJYqKvF0VfVJRNAqejwjIiFIbbjqV0Sk5391kFuhuBErQQDM1bOHGdxZ41HsJH29qNWIl7C33Yl10qERoqecgsJ1N/bS2ZEmWqm/zQh5GClCXPvYmzEqMYsMGM3vjbKdjDlc1Wh2w/eFclsXN9LSXh1mc35rtj46frcT6e5Kof87AIfC9hTgDvk9kAsyjaHMkSHSZthbZXCIcsD8qriNm5UqfFBYD79mPIP1S2YMQ2jscCsjHOZgYVrcm0kzDF21J1w6H0Lo7d1jw37LYlegBdtLQ9gYgqY2D5m+nxWuVoD5FZmpR+5JGtK+ootyLFF8aiFoHXd4op1JCxRLjgkmnZKXzw3kTQSpE7oa7CgzchtQmK2nqcqla1b5Qk7ilVcjooo=
- travis
8 changes: 6 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,12 @@
# mailcow: dockerized - 🐮 + 🐋 = 💕

[![Donate](https://img.shields.io/badge/Donate-PayPal-green.svg)](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=JWBSYHF4SMC68)
## Want to support mailcow?

**mailcow Bitcoin donations:** 1E5rgzgA1sS3QH7r1ToWxRC3GEavfsGMrx
Donate via **PayPal** [![Donate](https://www.paypalobjects.com/en_US/i/btn/btn_donate_LG.gif)](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=JWBSYHF4SMC68) or via **Liberapay** [![Liberapay.com](https://mailcow.email/img/lp.png)](https://liberapay.com/mailcow)

Or just spread the word: moo.

## Info and documentation

Please see [the official documentation](https://mailcow.github.io/mailcow-dockerized-docs/) for instructions.

Expand Down
69 changes: 47 additions & 22 deletions data/Dockerfiles/acme/docker-entrypoint.sh
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,12 @@ log_f() {
elif [[ ${2} != "redis_only" ]]; then
echo "$(date) - ${1}"
fi
redis-cli -h redis LPUSH ACME_LOG "{\"time\":\"$(date +%s)\",\"message\":\"$(printf '%s' "${1}" | \
tr '%&;$"_[]{}-\r\n' ' ')\"}" > /dev/null
if [[ ${3} == "b64" ]]; then
redis-cli -h redis LPUSH ACME_LOG "{\"time\":\"$(date +%s)\",\"message\":\"base64,$(printf '%s' "${1}")\"}" > /dev/null
else
redis-cli -h redis LPUSH ACME_LOG "{\"time\":\"$(date +%s)\",\"message\":\"$(printf '%s' "${1}" | \
tr '%&;$"_[]{}-\r\n' ' ')\"}" > /dev/null
fi
}

if [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
Expand All @@ -37,7 +41,7 @@ mkdir -p ${ACME_BASE}/acme/private
restart_containers(){
for container in $*; do
log_f "Restarting ${container}..." no_nl
C_REST_OUT=$(curl -X POST http://dockerapi:8080/containers/${container}/restart | jq -r '.msg')
C_REST_OUT=$(curl -X POST --insecure https://dockerapi/containers/${container}/restart | jq -r '.msg')
log_f "${C_REST_OUT}" no_date
done
}
Expand Down Expand Up @@ -66,12 +70,8 @@ get_ipv4(){
local IPV4=
local IPV4_SRCS=
local TRY=
IPV4_SRCS[0]="api.ipify.org"
IPV4_SRCS[1]="ifconfig.co"-
IPV4_SRCS[2]="icanhazip.com"
IPV4_SRCS[3]="v4.ident.me"
IPV4_SRCS[4]="ipecho.net/plain"
IPV4_SRCS[5]="ip4.mailcow.email"
IPV4_SRCS[0]="ip4.mailcow.email"
IPV4_SRCS[1]="ip4.korves.net"
until [[ ! -z ${IPV4} ]] || [[ ${TRY} -ge 10 ]]; do
IPV4=$(curl --connect-timeout 3 -m 10 -L4s ${IPV4_SRCS[$RANDOM % ${#IPV4_SRCS[@]} ]} | grep -E "^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$")
[[ ! -z ${TRY} ]] && sleep 1
Expand All @@ -84,10 +84,8 @@ get_ipv6(){
local IPV6=
local IPV6_SRCS=
local TRY=
IPV6_SRCS[0]="ifconfig.co"
IPV6_SRCS[1]="icanhazip.com"
IPV6_SRCS[2]="v6.ident.me"
IPV6_SRCS[3]="ip6.mailcow.email"
IPV6_SRCS[0]="ip6.korves.net"
IPV6_SRCS[1]="ip6.mailcow.email"
until [[ ! -z ${IPV6} ]] || [[ ${TRY} -ge 10 ]]; do
IPV6=$(curl --connect-timeout 3 -m 10 -L6s ${IPV6_SRCS[$RANDOM % ${#IPV6_SRCS[@]} ]} | grep "^\([0-9a-fA-F]\{0,4\}:\)\{1,7\}[0-9a-fA-F]\{0,4\}$")
[[ ! -z ${TRY} ]] && sleep 1
Expand Down Expand Up @@ -131,7 +129,7 @@ else
fi

log_f "Waiting for database... "
while ! mysqladmin ping --host mysql -u${DBUSER} -p${DBPASS} --silent; do
while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
sleep 2
done
log_f "Initializing, please wait... "
Expand All @@ -153,20 +151,33 @@ while true; do
IPV6=$(get_ipv6)
log_f "OK" no_date

# Hard-fail on CAA errors for MAILCOW_HOSTNAME
MH_PARENT_DOMAIN=$(echo ${MAILCOW_HOSTNAME} | cut -d. -f2-)
MH_CAAS=( $(dig CAA ${MH_PARENT_DOMAIN} +short | sed -n 's/\d issue "\(.*\)"/\1/p') )
if [[ ! -z ${MH_CAAS} ]]; then
if [[ ${MH_CAAS[@]} =~ "letsencrypt.org" ]]; then
echo "Validated CAA for parent domain ${MH_PARENT_DOMAIN}"
else
echo "Skipping ACME validation: Lets Encrypt disallowed for ${MAILCOW_HOSTNAME} by CAA record, retrying in 1h..."
sleep 1h
exec $(readlink -f "$0")
fi
fi

# Container ids may have changed
CONTAINERS_RESTART=($(curl --silent http://dockerapi:8080/containers/json | jq -r '.[] | {name: .Config.Labels["com.docker.compose.service"], id: .Id}' | jq -rc 'select( .name | tostring | contains("nginx-mailcow") or contains("postfix-mailcow") or contains("dovecot-mailcow")) | .id' | tr "\n" " "))
CONTAINERS_RESTART=($(curl --silent --insecure https://dockerapi/containers/json | jq -r '.[] | {name: .Config.Labels["com.docker.compose.service"], id: .Id}' | jq -rc 'select( .name | tostring | contains("nginx-mailcow") or contains("postfix-mailcow") or contains("dovecot-mailcow")) | .id' | tr "\n" " "))

log_f "Waiting for domain table... " no_nl
while [[ -z ${DOMAIN_TABLE} ]]; do
curl --silent http://nginx/ >/dev/null 2>&1
DOMAIN_TABLE=$(mysql -h mysql-mailcow -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SHOW TABLES LIKE 'domain'" -Bs)
DOMAIN_TABLE=$(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SHOW TABLES LIKE 'domain'" -Bs)
[[ -z ${DOMAIN_TABLE} ]] && sleep 10
done
log_f "OK" no_date

while read domains; do
SQL_DOMAIN_ARR+=("${domains}")
done < <(mysql -h mysql-mailcow -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain FROM domain WHERE backupmx=0 UNION SELECT alias_domain FROM alias_domain" -Bs)
done < <(mysql --socket=/var/run/mysqld/mysqld.sock -u ${DBUSER} -p${DBPASS} ${DBNAME} -e "SELECT domain FROM domain WHERE backupmx=0 UNION SELECT alias_domain FROM alias_domain" -Bs)

for SQL_DOMAIN in "${SQL_DOMAIN_ARR[@]}"; do
A_CONFIG=$(dig A autoconfig.${SQL_DOMAIN} +short | tail -n 1)
Expand Down Expand Up @@ -249,6 +260,17 @@ while true; do
fi

for SAN in "${ADDITIONAL_SAN_ARR[@]}"; do
# Skip on CAA errors for SAN
SAN_PARENT_DOMAIN=$(echo ${SAN} | cut -d. -f2-)
SAN_CAAS=( $(dig CAA ${SAN_PARENT_DOMAIN} +short | sed -n 's/\d issue "\(.*\)"/\1/p') )
if [[ ! -z ${SAN_CAAS} ]]; then
if [[ ${SAN_CAAS[@]} =~ "letsencrypt.org" ]]; then
echo "Validated CAA for parent domain ${SAN_PARENT_DOMAIN} of ${SAN}"
else
echo "Skipping ACME validation for ${SAN}: Lets Encrypt disallowed for ${SAN} by CAA record"
continue
fi
fi
if [[ ${SAN} == ${MAILCOW_HOSTNAME} ]]; then
continue
fi
Expand Down Expand Up @@ -306,10 +328,10 @@ while true; do
-k ${ACME_BASE}/acme/private/privkey.pem \
-c ${ACME_BASE}/acme \
${ALL_VALIDATED[*]} 2>&1 | tee /dev/fd/5)

case "$?" in
0) # new certs
log_f "${ACME_RESPONSE}" redis_only
ACME_RESPONSE_B64=$(echo ${ACME_RESPONSE} | openssl enc -e -A -base64)
log_f "${ACME_RESPONSE_B64}" redis_only b64
# cp the new certificates and keys
cp ${ACME_BASE}/acme/fullchain.pem ${ACME_BASE}/cert.pem
cp ${ACME_BASE}/acme/private/privkey.pem ${ACME_BASE}/key.pem
Expand All @@ -323,7 +345,8 @@ while true; do
restart_containers ${CONTAINERS_RESTART[*]}
;;
1) # failure
log_f "${ACME_RESPONSE}" redis_only
ACME_RESPONSE_B64=$(echo ${ACME_RESPONSE} | openssl enc -e -A -base64)
log_f "${ACME_RESPONSE_B64}" redis_only b64
if [[ $ACME_RESPONSE =~ "No registration exists" ]]; then
log_f "Registration keys are invalid, deleting old keys and restarting..."
rm ${ACME_BASE}/acme/private/account.key
Expand Down Expand Up @@ -352,7 +375,8 @@ while true; do
exec $(readlink -f "$0")
;;
2) # no change
log_f "${ACME_RESPONSE}" redis_only
ACME_RESPONSE_B64=$(echo ${ACME_RESPONSE} | openssl enc -e -A -base64)
log_f "${ACME_RESPONSE_B64}" redis_only b64
if ! diff ${ACME_BASE}/acme/fullchain.pem ${ACME_BASE}/cert.pem; then
log_f "Certificate was not changed, but active certificate does not match the verified certificate, fixing and restarting containers..."
cp ${ACME_BASE}/acme/fullchain.pem ${ACME_BASE}/cert.pem
Expand All @@ -369,7 +393,8 @@ while true; do
[[ ${TRIGGER_RESTART} == 1 ]] && restart_containers ${CONTAINERS_RESTART[*]}
;;
*) # unspecified
log_f "${ACME_RESPONSE}" redis_only
ACME_RESPONSE_B64=$(echo ${ACME_RESPONSE} | openssl enc -e -A -base64)
log_f "${ACME_RESPONSE_B64}" redis_only b64
if [[ -f ${ACME_BASE}/acme/private/${DATE}.bak/fullchain.pem ]] && [[ -f ${ACME_BASE}/acme/private/${DATE}.bak/privkey.pem ]]; then
log_f "Error requesting certificate, restoring previous certificate from backup and restarting containers...."
cp ${ACME_BASE}/acme/private/${DATE}.bak/fullchain.pem ${ACME_BASE}/cert.pem
Expand Down
4 changes: 4 additions & 0 deletions data/Dockerfiles/clamd/bootstrap.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,10 @@ chown root:tty /dev/console
chmod g+rw /dev/console

# Prepare
[[ ! -f /var/lib/clamav/whitelist.ign2 ]] && touch /var/lib/clamav/whitelist.ign2
dos2unix /var/lib/clamav/whitelist.ign2
sed -i '/^\s*$/d' /var/lib/clamav/whitelist.ign2

BACKGROUND_TASKS=()

(
Expand Down
8 changes: 5 additions & 3 deletions data/Dockerfiles/dockerapi/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,8 +1,10 @@
FROM python:2-alpine
FROM alpine:3.8
LABEL maintainer "Andre Peters <andre.peters@servercow.de>"

RUN apk add -U --no-cache iptables ip6tables tzdata
RUN pip install docker==3.0.1 flask flask-restful
RUN apk add -U --no-cache python2 python-dev py-pip gcc musl-dev tzdata openssl-dev libffi-dev \
&& pip2 install --upgrade docker==3.0.1 flask flask-restful pyOpenSSL \
&& apk del python-dev py2-pip gcc

COPY server.py /

CMD ["python2", "-u", "/server.py"]
Loading