mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2024-11-22 20:51:07 +01:00
Updated draft
This commit is contained in:
parent
c793e01c2d
commit
6c51f63aa6
@ -1,5 +1,7 @@
|
|||||||
# role docker-mailu
|
# role docker-mailu
|
||||||
|
|
||||||
|
## setup
|
||||||
|
### ports
|
||||||
Keep in mind to change the conflicting ports manual.
|
Keep in mind to change the conflicting ports manual.
|
||||||
Execute
|
Execute
|
||||||
|
|
||||||
@ -9,7 +11,7 @@ Execute
|
|||||||
|
|
||||||
to verify that there aren't port conflicts
|
to verify that there aren't port conflicts
|
||||||
|
|
||||||
# admin account
|
### admin account
|
||||||
|
|
||||||
Before you can use Mailu, you must create the primary administrator user account. This should be admin@{{hostname}}. Use the following command, changing PASSWORD to your liking:
|
Before you can use Mailu, you must create the primary administrator user account. This should be admin@{{hostname}}. Use the following command, changing PASSWORD to your liking:
|
||||||
|
|
||||||
@ -17,6 +19,13 @@ Before you can use Mailu, you must create the primary administrator user account
|
|||||||
docker-compose -p mailu exec admin flask mailu admin admin {{hostname}} PASSWORD
|
docker-compose -p mailu exec admin flask mailu admin admin {{hostname}} PASSWORD
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Up
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker-compose -p mailu up -d
|
||||||
|
```
|
||||||
|
|
||||||
## See
|
## See
|
||||||
- https://gist.github.com/marienfressinaud/f284a59b18aad395eb0de2d22836ae6b
|
- https://gist.github.com/marienfressinaud/f284a59b18aad395eb0de2d22836ae6b
|
||||||
- https://mailu.io/1.7/compose/setup.html
|
- https://mailu.io/1.7/compose/setup.html
|
||||||
|
- https://mailu.io/master/faq.html#i-want-to-integrate-nextcloud-15-and-newer-with-mailu
|
||||||
|
@ -1,26 +1,25 @@
|
|||||||
---
|
---
|
||||||
|
|
||||||
|
- name: recieve {{domain}} certificate
|
||||||
|
command: certbot certonly --agree-tos --email {{administrator_email}} --non-interactive --webroot -w /var/lib/letsencrypt/ -d {{domain}}
|
||||||
|
|
||||||
- name: configure {{domain}}.conf
|
- name: configure {{domain}}.conf
|
||||||
template: src=domain.conf.j2 dest=/etc/nginx/conf.d/{{domain}}.conf
|
template: src=domain.conf.j2 dest=/etc/nginx/conf.d/{{domain}}.conf
|
||||||
notify: restart nginx
|
notify: restart nginx
|
||||||
|
|
||||||
- name: "Create mailu dir"
|
- name: "create mailu dir"
|
||||||
file:
|
file:
|
||||||
path: "/mailu"
|
path: "/mailu"
|
||||||
state: directory
|
state: directory
|
||||||
mode: 0755
|
mode: 0755
|
||||||
|
|
||||||
- name: "Add docker-compose.yml"
|
- name: add docker-compose.yml
|
||||||
copy:
|
template: src=docker-compose.yml.j2 dest=/mailu/docker-compose.yml
|
||||||
src: "{{ inventory_dir }}/files/{{ inventory_hostname }}/mailu/docker-compose.yml"
|
|
||||||
dest: "/mailu/docker-compose.yml"
|
|
||||||
|
|
||||||
- name: "Add mailu.env"
|
- name: add mailu.env
|
||||||
copy:
|
template: src=mailu.env.j2 dest=/mailu/mailu.env
|
||||||
src: "{{ inventory_dir }}/files/{{ inventory_hostname }}/mailu/mailu.env"
|
|
||||||
dest: "/mailu/mailu.env"
|
|
||||||
|
|
||||||
- name: "Install mailu service"
|
- name: "install mailu service"
|
||||||
copy:
|
copy:
|
||||||
src: "mailu.service"
|
src: "mailu.service"
|
||||||
dest: "/etc/systemd/system/mailu.service"
|
dest: "/etc/systemd/system/mailu.service"
|
||||||
|
113
roles/docker-mailu/templates/docker-compose.yml.j2
Normal file
113
roles/docker-mailu/templates/docker-compose.yml.j2
Normal file
@ -0,0 +1,113 @@
|
|||||||
|
# This file is auto-generated by the Mailu configuration wizard.
|
||||||
|
# Please read the documentation before attempting any change.
|
||||||
|
# Generated for compose flavor
|
||||||
|
|
||||||
|
version: '2.2'
|
||||||
|
|
||||||
|
services:
|
||||||
|
|
||||||
|
# External dependencies
|
||||||
|
redis:
|
||||||
|
image: redis:alpine
|
||||||
|
restart: always
|
||||||
|
volumes:
|
||||||
|
- "/mailu/redis:/data"
|
||||||
|
|
||||||
|
# Core services
|
||||||
|
front:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}nginx:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
logging:
|
||||||
|
driver: json-file
|
||||||
|
ports:
|
||||||
|
- "{{ http_port }}:80"
|
||||||
|
- "{{ https_port }}:443"
|
||||||
|
- "{{ ip4_address }}:25:25"
|
||||||
|
- "{{ ip4_address }}:465:465"
|
||||||
|
- "{{ ip4_address }}:587:587"
|
||||||
|
- "{{ ip4_address }}:110:110"
|
||||||
|
- "{{ ip4_address }}:995:995"
|
||||||
|
- "{{ ip4_address }}:143:143"
|
||||||
|
- "{{ ip4_address }}:993:993"
|
||||||
|
volumes:
|
||||||
|
- "/mailu/certs:/certs"
|
||||||
|
- "/mailu/overrides/nginx:/overrides"
|
||||||
|
|
||||||
|
admin:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}admin:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/data:/data"
|
||||||
|
- "/mailu/dkim:/dkim"
|
||||||
|
depends_on:
|
||||||
|
- redis
|
||||||
|
|
||||||
|
imap:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}dovecot:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/mail:/mail"
|
||||||
|
- "/mailu/overrides:/overrides"
|
||||||
|
depends_on:
|
||||||
|
- front
|
||||||
|
|
||||||
|
smtp:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}postfix:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/overrides:/overrides"
|
||||||
|
depends_on:
|
||||||
|
- front
|
||||||
|
|
||||||
|
antispam:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}rspamd:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/filter:/var/lib/rspamd"
|
||||||
|
- "/mailu/dkim:/dkim"
|
||||||
|
- "/mailu/overrides/rspamd:/etc/rspamd/override.d"
|
||||||
|
depends_on:
|
||||||
|
- front
|
||||||
|
|
||||||
|
# Optional services
|
||||||
|
antivirus:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}clamav:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/filter:/data"
|
||||||
|
|
||||||
|
webdav:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}radicale:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/dav:/data"
|
||||||
|
|
||||||
|
fetchmail:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}fetchmail:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
|
||||||
|
# Webmail
|
||||||
|
webmail:
|
||||||
|
image: ${DOCKER_ORG:-mailu}/${DOCKER_PREFIX:-}roundcube:${MAILU_VERSION:-1.7}
|
||||||
|
restart: always
|
||||||
|
env_file: mailu.env
|
||||||
|
volumes:
|
||||||
|
- "/mailu/webmail:/data"
|
||||||
|
depends_on:
|
||||||
|
- imap
|
||||||
|
|
||||||
|
networks:
|
||||||
|
default:
|
||||||
|
driver: bridge
|
||||||
|
ipam:
|
||||||
|
driver: default
|
||||||
|
config:
|
||||||
|
- subnet: 192.168.203.0/24
|
@ -1,18 +1,8 @@
|
|||||||
server
|
server
|
||||||
{
|
{
|
||||||
server_name {{domain}};
|
server_name {{domain}};
|
||||||
listen 443 ssl http2;
|
{% include 'roles/native-letsencrypt/templates/ssl_header.j2' %}
|
||||||
listen [::]:443 ssl http2;
|
{% include 'roles/native-nginx-docker-proxy/templates/https_proxy_pass.conf.j2'%}
|
||||||
|
access_log /var/log/nginx/{{domain}}-access.log;
|
||||||
{% with http_port=https_port %}
|
error_log /var/log/nginx/{{domain}}-error.log;
|
||||||
{% include 'roles/native-nginx-docker-proxy/templates/proxy_pass.conf.j2'%}
|
|
||||||
{% endwith %}
|
|
||||||
}
|
|
||||||
|
|
||||||
server
|
|
||||||
{
|
|
||||||
server_name {{domain}};
|
|
||||||
listen 80;
|
|
||||||
listen [::]:80;
|
|
||||||
{% include 'roles/native-nginx-docker-proxy/templates/proxy_pass.conf.j2'%}
|
|
||||||
}
|
}
|
||||||
|
142
roles/docker-mailu/templates/mailu.env.j2
Normal file
142
roles/docker-mailu/templates/mailu.env.j2
Normal file
@ -0,0 +1,142 @@
|
|||||||
|
# Mailu main configuration file
|
||||||
|
#
|
||||||
|
# This file is autogenerated by the configuration management wizard for compose flavor.
|
||||||
|
# For a detailed list of configuration variables, see the documentation at
|
||||||
|
# https://mailu.io
|
||||||
|
|
||||||
|
###################################
|
||||||
|
# Common configuration variables
|
||||||
|
###################################
|
||||||
|
|
||||||
|
# Set to a randomly generated 16 bytes string
|
||||||
|
SECRET_KEY={{mailu_secret_key}}
|
||||||
|
|
||||||
|
# Subnet of the docker network. This should not conflict with any networks to which your system is connected. (Internal and external!)
|
||||||
|
SUBNET=192.168.203.0/24
|
||||||
|
|
||||||
|
# Main mail domain
|
||||||
|
DOMAIN={{domain}}
|
||||||
|
|
||||||
|
# Hostnames for this server, separated with comas
|
||||||
|
HOSTNAMES=infinito.one
|
||||||
|
|
||||||
|
# Postmaster local part (will append the main mail domain)
|
||||||
|
POSTMASTER=admin
|
||||||
|
|
||||||
|
# Choose how secure connections will behave (value: letsencrypt, cert, notls, mail, mail-letsencrypt)
|
||||||
|
TLS_FLAVOR=letsencrypt
|
||||||
|
|
||||||
|
# Authentication rate limit (per source IP address)
|
||||||
|
AUTH_RATELIMIT=10/minute;1000/hour
|
||||||
|
|
||||||
|
# Opt-out of statistics, replace with "True" to opt out
|
||||||
|
DISABLE_STATISTICS=True
|
||||||
|
|
||||||
|
###################################
|
||||||
|
# Optional features
|
||||||
|
###################################
|
||||||
|
|
||||||
|
# Expose the admin interface (value: true, false)
|
||||||
|
ADMIN=true
|
||||||
|
|
||||||
|
# Choose which webmail to run if any (values: roundcube, rainloop, none)
|
||||||
|
WEBMAIL=roundcube
|
||||||
|
|
||||||
|
# Dav server implementation (value: radicale, none)
|
||||||
|
WEBDAV=radicale
|
||||||
|
|
||||||
|
# Antivirus solution (value: clamav, none)
|
||||||
|
ANTIVIRUS=clamav
|
||||||
|
|
||||||
|
###################################
|
||||||
|
# Mail settings
|
||||||
|
###################################
|
||||||
|
|
||||||
|
# Message size limit in bytes
|
||||||
|
# Default: accept messages up to 50MB
|
||||||
|
# Max attachment size will be 33% smaller
|
||||||
|
MESSAGE_SIZE_LIMIT=50000000
|
||||||
|
|
||||||
|
# Networks granted relay permissions
|
||||||
|
# Use this with care, all hosts in this networks will be able to send mail without authentication!
|
||||||
|
RELAYNETS=
|
||||||
|
|
||||||
|
# Will relay all outgoing mails if configured
|
||||||
|
RELAYHOST=
|
||||||
|
|
||||||
|
# Fetchmail delay
|
||||||
|
FETCHMAIL_DELAY=600
|
||||||
|
|
||||||
|
# Recipient delimiter, character used to delimiter localpart from custom address part
|
||||||
|
RECIPIENT_DELIMITER=+
|
||||||
|
|
||||||
|
# DMARC rua and ruf email
|
||||||
|
DMARC_RUA=admin
|
||||||
|
DMARC_RUF=admin
|
||||||
|
|
||||||
|
# Welcome email, enable and set a topic and body if you wish to send welcome
|
||||||
|
# emails to all users.
|
||||||
|
WELCOME=false
|
||||||
|
WELCOME_SUBJECT=Welcome to your new email account
|
||||||
|
WELCOME_BODY=Welcome to your new email account, if you can read this, then it is configured properly!
|
||||||
|
|
||||||
|
# Maildir Compression
|
||||||
|
# choose compression-method, default: none (value: bz2, gz)
|
||||||
|
COMPRESSION=
|
||||||
|
# change compression-level, default: 6 (value: 1-9)
|
||||||
|
COMPRESSION_LEVEL=
|
||||||
|
|
||||||
|
###################################
|
||||||
|
# Web settings
|
||||||
|
###################################
|
||||||
|
|
||||||
|
# Path to redirect / to
|
||||||
|
WEBROOT_REDIRECT=/webmail
|
||||||
|
|
||||||
|
# Path to the admin interface if enabled
|
||||||
|
WEB_ADMIN=/admin
|
||||||
|
|
||||||
|
# Path to the webmail if enabled
|
||||||
|
WEB_WEBMAIL=/webmail
|
||||||
|
|
||||||
|
# Website name
|
||||||
|
SITENAME=Website name Infinito.one
|
||||||
|
|
||||||
|
# Linked Website URL
|
||||||
|
WEBSITE=https://{{domain}}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
###################################
|
||||||
|
# Advanced settings
|
||||||
|
###################################
|
||||||
|
|
||||||
|
# Log driver for front service. Possible values:
|
||||||
|
# json-file (default)
|
||||||
|
# journald (On systemd platforms, useful for Fail2Ban integration)
|
||||||
|
# syslog (Non systemd platforms, Fail2Ban integration. Disables `docker-compose log` for front!)
|
||||||
|
# LOG_DRIVER=json-file
|
||||||
|
|
||||||
|
# Docker-compose project name, this will prepended to containers names.
|
||||||
|
COMPOSE_PROJECT_NAME=mailu
|
||||||
|
|
||||||
|
# Default password scheme used for newly created accounts and changed passwords
|
||||||
|
# (value: BLF-CRYPT, SHA512-CRYPT, SHA256-CRYPT, MD5-CRYPT, CRYPT)
|
||||||
|
PASSWORD_SCHEME=BLF-CRYPT
|
||||||
|
|
||||||
|
# Header to take the real ip from
|
||||||
|
REAL_IP_HEADER=
|
||||||
|
|
||||||
|
# IPs for nginx set_real_ip_from (CIDR list separated by commas)
|
||||||
|
REAL_IP_FROM=
|
||||||
|
|
||||||
|
# choose wether mailu bounces (no) or rejects (yes) mail when recipient is unknown (value: yes, no)
|
||||||
|
REJECT_UNLISTED_RECIPIENT=
|
||||||
|
|
||||||
|
# Log level threshold in start.py (value: CRITICAL, ERROR, WARNING, INFO, DEBUG, NOTSET)
|
||||||
|
LOG_LEVEL=WARNING
|
||||||
|
|
||||||
|
###################################
|
||||||
|
# Database settings
|
||||||
|
###################################
|
||||||
|
DB_FLAVOR=sqlite
|
@ -0,0 +1,11 @@
|
|||||||
|
location /
|
||||||
|
{
|
||||||
|
proxy_pass https://127.0.0.1:{{https_port}}/;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
|
||||||
|
proxy_connect_timeout 300;
|
||||||
|
proxy_send_timeout 300;
|
||||||
|
proxy_read_timeout 300;
|
||||||
|
send_timeout 300;
|
||||||
|
}
|
Loading…
Reference in New Issue
Block a user