update.sh 73 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551
  1. #!/usr/bin/env bash
  2. ############## Begin Function Section ##############
  3. check_online_status() {
  4. CHECK_ONLINE_DOMAINS=('https://github.com' 'https://hub.docker.com')
  5. for domain in "${CHECK_ONLINE_DOMAINS[@]}"; do
  6. if timeout 6 curl --head --silent --output /dev/null ${domain}; then
  7. return 0
  8. fi
  9. done
  10. return 1
  11. }
  12. prefetch_images() {
  13. [[ -z ${BRANCH} ]] && { echo -e "\e[33m\nUnknown branch...\e[0m"; exit 1; }
  14. git fetch origin #${BRANCH}
  15. while read image; do
  16. if [[ "${image}" == "robbertkl/ipv6nat" ]]; then
  17. if ! grep -qi "ipv6nat-mailcow" docker-compose.yml || grep -qi "enable_ipv6: false" docker-compose.yml; then
  18. continue
  19. fi
  20. fi
  21. RET_C=0
  22. until docker pull "${image}"; do
  23. RET_C=$((RET_C + 1))
  24. echo -e "\e[33m\nError pulling $image, retrying...\e[0m"
  25. [ ${RET_C} -gt 3 ] && { echo -e "\e[31m\nToo many failed retries, exiting\e[0m"; exit 1; }
  26. sleep 1
  27. done
  28. done < <(git show "origin/${BRANCH}:docker-compose.yml" | grep "image:" | awk '{ gsub("image:","", $3); print $2 }')
  29. }
  30. docker_garbage() {
  31. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  32. IMGS_TO_DELETE=()
  33. declare -A IMAGES_INFO
  34. COMPOSE_IMAGES=($(grep -oP "image: \Kmailcow.+" "${SCRIPT_DIR}/docker-compose.yml"))
  35. for existing_image in $(docker images --format "{{.ID}}:{{.Repository}}:{{.Tag}}" | grep 'mailcow/'); do
  36. ID=$(echo "$existing_image" | cut -d ':' -f 1)
  37. REPOSITORY=$(echo "$existing_image" | cut -d ':' -f 2)
  38. TAG=$(echo "$existing_image" | cut -d ':' -f 3)
  39. if [[ " ${COMPOSE_IMAGES[@]} " =~ " ${REPOSITORY}:${TAG} " ]]; then
  40. continue
  41. else
  42. IMGS_TO_DELETE+=("$ID")
  43. IMAGES_INFO["$ID"]="$REPOSITORY:$TAG"
  44. fi
  45. done
  46. if [[ ! -z ${IMGS_TO_DELETE[*]} ]]; then
  47. echo "The following unused mailcow images were found:"
  48. for id in "${IMGS_TO_DELETE[@]}"; do
  49. echo " ${IMAGES_INFO[$id]} ($id)"
  50. done
  51. if [ ! $FORCE ]; then
  52. read -r -p "Do you want to delete them to free up some space? [y/N] " response
  53. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  54. docker rmi ${IMGS_TO_DELETE[*]}
  55. else
  56. echo "OK, skipped."
  57. fi
  58. else
  59. echo "Running in forced mode! Force removing old mailcow images..."
  60. docker rmi ${IMGS_TO_DELETE[*]}
  61. fi
  62. echo -e "\e[32mFurther cleanup...\e[0m"
  63. echo "If you want to cleanup further garbage collected by Docker, please make sure all containers are up and running before cleaning your system by executing \"docker system prune\""
  64. fi
  65. }
  66. in_array() {
  67. local e match="$1"
  68. shift
  69. for e; do [[ "$e" == "$match" ]] && return 0; done
  70. return 1
  71. }
  72. migrate_docker_nat() {
  73. NAT_CONFIG='{"ipv6":true,"fixed-cidr-v6":"fd00:dead:beef:c0::/80","experimental":true,"ip6tables":true}'
  74. # Min Docker version
  75. DOCKERV_REQ=20.10.2
  76. # Current Docker version
  77. DOCKERV_CUR=$(docker version -f '{{.Server.Version}}')
  78. if grep -qi "ipv6nat-mailcow" docker-compose.yml && grep -qi "enable_ipv6: true" docker-compose.yml; then
  79. echo -e "\e[32mNative IPv6 implementation available.\e[0m"
  80. echo "This will enable experimental features in the Docker daemon and configure Docker to do the IPv6 NATing instead of ipv6nat-mailcow."
  81. echo '!!! This step is recommended !!!'
  82. echo "mailcow will try to roll back the changes if starting Docker fails after modifying the daemon.json configuration file."
  83. read -r -p "Should we try to enable the native IPv6 implementation in Docker now (recommended)? [y/N] " dockernatresponse
  84. if [[ ! "${dockernatresponse}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  85. echo "OK, skipping this step."
  86. return 0
  87. fi
  88. fi
  89. # Sort versions and check if we are running a newer or equal version to req
  90. if [ $(printf "${DOCKERV_REQ}\n${DOCKERV_CUR}" | sort -V | tail -n1) == "${DOCKERV_CUR}" ]; then
  91. # If Dockerd daemon json exists
  92. if [ -s /etc/docker/daemon.json ]; then
  93. IFS=',' read -r -a dockerconfig <<< $(cat /etc/docker/daemon.json | tr -cd '[:alnum:],')
  94. if ! in_array ipv6true "${dockerconfig[@]}" || \
  95. ! in_array experimentaltrue "${dockerconfig[@]}" || \
  96. ! in_array ip6tablestrue "${dockerconfig[@]}" || \
  97. ! grep -qi "fixed-cidr-v6" /etc/docker/daemon.json; then
  98. echo -e "\e[33mWarning:\e[0m You seem to have modified the /etc/docker/daemon.json configuration by yourself and not fully/correctly activated the native IPv6 NAT implementation."
  99. echo "You will need to merge your existing configuration manually or fix/delete the existing daemon.json configuration before trying the update process again."
  100. echo -e "Please merge the following content and restart the Docker daemon:\n"
  101. echo "${NAT_CONFIG}"
  102. return 1
  103. fi
  104. else
  105. echo "Working on IPv6 NAT, please wait..."
  106. echo "${NAT_CONFIG}" > /etc/docker/daemon.json
  107. ip6tables -F -t nat
  108. [[ -e /etc/rc.conf ]] && rc-service docker restart || systemctl restart docker.service
  109. if [[ $? -ne 0 ]]; then
  110. echo -e "\e[31mError:\e[0m Failed to activate IPv6 NAT! Reverting and exiting."
  111. rm /etc/docker/daemon.json
  112. if [[ -e /etc/rc.conf ]]; then
  113. rc-service docker restart
  114. else
  115. systemctl reset-failed docker.service
  116. systemctl restart docker.service
  117. fi
  118. return 1
  119. fi
  120. fi
  121. # Removing legacy container
  122. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.yml
  123. if [ -s docker-compose.override.yml ]; then
  124. sed -i '/ipv6nat-mailcow:$/,/^$/d' docker-compose.override.yml
  125. if [[ "$(cat docker-compose.override.yml | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  126. mv docker-compose.override.yml docker-compose.override.yml_backup
  127. fi
  128. fi
  129. echo -e "\e[32mGreat! \e[0mNative IPv6 NAT is active.\e[0m"
  130. else
  131. echo -e "\e[31mPlease upgrade Docker to version ${DOCKERV_REQ} or above.\e[0m"
  132. return 0
  133. fi
  134. }
  135. remove_obsolete_nginx_ports() {
  136. # Removing obsolete docker-compose.override.yml
  137. for override in docker-compose.override.yml docker-compose.override.yaml; do
  138. if [ -s $override ] ; then
  139. if cat $override | grep nginx-mailcow > /dev/null 2>&1; then
  140. if cat $override | grep -E '(\[::])' > /dev/null 2>&1; then
  141. if cat $override | grep -w 80:80 > /dev/null 2>&1 && cat $override | grep -w 443:443 > /dev/null 2>&1 ; then
  142. echo -e "\e[33mBacking up ${override} to preserve custom changes...\e[0m"
  143. echo -e "\e[33m!!! Manual Merge needed (if other overrides are set) !!!\e[0m"
  144. sleep 3
  145. cp $override ${override}_backup
  146. sed -i '/nginx-mailcow:$/,/^$/d' $override
  147. echo -e "\e[33mRemoved obsolete NGINX IPv6 Bind from original override File.\e[0m"
  148. if [[ "$(cat $override | sed '/^\s*$/d' | wc -l)" == "2" ]]; then
  149. mv $override ${override}_empty
  150. echo -e "\e[31m${override} is empty. Renamed it to ensure mailcow is startable.\e[0m"
  151. fi
  152. fi
  153. fi
  154. fi
  155. fi
  156. done
  157. }
  158. detect_docker_compose_command(){
  159. if ! [[ "${DOCKER_COMPOSE_VERSION}" =~ ^(native|standalone)$ ]]; then
  160. if docker compose > /dev/null 2>&1; then
  161. if docker compose version --short | grep -e "^2." -e "^v2." > /dev/null 2>&1; then
  162. DOCKER_COMPOSE_VERSION=native
  163. COMPOSE_COMMAND="docker compose"
  164. echo -e "\e[33mFound Docker Compose Plugin (native).\e[0m"
  165. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to native\e[0m"
  166. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' "$SCRIPT_DIR/mailcow.conf"
  167. sleep 2
  168. echo -e "\e[33mNotice: You'll have to update this Compose Version via your Package Manager manually!\e[0m"
  169. else
  170. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  171. echo -e "\e[31mPlease update/install it manually regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  172. exit 1
  173. fi
  174. elif docker-compose > /dev/null 2>&1; then
  175. if ! [[ $(alias docker-compose 2> /dev/null) ]] ; then
  176. if docker-compose version --short | grep "^2." > /dev/null 2>&1; then
  177. DOCKER_COMPOSE_VERSION=standalone
  178. COMPOSE_COMMAND="docker-compose"
  179. echo -e "\e[33mFound Docker Compose Standalone.\e[0m"
  180. echo -e "\e[33mSetting the DOCKER_COMPOSE_VERSION Variable to standalone\e[0m"
  181. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' "$SCRIPT_DIR/mailcow.conf"
  182. sleep 2
  183. echo -e "\e[33mNotice: For an automatic update of docker-compose please use the update_compose.sh scripts located at the helper-scripts folder.\e[0m"
  184. else
  185. echo -e "\e[31mCannot find Docker Compose with a Version Higher than 2.X.X.\e[0m"
  186. echo -e "\e[31mPlease update/install regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  187. exit 1
  188. fi
  189. fi
  190. else
  191. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  192. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  193. exit 1
  194. fi
  195. elif [ "${DOCKER_COMPOSE_VERSION}" == "native" ]; then
  196. COMPOSE_COMMAND="docker compose"
  197. # Check if Native Compose works and has not been deleted
  198. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  199. # IF it not exists/work anymore try the other command
  200. COMPOSE_COMMAND="docker-compose"
  201. if ! $COMPOSE_COMMAND > /dev/null 2>&1 || ! $COMPOSE_COMMAND --version | grep "^2." > /dev/null 2>&1; then
  202. # IF it cannot find Standalone in > 2.X, then script stops
  203. echo -e "\e[31mCannot find Docker Compose or the Version is lower then 2.X.X.\e[0m"
  204. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  205. exit 1
  206. fi
  207. # If it finds the standalone Plugin it will use this instead and change the mailcow.conf Variable accordingly
  208. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  209. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from native to standalone\e[0m"
  210. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=standalone/' "$SCRIPT_DIR/mailcow.conf"
  211. sleep 2
  212. fi
  213. elif [ "${DOCKER_COMPOSE_VERSION}" == "standalone" ]; then
  214. COMPOSE_COMMAND="docker-compose"
  215. # Check if Standalone Compose works and has not been deleted
  216. if ! $COMPOSE_COMMAND > /dev/null 2>&1 && ! $COMPOSE_COMMAND --version > /dev/null 2>&1 | grep "^2." > /dev/null 2>&1; then
  217. # IF it not exists/work anymore try the other command
  218. COMPOSE_COMMAND="docker compose"
  219. if ! $COMPOSE_COMMAND > /dev/null 2>&1; then
  220. # IF it cannot find Native in > 2.X, then script stops
  221. echo -e "\e[31mCannot find Docker Compose.\e[0m"
  222. echo -e "\e[31mPlease install it regarding to this doc site: https://docs.mailcow.email/install/\e[0m"
  223. exit 1
  224. fi
  225. # If it finds the native Plugin it will use this instead and change the mailcow.conf Variable accordingly
  226. echo -e "\e[31mFound different Docker Compose Version then declared in mailcow.conf!\e[0m"
  227. echo -e "\e[31mSetting the DOCKER_COMPOSE_VERSION Variable from standalone to native\e[0m"
  228. sed -i 's/^DOCKER_COMPOSE_VERSION=.*/DOCKER_COMPOSE_VERSION=native/' "$SCRIPT_DIR/mailcow.conf"
  229. sleep 2
  230. fi
  231. fi
  232. }
  233. detect_bad_asn() {
  234. echo -e "\e[33mDetecting if your IP is listed on Spamhaus Bad ASN List...\e[0m"
  235. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  236. if [ "$response" -eq 503 ]; then
  237. if [ -z "$SPAMHAUS_DQS_KEY" ]; then
  238. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  239. echo -e "\e[33mmailcow did not detected a value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf!\e[0m"
  240. sleep 2
  241. echo ""
  242. echo -e "\e[33mTo use the Spamhaus DNS Blocklists again, you will need to create a FREE account for their Data Query Service (DQS) at: https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account\e[0m"
  243. echo -e "\e[33mOnce done, enter your DQS API key in mailcow.conf and mailcow will do the rest for you!\e[0m"
  244. echo ""
  245. sleep 2
  246. else
  247. echo -e "\e[33mYour server's public IP uses an AS that is blocked by Spamhaus to use their DNS public blocklists for Postfix.\e[0m"
  248. echo -e "\e[32mmailcow detected a Value for the variable SPAMHAUS_DQS_KEY inside mailcow.conf. Postfix will use DQS with the given API key...\e[0m"
  249. fi
  250. elif [ "$response" -eq 200 ]; then
  251. echo -e "\e[33mCheck completed! Your IP is \e[32mclean\e[0m"
  252. elif [ "$response" -eq 429 ]; then
  253. echo -e "\e[33mCheck completed! \e[31mYour IP seems to be rate limited on the ASN Check service... please try again later!\e[0m"
  254. else
  255. echo -e "\e[31mCheck failed! \e[0mMaybe a DNS or Network problem?\e[0m"
  256. fi
  257. }
  258. fix_broken_dnslist_conf() {
  259. # Fixing issue: #6143. To be removed in a later patch
  260. local file="${SCRIPT_DIR}/data/conf/postfix/dns_blocklists.cf"
  261. # Check if the file exists
  262. if [[ ! -f "$file" ]]; then
  263. return 1
  264. fi
  265. # Check if the file contains the autogenerated comment
  266. if grep -q "# Autogenerated by mailcow" "$file"; then
  267. # Ask the user if custom changes were made
  268. echo -e "\e[91mWARNING!!! \e[31mAn old version of dns_blocklists.cf has been detected which may cause a broken postfix upon startup (see: https://github.com/mailcow/mailcow-dockerized/issues/6143)...\e[0m"
  269. echo -e "\e[31mIf you have any custom settings in there you might copy it away and adapt the changes after the file is regenerated...\e[0m"
  270. read -p "Do you want to delete the file now and let mailcow regenerate it properly? [y/n]" response
  271. if [[ "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  272. rm "$file"
  273. echo -e "\e[32mdns_blocklists.cf has been deleted and will be properly regenerated"
  274. return 0
  275. else
  276. echo -e "\e[35mOk, not deleting it! Please make sure you take a look at postfix upon start then..."
  277. return 2
  278. fi
  279. fi
  280. }
  281. adapt_new_options() {
  282. CONFIG_ARRAY=(
  283. "SKIP_LETS_ENCRYPT"
  284. "SKIP_SOGO"
  285. "USE_WATCHDOG"
  286. "WATCHDOG_NOTIFY_EMAIL"
  287. "WATCHDOG_NOTIFY_WEBHOOK"
  288. "WATCHDOG_NOTIFY_WEBHOOK_BODY"
  289. "WATCHDOG_NOTIFY_BAN"
  290. "WATCHDOG_NOTIFY_START"
  291. "WATCHDOG_EXTERNAL_CHECKS"
  292. "WATCHDOG_SUBJECT"
  293. "SKIP_CLAMD"
  294. "SKIP_IP_CHECK"
  295. "ADDITIONAL_SAN"
  296. "DOVEADM_PORT"
  297. "IPV4_NETWORK"
  298. "IPV6_NETWORK"
  299. "LOG_LINES"
  300. "SNAT_TO_SOURCE"
  301. "SNAT6_TO_SOURCE"
  302. "COMPOSE_PROJECT_NAME"
  303. "DOCKER_COMPOSE_VERSION"
  304. "SQL_PORT"
  305. "API_KEY"
  306. "API_KEY_READ_ONLY"
  307. "API_ALLOW_FROM"
  308. "MAILDIR_GC_TIME"
  309. "MAILDIR_SUB"
  310. "ACL_ANYONE"
  311. "FTS_HEAP"
  312. "FTS_PROCS"
  313. "SKIP_FTS"
  314. "ENABLE_SSL_SNI"
  315. "ALLOW_ADMIN_EMAIL_LOGIN"
  316. "SKIP_HTTP_VERIFICATION"
  317. "SOGO_EXPIRE_SESSION"
  318. "REDIS_PORT"
  319. "DOVECOT_MASTER_USER"
  320. "DOVECOT_MASTER_PASS"
  321. "MAILCOW_PASS_SCHEME"
  322. "ADDITIONAL_SERVER_NAMES"
  323. "ACME_CONTACT"
  324. "WATCHDOG_VERBOSE"
  325. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  326. "SPAMHAUS_DQS_KEY"
  327. "SKIP_UNBOUND_HEALTHCHECK"
  328. "DISABLE_NETFILTER_ISOLATION_RULE"
  329. "HTTP_REDIRECT"
  330. )
  331. sed -i --follow-symlinks '$a\' mailcow.conf
  332. for option in ${CONFIG_ARRAY[@]}; do
  333. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  334. if ! grep -q ${option} mailcow.conf; then
  335. echo "Adding new option \"${option}\" to mailcow.conf"
  336. echo "${option}=" >> mailcow.conf
  337. fi
  338. elif [[ ${option} == "COMPOSE_PROJECT_NAME" ]]; then
  339. if ! grep -q ${option} mailcow.conf; then
  340. echo "Adding new option \"${option}\" to mailcow.conf"
  341. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  342. fi
  343. elif [[ ${option} == "DOCKER_COMPOSE_VERSION" ]]; then
  344. if ! grep -q ${option} mailcow.conf; then
  345. echo "Adding new option \"${option}\" to mailcow.conf"
  346. echo "# Used Docker Compose version" >> mailcow.conf
  347. echo "# Switch here between native (compose plugin) and standalone" >> mailcow.conf
  348. echo "# For more informations take a look at the mailcow docs regarding the configuration options." >> mailcow.conf
  349. echo "# Normally this should be untouched but if you decided to use either of those you can switch it manually here." >> mailcow.conf
  350. echo "# Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail." >> mailcow.conf
  351. echo "" >> mailcow.conf
  352. echo "DOCKER_COMPOSE_VERSION=${DOCKER_COMPOSE_VERSION}" >> mailcow.conf
  353. fi
  354. elif [[ ${option} == "DOVEADM_PORT" ]]; then
  355. if ! grep -q ${option} mailcow.conf; then
  356. echo "Adding new option \"${option}\" to mailcow.conf"
  357. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  358. fi
  359. elif [[ ${option} == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  360. if ! grep -q ${option} mailcow.conf; then
  361. echo "Adding new option \"${option}\" to mailcow.conf"
  362. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  363. fi
  364. elif [[ ${option} == "LOG_LINES" ]]; then
  365. if ! grep -q ${option} mailcow.conf; then
  366. echo "Adding new option \"${option}\" to mailcow.conf"
  367. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  368. echo "LOG_LINES=9999" >> mailcow.conf
  369. fi
  370. elif [[ ${option} == "IPV4_NETWORK" ]]; then
  371. if ! grep -q ${option} mailcow.conf; then
  372. echo "Adding new option \"${option}\" to mailcow.conf"
  373. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  374. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  375. fi
  376. elif [[ ${option} == "IPV6_NETWORK" ]]; then
  377. if ! grep -q ${option} mailcow.conf; then
  378. echo "Adding new option \"${option}\" to mailcow.conf"
  379. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  380. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  381. fi
  382. elif [[ ${option} == "SQL_PORT" ]]; then
  383. if ! grep -q ${option} mailcow.conf; then
  384. echo "Adding new option \"${option}\" to mailcow.conf"
  385. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  386. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  387. fi
  388. elif [[ ${option} == "API_KEY" ]]; then
  389. if ! grep -q ${option} mailcow.conf; then
  390. echo "Adding new option \"${option}\" to mailcow.conf"
  391. echo '# Create or override API key for web UI' >> mailcow.conf
  392. echo "#API_KEY=" >> mailcow.conf
  393. fi
  394. elif [[ ${option} == "API_KEY_READ_ONLY" ]]; then
  395. if ! grep -q ${option} mailcow.conf; then
  396. echo "Adding new option \"${option}\" to mailcow.conf"
  397. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  398. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  399. fi
  400. elif [[ ${option} == "API_ALLOW_FROM" ]]; then
  401. if ! grep -q ${option} mailcow.conf; then
  402. echo "Adding new option \"${option}\" to mailcow.conf"
  403. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  404. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  405. echo "#API_ALLOW_FROM=" >> mailcow.conf
  406. fi
  407. elif [[ ${option} == "SNAT_TO_SOURCE" ]]; then
  408. if ! grep -q ${option} mailcow.conf; then
  409. echo "Adding new option \"${option}\" to mailcow.conf"
  410. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  411. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  412. fi
  413. elif [[ ${option} == "SNAT6_TO_SOURCE" ]]; then
  414. if ! grep -q ${option} mailcow.conf; then
  415. echo "Adding new option \"${option}\" to mailcow.conf"
  416. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  417. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  418. fi
  419. elif [[ ${option} == "MAILDIR_GC_TIME" ]]; then
  420. if ! grep -q ${option} mailcow.conf; then
  421. echo "Adding new option \"${option}\" to mailcow.conf"
  422. echo '# Garbage collector cleanup' >> mailcow.conf
  423. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  424. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  425. echo '# Check interval is hourly' >> mailcow.conf
  426. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  427. fi
  428. elif [[ ${option} == "ACL_ANYONE" ]]; then
  429. if ! grep -q ${option} mailcow.conf; then
  430. echo "Adding new option \"${option}\" to mailcow.conf"
  431. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  432. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  433. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  434. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  435. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  436. fi
  437. elif [[ ${option} == "FTS_HEAP" ]]; then
  438. if ! grep -q ${option} mailcow.conf; then
  439. echo "Adding new option \"${option}\" to mailcow.conf"
  440. echo '# Dovecot Indexing (FTS) Process maximum heap size in MB, there is no recommendation, please see Dovecot docs.' >> mailcow.conf
  441. echo '# Flatcurve is used as FTS Engine. It is supposed to be pretty efficient in CPU and RAM consumption.' >> mailcow.conf
  442. echo '# Please always monitor your Resource consumption!' >> mailcow.conf
  443. echo "FTS_HEAP=128" >> mailcow.conf
  444. fi
  445. elif [[ ${option} == "SKIP_FTS" ]]; then
  446. if ! grep -q ${option} mailcow.conf; then
  447. echo "Adding new option \"${option}\" to mailcow.conf"
  448. echo '# Skip FTS (Fulltext Search) for Dovecot on low-memory, low-threaded systems or if you simply want to disable it.' >> mailcow.conf
  449. echo "# Dovecot inside mailcow use Flatcurve as FTS Backend." >> mailcow.conf
  450. echo "SKIP_FTS=y" >> mailcow.conf
  451. fi
  452. elif [[ ${option} == "FTS_PROCS" ]]; then
  453. if ! grep -q ${option} mailcow.conf; then
  454. echo "Adding new option \"${option}\" to mailcow.conf"
  455. echo '# Controls how many processes the Dovecot indexing process can spawn at max.' >> mailcow.conf
  456. echo '# Too many indexing processes can use a lot of CPU and Disk I/O' >> mailcow.conf
  457. echo '# Please visit: https://doc.dovecot.org/configuration_manual/service_configuration/#indexer-worker for more informations' >> mailcow.conf
  458. echo "FTS_PROCS=1" >> mailcow.conf
  459. fi
  460. elif [[ ${option} == "ENABLE_SSL_SNI" ]]; then
  461. if ! grep -q ${option} mailcow.conf; then
  462. echo "Adding new option \"${option}\" to mailcow.conf"
  463. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  464. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  465. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  466. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  467. fi
  468. elif [[ ${option} == "SKIP_SOGO" ]]; then
  469. if ! grep -q ${option} mailcow.conf; then
  470. echo "Adding new option \"${option}\" to mailcow.conf"
  471. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  472. echo "SKIP_SOGO=n" >> mailcow.conf
  473. fi
  474. elif [[ ${option} == "MAILDIR_SUB" ]]; then
  475. if ! grep -q ${option} mailcow.conf; then
  476. echo "Adding new option \"${option}\" to mailcow.conf"
  477. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  478. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  479. echo "MAILDIR_SUB=" >> mailcow.conf
  480. fi
  481. elif [[ ${option} == "WATCHDOG_NOTIFY_WEBHOOK" ]]; then
  482. if ! grep -q ${option} mailcow.conf; then
  483. echo "Adding new option \"${option}\" to mailcow.conf"
  484. echo '# Send notifications to a webhook URL that receives a POST request with the content type "application/json".' >> mailcow.conf
  485. echo '# You can use this to send notifications to services like Discord, Slack and others.' >> mailcow.conf
  486. echo '#WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX' >> mailcow.conf
  487. fi
  488. elif [[ ${option} == "WATCHDOG_NOTIFY_WEBHOOK_BODY" ]]; then
  489. if ! grep -q ${option} mailcow.conf; then
  490. echo "Adding new option \"${option}\" to mailcow.conf"
  491. echo '# JSON body included in the webhook POST request. Needs to be in single quotes.' >> mailcow.conf
  492. echo '# Following variables are available: SUBJECT, BODY' >> mailcow.conf
  493. WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  494. echo "#WATCHDOG_NOTIFY_WEBHOOK_BODY='${WEBHOOK_BODY}'" >> mailcow.conf
  495. fi
  496. elif [[ ${option} == "WATCHDOG_NOTIFY_BAN" ]]; then
  497. if ! grep -q ${option} mailcow.conf; then
  498. echo "Adding new option \"${option}\" to mailcow.conf"
  499. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  500. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  501. fi
  502. elif [[ ${option} == "WATCHDOG_NOTIFY_START" ]]; then
  503. if ! grep -q ${option} mailcow.conf; then
  504. echo "Adding new option \"${option}\" to mailcow.conf"
  505. echo '# Send a notification when the watchdog is started.' >> mailcow.conf
  506. echo "WATCHDOG_NOTIFY_START=y" >> mailcow.conf
  507. fi
  508. elif [[ ${option} == "WATCHDOG_SUBJECT" ]]; then
  509. if ! grep -q ${option} mailcow.conf; then
  510. echo "Adding new option \"${option}\" to mailcow.conf"
  511. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  512. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  513. fi
  514. elif [[ ${option} == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  515. if ! grep -q ${option} mailcow.conf; then
  516. echo "Adding new option \"${option}\" to mailcow.conf"
  517. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  518. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  519. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  520. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  521. fi
  522. elif [[ ${option} == "SOGO_EXPIRE_SESSION" ]]; then
  523. if ! grep -q ${option} mailcow.conf; then
  524. echo "Adding new option \"${option}\" to mailcow.conf"
  525. echo '# SOGo session timeout in minutes' >> mailcow.conf
  526. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  527. fi
  528. elif [[ ${option} == "REDIS_PORT" ]]; then
  529. if ! grep -q ${option} mailcow.conf; then
  530. echo "Adding new option \"${option}\" to mailcow.conf"
  531. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  532. fi
  533. elif [[ ${option} == "DOVECOT_MASTER_USER" ]]; then
  534. if ! grep -q ${option} mailcow.conf; then
  535. echo "Adding new option \"${option}\" to mailcow.conf"
  536. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  537. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  538. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  539. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  540. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  541. fi
  542. elif [[ ${option} == "DOVECOT_MASTER_PASS" ]]; then
  543. if ! grep -q ${option} mailcow.conf; then
  544. echo "Adding new option \"${option}\" to mailcow.conf"
  545. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  546. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  547. fi
  548. elif [[ ${option} == "MAILCOW_PASS_SCHEME" ]]; then
  549. if ! grep -q ${option} mailcow.conf; then
  550. echo "Adding new option \"${option}\" to mailcow.conf"
  551. echo '# Password hash algorithm' >> mailcow.conf
  552. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  553. echo '# see https://docs.mailcow.email/models/model-passwd/' >> mailcow.conf
  554. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  555. fi
  556. elif [[ ${option} == "ADDITIONAL_SERVER_NAMES" ]]; then
  557. if ! grep -q ${option} mailcow.conf; then
  558. echo "Adding new option \"${option}\" to mailcow.conf"
  559. echo '# Additional server names for mailcow UI' >> mailcow.conf
  560. echo '#' >> mailcow.conf
  561. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  562. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  563. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  564. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  565. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  566. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  567. fi
  568. elif [[ ${option} == "ACME_CONTACT" ]]; then
  569. if ! grep -q ${option} mailcow.conf; then
  570. echo "Adding new option \"${option}\" to mailcow.conf"
  571. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  572. echo '# Optional: Leave empty for none' >> mailcow.conf
  573. echo '# This value is only used on first order!' >> mailcow.conf
  574. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  575. echo '# https://docs.mailcow.email/troubleshooting/debug-reset_tls/' >> mailcow.conf
  576. echo 'ACME_CONTACT=' >> mailcow.conf
  577. fi
  578. elif [[ ${option} == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  579. if ! grep -q ${option} mailcow.conf; then
  580. echo "Adding new option \"${option}\" to mailcow.conf"
  581. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  582. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  583. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  584. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  585. fi
  586. elif [[ ${option} == "SPAMHAUS_DQS_KEY" ]]; then
  587. if ! grep -q ${option} mailcow.conf; then
  588. echo "Adding new option \"${option}\" to mailcow.conf"
  589. echo "# Spamhaus Data Query Service Key" >> mailcow.conf
  590. echo '# Optional: Leave empty for none' >> mailcow.conf
  591. echo '# Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.' >> mailcow.conf
  592. echo '# If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.' >> mailcow.conf
  593. echo '# Otherwise it will work as usual.' >> mailcow.conf
  594. echo 'SPAMHAUS_DQS_KEY=' >> mailcow.conf
  595. fi
  596. elif [[ ${option} == "WATCHDOG_VERBOSE" ]]; then
  597. if ! grep -q ${option} mailcow.conf; then
  598. echo "Adding new option \"${option}\" to mailcow.conf"
  599. echo '# Enable watchdog verbose logging' >> mailcow.conf
  600. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  601. fi
  602. elif [[ ${option} == "SKIP_UNBOUND_HEALTHCHECK" ]]; then
  603. if ! grep -q ${option} mailcow.conf; then
  604. echo "Adding new option \"${option}\" to mailcow.conf"
  605. echo '# Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n' >> mailcow.conf
  606. echo 'SKIP_UNBOUND_HEALTHCHECK=n' >> mailcow.conf
  607. fi
  608. elif [[ ${option} == "DISABLE_NETFILTER_ISOLATION_RULE" ]]; then
  609. if ! grep -q ${option} mailcow.conf; then
  610. echo "Adding new option \"${option}\" to mailcow.conf"
  611. echo '# Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n' >> mailcow.conf
  612. echo '# CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost' >> mailcow.conf
  613. echo 'DISABLE_NETFILTER_ISOLATION_RULE=n' >> mailcow.conf
  614. fi
  615. elif [[ ${option} == "HTTP_REDIRECT" ]]; then
  616. if ! grep -q ${option} mailcow.conf; then
  617. echo "Adding new option \"${option}\" to mailcow.conf"
  618. echo '# Redirect HTTP connections to HTTPS - y/n' >> mailcow.conf
  619. echo 'HTTP_REDIRECT=n' >> mailcow.conf
  620. fi
  621. elif ! grep -q ${option} mailcow.conf; then
  622. echo "Adding new option \"${option}\" to mailcow.conf"
  623. echo "${option}=n" >> mailcow.conf
  624. fi
  625. done
  626. }
  627. migrate_solr_config_options() {
  628. sed -i --follow-symlinks '$a\' mailcow.conf
  629. if grep -q "SOLR_HEAP" mailcow.conf; then
  630. echo "Removing SOLR_HEAP in mailcow.conf"
  631. sed -i '/# Solr heap size in MB\b/d' mailcow.conf
  632. sed -i '/# Solr is a prone to run\b/d' mailcow.conf
  633. sed -i '/SOLR_HEAP\b/d' mailcow.conf
  634. fi
  635. if grep -q "SKIP_SOLR" mailcow.conf; then
  636. echo "Removing SKIP_SOLR in mailcow.conf"
  637. sed -i '/\bSkip Solr on low-memory\b/d' mailcow.conf
  638. sed -i '/\bSolr is disabled by default\b/d' mailcow.conf
  639. sed -i '/\bDisable Solr or\b/d' mailcow.conf
  640. sed -i '/\bSKIP_SOLR\b/d' mailcow.conf
  641. fi
  642. if grep -q "SOLR_PORT" mailcow.conf; then
  643. echo "Removing SOLR_PORT in mailcow.conf"
  644. sed -i '/\bSOLR_PORT\b/d' mailcow.conf
  645. fi
  646. if grep -q "FLATCURVE_EXPERIMENTAL" mailcow.conf; then
  647. echo "Removing FLATCURVE_EXPERIMENTAL in mailcow.conf"
  648. sed -i '/\bFLATCURVE_EXPERIMENTAL\b/d' mailcow.conf
  649. fi
  650. solr_volume=$(docker volume ls -qf name=^${COMPOSE_PROJECT_NAME}_solr-vol-1)
  651. if [[ -n $solr_volume ]]; then
  652. echo -e "\e[34mSolr has been replaced within mailcow since 2025-01.\nThe volume $solr_volume is unused.\e[0m"
  653. sleep 1
  654. if [ ! "$FORCE" ]; then
  655. read -r -p "Remove $solr_volume? [y/N] " response
  656. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  657. echo -e "\e[33mRemoving $solr_volume...\e[0m"
  658. docker volume rm $solr_volume || echo -e "\e[31mFailed to remove. Remove it manually!\e[0m"
  659. echo -e "\e[32mSuccessfully removed $solr_volume!\e[0m"
  660. else
  661. echo -e "Not removing $solr_volume. Run \`docker volume rm $solr_volume\` manually if needed."
  662. fi
  663. else
  664. echo -e "\e[33mForce removing $solr_volume...\e[0m"
  665. docker volume rm $solr_volume || echo -e "\e[31mFailed to remove. Remove it manually!\e[0m"
  666. echo -e "\e[32mSuccessfully removed $solr_volume!\e[0m"
  667. fi
  668. fi
  669. # Delete old fts.conf before forced switch to flatcurve to ensure update is working properly
  670. FTS_CONF_PATH="${SCRIPT_DIR}/data/conf/dovecot/conf.d/fts.conf"
  671. if [[ -f "$FTS_CONF_PATH" ]]; then
  672. if grep -q "Autogenerated by mailcow" "$FTS_CONF_PATH"; then
  673. rm -rf $FTS_CONF_PATH
  674. fi
  675. fi
  676. }
  677. ############## End Function Section ##############
  678. # Check permissions
  679. if [ "$(id -u)" -ne "0" ]; then
  680. echo "You need to be root"
  681. exit 1
  682. fi
  683. SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
  684. # Run pre-update-hook
  685. if [ -f "${SCRIPT_DIR}/pre_update_hook.sh" ]; then
  686. bash "${SCRIPT_DIR}/pre_update_hook.sh"
  687. fi
  688. if [[ "$(uname -r)" =~ ^4\.15\.0-60 ]]; then
  689. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!";
  690. echo "Please update to 5.x or use another distribution."
  691. exit 1
  692. fi
  693. if [[ "$(uname -r)" =~ ^4\.4\. ]]; then
  694. if grep -q Ubuntu <<< "$(uname -a)"; then
  695. echo "DO NOT RUN mailcow ON THIS UBUNTU KERNEL!"
  696. echo "Please update to linux-generic-hwe-16.04 by running \"apt-get install --install-recommends linux-generic-hwe-16.04\""
  697. exit 1
  698. fi
  699. echo "mailcow on a 4.4.x kernel is not supported. It may or may not work, please upgrade your kernel or continue at your own risk."
  700. read -p "Press any key to continue..." < /dev/tty
  701. fi
  702. # Exit on error and pipefail
  703. set -o pipefail
  704. # Setting high dc timeout
  705. export COMPOSE_HTTP_TIMEOUT=600
  706. # Add /opt/bin to PATH
  707. PATH=$PATH:/opt/bin
  708. umask 0022
  709. # Unset COMPOSE_COMMAND and DOCKER_COMPOSE_VERSION Variable to be on the newest state.
  710. unset COMPOSE_COMMAND
  711. unset DOCKER_COMPOSE_VERSION
  712. for bin in curl docker git awk sha1sum grep cut; do
  713. if [[ -z $(command -v ${bin}) ]]; then
  714. echo "Cannot find ${bin}, exiting..."
  715. exit 1;
  716. fi
  717. done
  718. # Check Docker Version (need at least 24.X)
  719. docker_version=$(docker -v | grep -oP '\d+\.\d+\.\d+' | cut -d '.' -f 1 | head -1)
  720. if [[ $docker_version -lt 24 ]]; then
  721. echo -e "\e[31mCannot find Docker with a Version higher or equals 24.0.0\e[0m"
  722. echo -e "\e[33mmailcow needs a newer Docker version to work properly... continuing on your own risk!\e[0m"
  723. echo -e "\e[31mPlease update your Docker installation... sleeping 10s\e[0m"
  724. sleep 10
  725. fi
  726. export LC_ALL=C
  727. DATE=$(date +%Y-%m-%d_%H_%M_%S)
  728. BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  729. while (($#)); do
  730. case "${1}" in
  731. --check|-c)
  732. echo "Checking remote code for updates..."
  733. LATEST_REV=$(git ls-remote --exit-code --refs --quiet https://github.com/mailcow/mailcow-dockerized "${BRANCH}" | cut -f1)
  734. if [ "$?" -ne 0 ]; then
  735. echo "A problem occurred while trying to fetch the latest revision from github."
  736. exit 99
  737. fi
  738. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_REV}") ]]; then
  739. echo -e "Updated code is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/commits/master"
  740. git log --date=short --pretty=format:"%ad - %s" "$(git rev-parse --short HEAD)"..origin/master
  741. exit 0
  742. else
  743. echo "No updates available."
  744. exit 3
  745. fi
  746. ;;
  747. --check-tags)
  748. echo "Checking remote tags for updates..."
  749. LATEST_TAG_REV=$(git ls-remote --exit-code --quiet --tags origin | tail -1 | cut -f1)
  750. if [ "$?" -ne 0 ]; then
  751. echo "A problem occurred while trying to fetch the latest tag from github."
  752. exit 99
  753. fi
  754. if [[ -z $(git log HEAD --pretty=format:"%H" | grep "${LATEST_TAG_REV}") ]]; then
  755. echo -e "New tag is available.\nThe changes can be found here: https://github.com/mailcow/mailcow-dockerized/releases/latest"
  756. exit 0
  757. else
  758. echo "No updates available."
  759. exit 3
  760. fi
  761. ;;
  762. --ours)
  763. MERGE_STRATEGY=ours
  764. ;;
  765. --skip-start)
  766. SKIP_START=y
  767. ;;
  768. --skip-ping-check)
  769. SKIP_PING_CHECK=y
  770. ;;
  771. --stable)
  772. CURRENT_BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  773. NEW_BRANCH="master"
  774. ;;
  775. --gc)
  776. echo -e "\e[32mCollecting garbage...\e[0m"
  777. docker_garbage
  778. exit 0
  779. ;;
  780. --nightly)
  781. CURRENT_BRANCH="$(cd "${SCRIPT_DIR}"; git rev-parse --abbrev-ref HEAD)"
  782. NEW_BRANCH="nightly"
  783. ;;
  784. --prefetch)
  785. echo -e "\e[32mPrefetching images...\e[0m"
  786. prefetch_images
  787. exit 0
  788. ;;
  789. -f|--force)
  790. echo -e "\e[32mRunning in forced mode...\e[0m"
  791. FORCE=y
  792. ;;
  793. -d|--dev)
  794. echo -e "\e[32mRunning in Developer mode...\e[0m"
  795. DEV=y
  796. ;;
  797. --help|-h)
  798. echo './update.sh [-c|--check, --check-tags, --ours, --gc, --nightly, --prefetch, --skip-start, --skip-ping-check, --stable, -f|--force, -d|--dev, -h|--help]
  799. -c|--check - Check for updates and exit (exit codes => 0: update available, 3: no updates)
  800. --check-tags - Check for newer tags and exit (exit codes => 0: newer tag available, 3: no newer tag)
  801. --ours - Use merge strategy option "ours" to solve conflicts in favor of non-mailcow code (local changes over remote changes), not recommended!
  802. --gc - Run garbage collector to delete old image tags
  803. --nightly - Switch your mailcow updates to the unstable (nightly) branch. FOR TESTING PURPOSES ONLY!!!!
  804. --prefetch - Only prefetch new images and exit (useful to prepare updates)
  805. --skip-start - Do not start mailcow after update
  806. --skip-ping-check - Skip ICMP Check to public DNS resolvers (Use it only if you'\''ve blocked any ICMP Connections to your mailcow machine)
  807. --stable - Switch your mailcow updates to the stable (master) branch. Default unless you changed it with --nightly.
  808. -f|--force - Force update, do not ask questions
  809. -d|--dev - Enables Developer Mode (No Checkout of update.sh for tests)
  810. '
  811. exit 0
  812. esac
  813. shift
  814. done
  815. [[ ! -f mailcow.conf ]] && { echo -e "\e[31mmailcow.conf is missing! Is mailcow installed?\e[0m"; exit 1;}
  816. chmod 600 mailcow.conf
  817. source mailcow.conf
  818. detect_docker_compose_command
  819. fix_broken_dnslist_conf
  820. DOTS=${MAILCOW_HOSTNAME//[^.]};
  821. if [ ${#DOTS} -lt 1 ]; then
  822. echo -e "\e[31mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is not a FQDN!\e[0m"
  823. sleep 1
  824. echo "Please change it to a FQDN and redeploy the stack with $COMPOSE_COMMAND up -d"
  825. exit 1
  826. elif [[ "${MAILCOW_HOSTNAME: -1}" == "." ]]; then
  827. echo "MAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) is ending with a dot. This is not a valid FQDN!"
  828. exit 1
  829. elif [ ${#DOTS} -eq 1 ]; then
  830. echo -e "\e[33mMAILCOW_HOSTNAME (${MAILCOW_HOSTNAME}) does not contain a Subdomain. This is not fully tested and may cause issues.\e[0m"
  831. echo "Find more information about why this message exists here: https://github.com/mailcow/mailcow-dockerized/issues/1572"
  832. read -r -p "Do you want to proceed anyway? [y/N] " response
  833. if [[ "$response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  834. echo "OK. Proceeding."
  835. else
  836. echo "OK. Exiting."
  837. exit 1
  838. fi
  839. fi
  840. if grep --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox grep detected, please install gnu grep, \"apk add --no-cache --upgrade grep\""; exit 1; fi
  841. # This will also cover sort
  842. if cp --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox cp detected, please install coreutils, \"apk add --no-cache --upgrade coreutils\""; exit 1; fi
  843. if sed --help 2>&1 | head -n 1 | grep -q -i "busybox"; then echo "BusyBox sed detected, please install gnu sed, \"apk add --no-cache --upgrade sed\""; exit 1; fi
  844. CONFIG_ARRAY=(
  845. "SKIP_LETS_ENCRYPT"
  846. "SKIP_SOGO"
  847. "USE_WATCHDOG"
  848. "WATCHDOG_NOTIFY_EMAIL"
  849. "WATCHDOG_NOTIFY_WEBHOOK"
  850. "WATCHDOG_NOTIFY_WEBHOOK_BODY"
  851. "WATCHDOG_NOTIFY_BAN"
  852. "WATCHDOG_NOTIFY_START"
  853. "WATCHDOG_EXTERNAL_CHECKS"
  854. "WATCHDOG_SUBJECT"
  855. "SKIP_CLAMD"
  856. "SKIP_IP_CHECK"
  857. "ADDITIONAL_SAN"
  858. "AUTODISCOVER_SAN"
  859. "DOVEADM_PORT"
  860. "IPV4_NETWORK"
  861. "IPV6_NETWORK"
  862. "LOG_LINES"
  863. "SNAT_TO_SOURCE"
  864. "SNAT6_TO_SOURCE"
  865. "COMPOSE_PROJECT_NAME"
  866. "DOCKER_COMPOSE_VERSION"
  867. "SQL_PORT"
  868. "API_KEY"
  869. "API_KEY_READ_ONLY"
  870. "API_ALLOW_FROM"
  871. "MAILDIR_GC_TIME"
  872. "MAILDIR_SUB"
  873. "ACL_ANYONE"
  874. "ENABLE_SSL_SNI"
  875. "ALLOW_ADMIN_EMAIL_LOGIN"
  876. "SKIP_HTTP_VERIFICATION"
  877. "SOGO_EXPIRE_SESSION"
  878. "REDIS_PORT"
  879. "DOVECOT_MASTER_USER"
  880. "DOVECOT_MASTER_PASS"
  881. "MAILCOW_PASS_SCHEME"
  882. "ADDITIONAL_SERVER_NAMES"
  883. "ACME_CONTACT"
  884. "WATCHDOG_VERBOSE"
  885. "WEBAUTHN_ONLY_TRUSTED_VENDORS"
  886. "SPAMHAUS_DQS_KEY"
  887. "SKIP_UNBOUND_HEALTHCHECK"
  888. "DISABLE_NETFILTER_ISOLATION_RULE"
  889. "REDISPASS"
  890. )
  891. detect_bad_asn
  892. sed -i --follow-symlinks '$a\' mailcow.conf
  893. for option in "${CONFIG_ARRAY[@]}"; do
  894. if [[ ${option} == "ADDITIONAL_SAN" ]]; then
  895. if ! grep -q "${option}" mailcow.conf; then
  896. echo "Adding new option \"${option}\" to mailcow.conf"
  897. echo "${option}=" >> mailcow.conf
  898. fi
  899. elif [[ "${option}" == "COMPOSE_PROJECT_NAME" ]]; then
  900. if ! grep -q "${option}" mailcow.conf; then
  901. echo "Adding new option \"${option}\" to mailcow.conf"
  902. echo "COMPOSE_PROJECT_NAME=mailcowdockerized" >> mailcow.conf
  903. fi
  904. elif [[ "${option}" == "DOCKER_COMPOSE_VERSION" ]]; then
  905. if ! grep -q "${option}" mailcow.conf; then
  906. echo "Adding new option \"${option}\" to mailcow.conf"
  907. echo "# Used Docker Compose version" >> mailcow.conf
  908. echo "# Switch here between native (compose plugin) and standalone" >> mailcow.conf
  909. echo "# For more informations take a look at the mailcow docs regarding the configuration options." >> mailcow.conf
  910. echo "# Normally this should be untouched but if you decided to use either of those you can switch it manually here." >> mailcow.conf
  911. echo "# Please be aware that at least one of those variants should be installed on your maschine or mailcow will fail." >> mailcow.conf
  912. echo "" >> mailcow.conf
  913. echo "DOCKER_COMPOSE_VERSION=${DOCKER_COMPOSE_VERSION}" >> mailcow.conf
  914. fi
  915. elif [[ "${option}" == "DOVEADM_PORT" ]]; then
  916. if ! grep -q "${option}" mailcow.conf; then
  917. echo "Adding new option \"${option}\" to mailcow.conf"
  918. echo "DOVEADM_PORT=127.0.0.1:19991" >> mailcow.conf
  919. fi
  920. elif [[ "${option}" == "WATCHDOG_NOTIFY_EMAIL" ]]; then
  921. if ! grep -q "${option}" mailcow.conf; then
  922. echo "Adding new option \"${option}\" to mailcow.conf"
  923. echo "WATCHDOG_NOTIFY_EMAIL=" >> mailcow.conf
  924. fi
  925. elif [[ "${option}" == "LOG_LINES" ]]; then
  926. if ! grep -q "${option}" mailcow.conf; then
  927. echo "Adding new option \"${option}\" to mailcow.conf"
  928. echo '# Max log lines per service to keep in Redis logs' >> mailcow.conf
  929. echo "LOG_LINES=9999" >> mailcow.conf
  930. fi
  931. elif [[ "${option}" == "IPV4_NETWORK" ]]; then
  932. if ! grep -q "${option}" mailcow.conf; then
  933. echo "Adding new option \"${option}\" to mailcow.conf"
  934. echo '# Internal IPv4 /24 subnet, format n.n.n. (expands to n.n.n.0/24)' >> mailcow.conf
  935. echo "IPV4_NETWORK=172.22.1" >> mailcow.conf
  936. fi
  937. elif [[ "${option}" == "IPV6_NETWORK" ]]; then
  938. if ! grep -q "${option}" mailcow.conf; then
  939. echo "Adding new option \"${option}\" to mailcow.conf"
  940. echo '# Internal IPv6 subnet in fc00::/7' >> mailcow.conf
  941. echo "IPV6_NETWORK=fd4d:6169:6c63:6f77::/64" >> mailcow.conf
  942. fi
  943. elif [[ "${option}" == "SQL_PORT" ]]; then
  944. if ! grep -q "${option}" mailcow.conf; then
  945. echo "Adding new option \"${option}\" to mailcow.conf"
  946. echo '# Bind SQL to 127.0.0.1 on port 13306' >> mailcow.conf
  947. echo "SQL_PORT=127.0.0.1:13306" >> mailcow.conf
  948. fi
  949. elif [[ "${option}" == "API_KEY" ]]; then
  950. if ! grep -q "${option}" mailcow.conf; then
  951. echo "Adding new option \"${option}\" to mailcow.conf"
  952. echo '# Create or override API key for web UI' >> mailcow.conf
  953. echo "#API_KEY=" >> mailcow.conf
  954. fi
  955. elif [[ "${option}" == "API_KEY_READ_ONLY" ]]; then
  956. if ! grep -q "${option}" mailcow.conf; then
  957. echo "Adding new option \"${option}\" to mailcow.conf"
  958. echo '# Create or override read-only API key for web UI' >> mailcow.conf
  959. echo "#API_KEY_READ_ONLY=" >> mailcow.conf
  960. fi
  961. elif [[ "${option}" == "API_ALLOW_FROM" ]]; then
  962. if ! grep -q "${option}" mailcow.conf; then
  963. echo "Adding new option \"${option}\" to mailcow.conf"
  964. echo '# Must be set for API_KEY to be active' >> mailcow.conf
  965. echo '# IPs only, no networks (networks can be set via UI)' >> mailcow.conf
  966. echo "#API_ALLOW_FROM=" >> mailcow.conf
  967. fi
  968. elif [[ "${option}" == "SNAT_TO_SOURCE" ]]; then
  969. if ! grep -q "${option}" mailcow.conf; then
  970. echo "Adding new option \"${option}\" to mailcow.conf"
  971. echo '# Use this IPv4 for outgoing connections (SNAT)' >> mailcow.conf
  972. echo "#SNAT_TO_SOURCE=" >> mailcow.conf
  973. fi
  974. elif [[ "${option}" == "SNAT6_TO_SOURCE" ]]; then
  975. if ! grep -q "${option}" mailcow.conf; then
  976. echo "Adding new option \"${option}\" to mailcow.conf"
  977. echo '# Use this IPv6 for outgoing connections (SNAT)' >> mailcow.conf
  978. echo "#SNAT6_TO_SOURCE=" >> mailcow.conf
  979. fi
  980. elif [[ "${option}" == "MAILDIR_GC_TIME" ]]; then
  981. if ! grep -q "${option}" mailcow.conf; then
  982. echo "Adding new option \"${option}\" to mailcow.conf"
  983. echo '# Garbage collector cleanup' >> mailcow.conf
  984. echo '# Deleted domains and mailboxes are moved to /var/vmail/_garbage/timestamp_sanitizedstring' >> mailcow.conf
  985. echo '# How long should objects remain in the garbage until they are being deleted? (value in minutes)' >> mailcow.conf
  986. echo '# Check interval is hourly' >> mailcow.conf
  987. echo 'MAILDIR_GC_TIME=1440' >> mailcow.conf
  988. fi
  989. elif [[ "${option}" == "ACL_ANYONE" ]]; then
  990. if ! grep -q "${option}" mailcow.conf; then
  991. echo "Adding new option \"${option}\" to mailcow.conf"
  992. echo '# Set this to "allow" to enable the anyone pseudo user. Disabled by default.' >> mailcow.conf
  993. echo '# When enabled, ACL can be created, that apply to "All authenticated users"' >> mailcow.conf
  994. echo '# This should probably only be activated on mail hosts, that are used exclusivly by one organisation.' >> mailcow.conf
  995. echo '# Otherwise a user might share data with too many other users.' >> mailcow.conf
  996. echo 'ACL_ANYONE=disallow' >> mailcow.conf
  997. fi
  998. elif [[ "${option}" == "ENABLE_SSL_SNI" ]]; then
  999. if ! grep -q "${option}" mailcow.conf; then
  1000. echo "Adding new option \"${option}\" to mailcow.conf"
  1001. echo '# Create seperate certificates for all domains - y/n' >> mailcow.conf
  1002. echo '# this will allow adding more than 100 domains, but some email clients will not be able to connect with alternative hostnames' >> mailcow.conf
  1003. echo '# see https://wiki.dovecot.org/SSL/SNIClientSupport' >> mailcow.conf
  1004. echo "ENABLE_SSL_SNI=n" >> mailcow.conf
  1005. fi
  1006. elif [[ "${option}" == "SKIP_SOGO" ]]; then
  1007. if ! grep -q "${option}" mailcow.conf; then
  1008. echo "Adding new option \"${option}\" to mailcow.conf"
  1009. echo '# Skip SOGo: Will disable SOGo integration and therefore webmail, DAV protocols and ActiveSync support (experimental, unsupported, not fully implemented) - y/n' >> mailcow.conf
  1010. echo "SKIP_SOGO=n" >> mailcow.conf
  1011. fi
  1012. elif [[ "${option}" == "MAILDIR_SUB" ]]; then
  1013. if ! grep -q "${option}" mailcow.conf; then
  1014. echo "Adding new option \"${option}\" to mailcow.conf"
  1015. echo '# MAILDIR_SUB defines a path in a users virtual home to keep the maildir in. Leave empty for updated setups.' >> mailcow.conf
  1016. echo "#MAILDIR_SUB=Maildir" >> mailcow.conf
  1017. echo "MAILDIR_SUB=" >> mailcow.conf
  1018. fi
  1019. elif [[ "${option}" == "WATCHDOG_NOTIFY_WEBHOOK" ]]; then
  1020. if ! grep -q "${option}" mailcow.conf; then
  1021. echo "Adding new option \"${option}\" to mailcow.conf"
  1022. echo '# Send notifications to a webhook URL that receives a POST request with the content type "application/json".' >> mailcow.conf
  1023. echo '# You can use this to send notifications to services like Discord, Slack and others.' >> mailcow.conf
  1024. echo '#WATCHDOG_NOTIFY_WEBHOOK=https://discord.com/api/webhooks/XXXXXXXXXXXXXXXXXXX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX' >> mailcow.conf
  1025. fi
  1026. elif [[ "${option}" == "WATCHDOG_NOTIFY_WEBHOOK_BODY" ]]; then
  1027. if ! grep -q "${option}" mailcow.conf; then
  1028. echo "Adding new option \"${option}\" to mailcow.conf"
  1029. echo '# JSON body included in the webhook POST request. Needs to be in single quotes.' >> mailcow.conf
  1030. echo '# Following variables are available: SUBJECT, BODY' >> mailcow.conf
  1031. WEBHOOK_BODY='{"username": "mailcow Watchdog", "content": "**${SUBJECT}**\n${BODY}"}'
  1032. echo "#WATCHDOG_NOTIFY_WEBHOOK_BODY='${WEBHOOK_BODY}'" >> mailcow.conf
  1033. fi
  1034. elif [[ "${option}" == "WATCHDOG_NOTIFY_BAN" ]]; then
  1035. if ! grep -q "${option}" mailcow.conf; then
  1036. echo "Adding new option \"${option}\" to mailcow.conf"
  1037. echo '# Notify about banned IP. Includes whois lookup.' >> mailcow.conf
  1038. echo "WATCHDOG_NOTIFY_BAN=y" >> mailcow.conf
  1039. fi
  1040. elif [[ "${option}" == "WATCHDOG_NOTIFY_START" ]]; then
  1041. if ! grep -q "${option}" mailcow.conf; then
  1042. echo "Adding new option \"${option}\" to mailcow.conf"
  1043. echo '# Send a notification when the watchdog is started.' >> mailcow.conf
  1044. echo "WATCHDOG_NOTIFY_START=y" >> mailcow.conf
  1045. fi
  1046. elif [[ "${option}" == "WATCHDOG_SUBJECT" ]]; then
  1047. if ! grep -q "${option}" mailcow.conf; then
  1048. echo "Adding new option \"${option}\" to mailcow.conf"
  1049. echo '# Subject for watchdog mails. Defaults to "Watchdog ALERT" followed by the error message.' >> mailcow.conf
  1050. echo "#WATCHDOG_SUBJECT=" >> mailcow.conf
  1051. fi
  1052. elif [[ "${option}" == "WATCHDOG_EXTERNAL_CHECKS" ]]; then
  1053. if ! grep -q "${option}" mailcow.conf; then
  1054. echo "Adding new option \"${option}\" to mailcow.conf"
  1055. echo '# Checks if mailcow is an open relay. Requires a SAL. More checks will follow.' >> mailcow.conf
  1056. echo '# No data is collected. Opt-in and anonymous.' >> mailcow.conf
  1057. echo '# Will only work with unmodified mailcow setups.' >> mailcow.conf
  1058. echo "WATCHDOG_EXTERNAL_CHECKS=n" >> mailcow.conf
  1059. fi
  1060. elif [[ "${option}" == "SOGO_EXPIRE_SESSION" ]]; then
  1061. if ! grep -q "${option}" mailcow.conf; then
  1062. echo "Adding new option \"${option}\" to mailcow.conf"
  1063. echo '# SOGo session timeout in minutes' >> mailcow.conf
  1064. echo "SOGO_EXPIRE_SESSION=480" >> mailcow.conf
  1065. fi
  1066. elif [[ "${option}" == "REDIS_PORT" ]]; then
  1067. if ! grep -q "${option}" mailcow.conf; then
  1068. echo "Adding new option \"${option}\" to mailcow.conf"
  1069. echo "REDIS_PORT=127.0.0.1:7654" >> mailcow.conf
  1070. fi
  1071. elif [[ "${option}" == "DOVECOT_MASTER_USER" ]]; then
  1072. if ! grep -q "${option}" mailcow.conf; then
  1073. echo "Adding new option \"${option}\" to mailcow.conf"
  1074. echo '# DOVECOT_MASTER_USER and _PASS must _both_ be provided. No special chars.' >> mailcow.conf
  1075. echo '# Empty by default to auto-generate master user and password on start.' >> mailcow.conf
  1076. echo '# User expands to DOVECOT_MASTER_USER@mailcow.local' >> mailcow.conf
  1077. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  1078. echo "DOVECOT_MASTER_USER=" >> mailcow.conf
  1079. fi
  1080. elif [[ "${option}" == "DOVECOT_MASTER_PASS" ]]; then
  1081. if ! grep -q "${option}" mailcow.conf; then
  1082. echo "Adding new option \"${option}\" to mailcow.conf"
  1083. echo '# LEAVE EMPTY IF UNSURE' >> mailcow.conf
  1084. echo "DOVECOT_MASTER_PASS=" >> mailcow.conf
  1085. fi
  1086. elif [[ "${option}" == "MAILCOW_PASS_SCHEME" ]]; then
  1087. if ! grep -q "${option}" mailcow.conf; then
  1088. echo "Adding new option \"${option}\" to mailcow.conf"
  1089. echo '# Password hash algorithm' >> mailcow.conf
  1090. echo '# Only certain password hash algorithm are supported. For a fully list of supported schemes,' >> mailcow.conf
  1091. echo '# see https://docs.mailcow.email/models/model-passwd/' >> mailcow.conf
  1092. echo "MAILCOW_PASS_SCHEME=BLF-CRYPT" >> mailcow.conf
  1093. fi
  1094. elif [[ "${option}" == "ADDITIONAL_SERVER_NAMES" ]]; then
  1095. if ! grep -q "${option}" mailcow.conf; then
  1096. echo "Adding new option \"${option}\" to mailcow.conf"
  1097. echo '# Additional server names for mailcow UI' >> mailcow.conf
  1098. echo '#' >> mailcow.conf
  1099. echo '# Specify alternative addresses for the mailcow UI to respond to' >> mailcow.conf
  1100. echo '# This is useful when you set mail.* as ADDITIONAL_SAN and want to make sure mail.maildomain.com will always point to the mailcow UI.' >> mailcow.conf
  1101. echo '# If the server name does not match a known site, Nginx decides by best-guess and may redirect users to the wrong web root.' >> mailcow.conf
  1102. echo '# You can understand this as server_name directive in Nginx.' >> mailcow.conf
  1103. echo '# Comma separated list without spaces! Example: ADDITIONAL_SERVER_NAMES=a.b.c,d.e.f' >> mailcow.conf
  1104. echo 'ADDITIONAL_SERVER_NAMES=' >> mailcow.conf
  1105. fi
  1106. elif [[ "${option}" == "AUTODISCOVER_SAN" ]]; then
  1107. if ! grep -q "${option}" mailcow.conf; then
  1108. echo "Adding new option \"${option}\" to mailcow.conf"
  1109. echo '# Obtain certificates for autodiscover.* and autoconfig.* domains.' >> mailcow.conf
  1110. echo '# This can be useful to switch off in case you are in a scenario where a reverse proxy already handles those.' >> mailcow.conf
  1111. echo '# There are mixed scenarios where ports 80,443 are occupied and you do not want to share certs' >> mailcow.conf
  1112. echo '# between services. So acme-mailcow obtains for maildomains and all web-things get handled' >> mailcow.conf
  1113. echo '# in the reverse proxy.' >> mailcow.conf
  1114. echo 'AUTODISCOVER_SAN=y' >> mailcow.conf
  1115. fi
  1116. elif [[ "${option}" == "ACME_CONTACT" ]]; then
  1117. if ! grep -q "${option}" mailcow.conf; then
  1118. echo "Adding new option \"${option}\" to mailcow.conf"
  1119. echo '# Lets Encrypt registration contact information' >> mailcow.conf
  1120. echo '# Optional: Leave empty for none' >> mailcow.conf
  1121. echo '# This value is only used on first order!' >> mailcow.conf
  1122. echo '# Setting it at a later point will require the following steps:' >> mailcow.conf
  1123. echo '# https://docs.mailcow.email/troubleshooting/debug-reset_tls/' >> mailcow.conf
  1124. echo 'ACME_CONTACT=' >> mailcow.conf
  1125. fi
  1126. elif [[ "${option}" == "WEBAUTHN_ONLY_TRUSTED_VENDORS" ]]; then
  1127. if ! grep -q "${option}" mailcow.conf; then
  1128. echo "Adding new option \"${option}\" to mailcow.conf"
  1129. echo "# WebAuthn device manufacturer verification" >> mailcow.conf
  1130. echo '# After setting WEBAUTHN_ONLY_TRUSTED_VENDORS=y only devices from trusted manufacturers are allowed' >> mailcow.conf
  1131. echo '# root certificates can be placed for validation under mailcow-dockerized/data/web/inc/lib/WebAuthn/rootCertificates' >> mailcow.conf
  1132. echo 'WEBAUTHN_ONLY_TRUSTED_VENDORS=n' >> mailcow.conf
  1133. fi
  1134. elif [[ "${option}" == "SPAMHAUS_DQS_KEY" ]]; then
  1135. if ! grep -q "${option}" mailcow.conf; then
  1136. echo "Adding new option \"${option}\" to mailcow.conf"
  1137. echo "# Spamhaus Data Query Service Key" >> mailcow.conf
  1138. echo '# Optional: Leave empty for none' >> mailcow.conf
  1139. echo '# Enter your key here if you are using a blocked ASN (OVH, AWS, Cloudflare e.g) for the unregistered Spamhaus Blocklist.' >> mailcow.conf
  1140. echo '# If empty, it will completely disable Spamhaus blocklists if it detects that you are running on a server using a blocked AS.' >> mailcow.conf
  1141. echo '# Otherwise it will work as usual.' >> mailcow.conf
  1142. echo 'SPAMHAUS_DQS_KEY=' >> mailcow.conf
  1143. fi
  1144. elif [[ "${option}" == "WATCHDOG_VERBOSE" ]]; then
  1145. if ! grep -q "${option}" mailcow.conf; then
  1146. echo "Adding new option \"${option}\" to mailcow.conf"
  1147. echo '# Enable watchdog verbose logging' >> mailcow.conf
  1148. echo 'WATCHDOG_VERBOSE=n' >> mailcow.conf
  1149. fi
  1150. elif [[ "${option}" == "SKIP_UNBOUND_HEALTHCHECK" ]]; then
  1151. if ! grep -q "${option}" mailcow.conf; then
  1152. echo "Adding new option \"${option}\" to mailcow.conf"
  1153. echo '# Skip Unbound (DNS Resolver) Healthchecks (NOT Recommended!) - y/n' >> mailcow.conf
  1154. echo 'SKIP_UNBOUND_HEALTHCHECK=n' >> mailcow.conf
  1155. fi
  1156. elif [[ "${option}" == "DISABLE_NETFILTER_ISOLATION_RULE" ]]; then
  1157. if ! grep -q "${option}" mailcow.conf; then
  1158. echo "Adding new option \"${option}\" to mailcow.conf"
  1159. echo '# Prevent netfilter from setting an iptables/nftables rule to isolate the mailcow docker network - y/n' >> mailcow.conf
  1160. echo '# CAUTION: Disabling this may expose container ports to other neighbors on the same subnet, even if the ports are bound to localhost' >> mailcow.conf
  1161. echo 'DISABLE_NETFILTER_ISOLATION_RULE=n' >> mailcow.conf
  1162. fi
  1163. elif [[ "${option}" == "REDISPASS" ]]; then
  1164. if ! grep -q "${option}" mailcow.conf; then
  1165. echo "Adding new option \"${option}\" to mailcow.conf"
  1166. echo -e '\n# ------------------------------' >> mailcow.conf
  1167. echo '# REDIS configuration' >> mailcow.conf
  1168. echo -e '# ------------------------------\n' >> mailcow.conf
  1169. echo "REDISPASS=$(LC_ALL=C </dev/urandom tr -dc A-Za-z0-9 2> /dev/null | head -c 28)" >> mailcow.conf
  1170. fi
  1171. elif ! grep -q "${option}" mailcow.conf; then
  1172. echo "Adding new option \"${option}\" to mailcow.conf"
  1173. echo "${option}=n" >> mailcow.conf
  1174. fi
  1175. done
  1176. if [[ ("${SKIP_PING_CHECK}" == "y") ]]; then
  1177. echo -e "\e[32mSkipping Ping Check...\e[0m"
  1178. else
  1179. echo -en "Checking internet connection... "
  1180. if ! check_online_status; then
  1181. echo -e "\e[31mfailed\e[0m"
  1182. exit 1
  1183. else
  1184. echo -e "\e[32mOK\e[0m"
  1185. fi
  1186. fi
  1187. if ! [ "$NEW_BRANCH" ]; then
  1188. echo -e "\e[33mDetecting which build your mailcow runs on...\e[0m"
  1189. sleep 1
  1190. if [ "${BRANCH}" == "master" ]; then
  1191. echo -e "\e[32mYou are receiving stable updates (master).\e[0m"
  1192. echo -e "\e[33mTo change that run the update.sh Script one time with the --nightly parameter to switch to nightly builds.\e[0m"
  1193. elif [ "${BRANCH}" == "nightly" ]; then
  1194. echo -e "\e[31mYou are receiving unstable updates (nightly). These are for testing purposes only!!!\e[0m"
  1195. sleep 1
  1196. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  1197. else
  1198. echo -e "\e[33mYou are receiving updates from an unsupported branch.\e[0m"
  1199. sleep 1
  1200. echo -e "\e[33mThe mailcow stack might still work but it is recommended to switch to the master branch (stable builds).\e[0m"
  1201. echo -e "\e[33mTo change that run the update.sh Script one time with the --stable parameter to switch to stable builds.\e[0m"
  1202. fi
  1203. elif [ "$FORCE" ]; then
  1204. echo -e "\e[31mYou are running in forced mode!\e[0m"
  1205. echo -e "\e[31mA Branch Switch can only be performed manually (monitored).\e[0m"
  1206. echo -e "\e[31mPlease rerun the update.sh Script without the --force/-f parameter.\e[0m"
  1207. sleep 1
  1208. elif [ "$NEW_BRANCH" == "master" ] && [ "$CURRENT_BRANCH" != "master" ]; then
  1209. echo -e "\e[33mYou are about to switch your mailcow updates to the stable (master) branch.\e[0m"
  1210. sleep 1
  1211. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no data is lost...\e[0m"
  1212. sleep 1
  1213. echo -e "\e[31mWARNING: Please see on GitHub or ask in the community if a switch to master is stable or not.
  1214. In some rear cases an update back to master can destroy your mailcow configuration such as database upgrade, etc.
  1215. Normally an upgrade back to master should be safe during each full release.
  1216. Check GitHub for Database changes and update only if there similar to the full release!\e[0m"
  1217. read -r -p "Are you sure you that want to continue upgrading to the stable (master) branch? [y/N] " response
  1218. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1219. echo "OK. If you prepared yourself for that please run the update.sh Script with the --stable parameter again to trigger this process here."
  1220. exit 0
  1221. fi
  1222. BRANCH="$NEW_BRANCH"
  1223. DIFF_DIRECTORY=update_diffs
  1224. DIFF_FILE="${DIFF_DIRECTORY}/diff_before_upgrade_to_master_$(date +"%Y-%m-%d-%H-%M-%S")"
  1225. mv diff_before_upgrade* "${DIFF_DIRECTORY}/" 2> /dev/null
  1226. if ! git diff-index --quiet HEAD; then
  1227. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1228. mkdir -p "${DIFF_DIRECTORY}"
  1229. git diff "${BRANCH}" --stat > "${DIFF_FILE}"
  1230. git diff "${BRANCH}" >> "${DIFF_FILE}"
  1231. fi
  1232. echo -e "\e[32mSwitching Branch to ${BRANCH}...\e[0m"
  1233. git fetch origin
  1234. git checkout -f "${BRANCH}"
  1235. elif [ "$NEW_BRANCH" == "nightly" ] && [ "$CURRENT_BRANCH" != "nightly" ]; then
  1236. echo -e "\e[33mYou are about to switch your mailcow Updates to the unstable (nightly) branch.\e[0m"
  1237. sleep 1
  1238. echo -e "\e[33mBefore you do: Please take a backup of all components to ensure that no Data is lost...\e[0m"
  1239. sleep 1
  1240. echo -e "\e[31mWARNING: A switch to nightly is possible any time. But a switch back (to master) isn't.\e[0m"
  1241. read -r -p "Are you sure you that want to continue upgrading to the unstable (nightly) branch? [y/N] " response
  1242. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1243. echo "OK. If you prepared yourself for that please run the update.sh Script with the --nightly parameter again to trigger this process here."
  1244. exit 0
  1245. fi
  1246. BRANCH=$NEW_BRANCH
  1247. DIFF_DIRECTORY=update_diffs
  1248. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_upgrade_to_nightly_$(date +"%Y-%m-%d-%H-%M-%S")
  1249. mv diff_before_upgrade* ${DIFF_DIRECTORY}/ 2> /dev/null
  1250. if ! git diff-index --quiet HEAD; then
  1251. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1252. mkdir -p ${DIFF_DIRECTORY}
  1253. git diff "${BRANCH}" --stat > "${DIFF_FILE}"
  1254. git diff "${BRANCH}" >> "${DIFF_FILE}"
  1255. fi
  1256. git fetch origin
  1257. git checkout -f "${BRANCH}"
  1258. fi
  1259. if [ ! "$DEV" ]; then
  1260. echo -e "\e[32mChecking for newer update script...\e[0m"
  1261. SHA1_1="$(sha1sum update.sh)"
  1262. git fetch origin #${BRANCH}
  1263. git checkout "origin/${BRANCH}" update.sh
  1264. SHA1_2=$(sha1sum update.sh)
  1265. if [[ "${SHA1_1}" != "${SHA1_2}" ]]; then
  1266. echo "update.sh changed, please run this script again, exiting."
  1267. chmod +x update.sh
  1268. exit 2
  1269. fi
  1270. fi
  1271. if [ ! "$FORCE" ]; then
  1272. read -r -p "Are you sure you want to update mailcow: dockerized? All containers will be stopped. [y/N] " response
  1273. if [[ ! "${response}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1274. echo "OK, exiting."
  1275. exit 0
  1276. fi
  1277. migrate_docker_nat
  1278. fi
  1279. remove_obsolete_nginx_ports
  1280. echo -e "\e[32mValidating docker-compose stack configuration...\e[0m"
  1281. sed -i 's/HTTPS_BIND:-:/HTTPS_BIND:-/g' docker-compose.yml
  1282. sed -i 's/HTTP_BIND:-:/HTTP_BIND:-/g' docker-compose.yml
  1283. if ! $COMPOSE_COMMAND config -q; then
  1284. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  1285. exit 1
  1286. fi
  1287. echo -e "\e[32mChecking for conflicting bridges...\e[0m"
  1288. MAILCOW_BRIDGE=$($COMPOSE_COMMAND config | grep -i com.docker.network.bridge.name | cut -d':' -f2)
  1289. while read NAT_ID; do
  1290. iptables -t nat -D POSTROUTING "$NAT_ID"
  1291. done < <(iptables -L -vn -t nat --line-numbers | grep "$IPV4_NETWORK" | grep -E 'MASQUERADE.*all' | grep -v "${MAILCOW_BRIDGE}" | cut -d' ' -f1)
  1292. DIFF_DIRECTORY=update_diffs
  1293. DIFF_FILE=${DIFF_DIRECTORY}/diff_before_update_$(date +"%Y-%m-%d-%H-%M-%S")
  1294. mv diff_before_update* ${DIFF_DIRECTORY}/ 2> /dev/null
  1295. if ! git diff-index --quiet HEAD; then
  1296. echo -e "\e[32mSaving diff to ${DIFF_FILE}...\e[0m"
  1297. mkdir -p ${DIFF_DIRECTORY}
  1298. git diff --stat > "${DIFF_FILE}"
  1299. git diff >> "${DIFF_FILE}"
  1300. fi
  1301. echo -e "\e[32mPrefetching images...\e[0m"
  1302. prefetch_images
  1303. echo -e "\e[32mStopping mailcow...\e[0m"
  1304. sleep 2
  1305. MAILCOW_CONTAINERS=($($COMPOSE_COMMAND ps -q))
  1306. $COMPOSE_COMMAND down
  1307. echo -e "\e[32mChecking for remaining containers...\e[0m"
  1308. sleep 2
  1309. for container in "${MAILCOW_CONTAINERS[@]}"; do
  1310. docker rm -f "$container" 2> /dev/null
  1311. done
  1312. [[ -f data/conf/nginx/ZZZ-ejabberd.conf ]] && rm data/conf/nginx/ZZZ-ejabberd.conf
  1313. migrate_solr_config_options
  1314. adapt_new_options
  1315. # Silently fixing remote url from andryyy to mailcow
  1316. # git remote set-url origin https://github.com/mailcow/mailcow-dockerized
  1317. DEFAULT_REPO="https://github.com/mailcow/mailcow-dockerized"
  1318. CURRENT_REPO=$(git config --get remote.origin.url)
  1319. if [ "$CURRENT_REPO" != "$DEFAULT_REPO" ]; then
  1320. echo "The Repository currently used is not the default Mailcow Repository."
  1321. echo "Currently Repository: $CURRENT_REPO"
  1322. echo "Default Repository: $DEFAULT_REPO"
  1323. if [ ! "$FORCE" ]; then
  1324. read -r -p "Should it be changed back to default? [y/N] " repo_response
  1325. if [[ "$repo_response" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  1326. git remote set-url origin $DEFAULT_REPO
  1327. fi
  1328. else
  1329. echo "Running in forced mode... setting Repo to default!"
  1330. git remote set-url origin $DEFAULT_REPO
  1331. fi
  1332. fi
  1333. if [ ! "$DEV" ]; then
  1334. echo -e "\e[32mCommitting current status...\e[0m"
  1335. [[ -z "$(git config user.name)" ]] && git config user.name moo
  1336. [[ -z "$(git config user.email)" ]] && git config user.email moo@cow.moo
  1337. [[ ! -z $(git ls-files data/conf/rspamd/override.d/worker-controller-password.inc) ]] && git rm data/conf/rspamd/override.d/worker-controller-password.inc
  1338. git add -u
  1339. git commit -am "Before update on ${DATE}" > /dev/null
  1340. echo -e "\e[32mFetching updated code from remote...\e[0m"
  1341. git fetch origin #${BRANCH}
  1342. echo -e "\e[32mMerging local with remote code (recursive, strategy: \"${MERGE_STRATEGY:-theirs}\", options: \"patience\"...\e[0m"
  1343. git config merge.defaultToUpstream true
  1344. git merge -X"${MERGE_STRATEGY:-theirs}" -Xpatience -m "After update on ${DATE}"
  1345. # Need to use a variable to not pass return codes of if checks
  1346. MERGE_RETURN=$?
  1347. if [[ ${MERGE_RETURN} == 128 ]]; then
  1348. echo -e "\e[31m\nOh no, what happened?\n=> You most likely added files to your local mailcow instance that were now added to the official mailcow repository. Please move them to another location before updating mailcow.\e[0m"
  1349. exit 1
  1350. elif [[ ${MERGE_RETURN} == 1 ]]; then
  1351. echo -e "\e[93mPotential conflict, trying to fix...\e[0m"
  1352. git status --porcelain | grep -E "UD|DU" | awk '{print $2}' | xargs rm -v
  1353. git add -A
  1354. git commit -m "After update on ${DATE}" > /dev/null
  1355. git checkout .
  1356. echo -e "\e[32mRemoved and recreated files if necessary.\e[0m"
  1357. elif [[ ${MERGE_RETURN} != 0 ]]; then
  1358. echo -e "\e[31m\nOh no, something went wrong. Please check the error message above.\e[0m"
  1359. echo
  1360. echo "Run $COMPOSE_COMMAND up -d to restart your stack without updates or try again after fixing the mentioned errors."
  1361. exit 1
  1362. fi
  1363. elif [ "$DEV" ]; then
  1364. echo -e "\e[33mDEVELOPER MODE: Not creating a git diff and commiting it to prevent development stuff within a backup diff...\e[0m"
  1365. fi
  1366. echo -e "\e[32mFetching new images, if any...\e[0m"
  1367. sleep 2
  1368. $COMPOSE_COMMAND pull
  1369. # Fix missing SSL, does not overwrite existing files
  1370. [[ ! -d data/assets/ssl ]] && mkdir -p data/assets/ssl
  1371. cp -n -d data/assets/ssl-example/*.pem data/assets/ssl/
  1372. echo -e "Checking IPv6 settings... "
  1373. if grep -q 'SYSCTL_IPV6_DISABLED=1' mailcow.conf; then
  1374. echo
  1375. echo '!! IMPORTANT !!'
  1376. echo
  1377. echo 'SYSCTL_IPV6_DISABLED was removed due to complications. IPv6 can be disabled by editing "docker-compose.yml" and setting "enable_ipv6: true" to "enable_ipv6: false".'
  1378. echo "This setting will only be active after a complete shutdown of mailcow by running $COMPOSE_COMMAND down followed by $COMPOSE_COMMAND up -d."
  1379. echo
  1380. echo '!! IMPORTANT !!'
  1381. echo
  1382. read -p "Press any key to continue..." < /dev/tty
  1383. fi
  1384. # Checking for old project name bug
  1385. sed -i --follow-symlinks 's#COMPOSEPROJECT_NAME#COMPOSE_PROJECT_NAME#g' mailcow.conf
  1386. # Fix Rspamd maps
  1387. if [ -f data/conf/rspamd/custom/global_from_blacklist.map ]; then
  1388. mv data/conf/rspamd/custom/global_from_blacklist.map data/conf/rspamd/custom/global_smtp_from_blacklist.map
  1389. fi
  1390. if [ -f data/conf/rspamd/custom/global_from_whitelist.map ]; then
  1391. mv data/conf/rspamd/custom/global_from_whitelist.map data/conf/rspamd/custom/global_smtp_from_whitelist.map
  1392. fi
  1393. # Fix deprecated metrics.conf
  1394. if [ -f "data/conf/rspamd/local.d/metrics.conf" ]; then
  1395. if [ ! -z "$(git diff --name-only origin/master data/conf/rspamd/local.d/metrics.conf)" ]; then
  1396. echo -e "\e[33mWARNING\e[0m - Please migrate your customizations of data/conf/rspamd/local.d/metrics.conf to actions.conf and groups.conf after this update."
  1397. echo "The deprecated configuration file metrics.conf will be moved to metrics.conf_deprecated after updating mailcow."
  1398. fi
  1399. mv data/conf/rspamd/local.d/metrics.conf data/conf/rspamd/local.d/metrics.conf_deprecated
  1400. fi
  1401. # Set app_info.inc.php
  1402. if [ ${BRANCH} == "master" ]; then
  1403. mailcow_git_version=$(git describe --tags $(git rev-list --tags --max-count=1))
  1404. elif [ ${BRANCH} == "nightly" ]; then
  1405. mailcow_git_version=$(git rev-parse --short $(git rev-parse @{upstream}))
  1406. mailcow_last_git_version=""
  1407. else
  1408. mailcow_git_version=$(git rev-parse --short HEAD)
  1409. mailcow_last_git_version=""
  1410. fi
  1411. mailcow_git_commit=$(git rev-parse "origin/${BRANCH}")
  1412. mailcow_git_commit_date=$(git log -1 --format=%ci @{upstream} )
  1413. if [ $? -eq 0 ]; then
  1414. echo '<?php' > data/web/inc/app_info.inc.php
  1415. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  1416. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  1417. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  1418. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1419. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1420. echo ' $MAILCOW_GIT_COMMIT="'$mailcow_git_commit'";' >> data/web/inc/app_info.inc.php
  1421. echo ' $MAILCOW_GIT_COMMIT_DATE="'$mailcow_git_commit_date'";' >> data/web/inc/app_info.inc.php
  1422. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  1423. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  1424. echo '?>' >> data/web/inc/app_info.inc.php
  1425. else
  1426. echo '<?php' > data/web/inc/app_info.inc.php
  1427. echo ' $MAILCOW_GIT_VERSION="'$mailcow_git_version'";' >> data/web/inc/app_info.inc.php
  1428. echo ' $MAILCOW_LAST_GIT_VERSION="";' >> data/web/inc/app_info.inc.php
  1429. echo ' $MAILCOW_GIT_OWNER="mailcow";' >> data/web/inc/app_info.inc.php
  1430. echo ' $MAILCOW_GIT_REPO="mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1431. echo ' $MAILCOW_GIT_URL="https://github.com/mailcow/mailcow-dockerized";' >> data/web/inc/app_info.inc.php
  1432. echo ' $MAILCOW_GIT_COMMIT="";' >> data/web/inc/app_info.inc.php
  1433. echo ' $MAILCOW_GIT_COMMIT_DATE="";' >> data/web/inc/app_info.inc.php
  1434. echo ' $MAILCOW_BRANCH="'$BRANCH'";' >> data/web/inc/app_info.inc.php
  1435. echo ' $MAILCOW_UPDATEDAT='$(date +%s)';' >> data/web/inc/app_info.inc.php
  1436. echo '?>' >> data/web/inc/app_info.inc.php
  1437. echo -e "\e[33mCannot determine current git repository version...\e[0m"
  1438. fi
  1439. if [[ ${SKIP_START} == "y" ]]; then
  1440. echo -e "\e[33mNot starting mailcow, please run \"$COMPOSE_COMMAND up -d --remove-orphans\" to start mailcow.\e[0m"
  1441. else
  1442. echo -e "\e[32mStarting mailcow...\e[0m"
  1443. sleep 2
  1444. $COMPOSE_COMMAND up -d --remove-orphans
  1445. fi
  1446. echo -e "\e[32mCollecting garbage...\e[0m"
  1447. docker_garbage
  1448. # Run post-update-hook
  1449. if [ -f "${SCRIPT_DIR}/post_update_hook.sh" ]; then
  1450. bash "${SCRIPT_DIR}/post_update_hook.sh"
  1451. fi
  1452. # echo "In case you encounter any problem, hard-reset to a state before updating mailcow:"
  1453. # echo
  1454. # git reflog --color=always | grep "Before update on "
  1455. # echo
  1456. # echo "Use \"git reset --hard hash-on-the-left\" and run $COMPOSE_COMMAND up -d afterwards."