From 33f925caa76b8ddbfcd08daf19dc6e7eac813392 Mon Sep 17 00:00:00 2001 From: holger krekel Date: Sat, 26 Sep 2026 23:18:20 +0200 Subject: [PATCH] refactor: un-hardcode filesystem paths in configuration templates Drive all file system paths from templating variables, useful e.g. for FreeBSD which keeps debian's `/etc` hiearchy rather in `/usr/local/etc`. Also support static nginx builds which have the stream module compiled in and thus don't need dynamic linking to a stream module. --- cmdeploy/src/cmdeploy/dovecot/deployer.py | 3 +++ cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 | 10 +++++----- cmdeploy/src/cmdeploy/nginx/deployer.py | 4 ++++ cmdeploy/src/cmdeploy/nginx/nginx.conf.j2 | 14 +++++++------- cmdeploy/src/cmdeploy/opendkim/KeyTable | 2 +- cmdeploy/src/cmdeploy/opendkim/deployer.py | 3 +++ cmdeploy/src/cmdeploy/opendkim/opendkim.conf | 8 ++++---- cmdeploy/src/cmdeploy/postfix/deployer.py | 3 +++ cmdeploy/src/cmdeploy/postfix/main.cf.j2 | 8 ++++---- cmdeploy/src/cmdeploy/postfix/master.cf.j2 | 2 +- 10 files changed, 35 insertions(+), 22 deletions(-) diff --git a/cmdeploy/src/cmdeploy/dovecot/deployer.py b/cmdeploy/src/cmdeploy/dovecot/deployer.py index a4e0d5a7..b0d23ec9 100644 --- a/cmdeploy/src/cmdeploy/dovecot/deployer.py +++ b/cmdeploy/src/cmdeploy/dovecot/deployer.py @@ -133,6 +133,9 @@ def _configure_dovecot(deployer, config: Config, debug: bool = False): config=config, debug=debug, disable_ipv6=config.disable_ipv6, + config_dir="/etc/dovecot", + dh_path="/usr/share/dovecot/dh.pem", + quota_expire_bin="/usr/local/lib/chatmaild/venv/bin/chatmail-quota-expire", ) deployer.put_template("dovecot/auth.lua.j2", "/etc/dovecot/auth.lua", config=config) deployer.remove_file("/etc/dovecot/auth.conf") diff --git a/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 b/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 index 19b08a64..5f4ff51e 100644 --- a/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 +++ b/cmdeploy/src/cmdeploy/dovecot/dovecot.conf.j2 @@ -62,11 +62,11 @@ imap_capability = +XDELTAPUSH XCHATMAIL # Authentication for system users. passdb { driver = lua - args = file=/etc/dovecot/auth.lua blocking=yes + args = file={{ config_dir }}/auth.lua blocking=yes } userdb { driver = lua - args = file=/etc/dovecot/auth.lua blocking=yes + args = file={{ config_dir }}/auth.lua blocking=yes } ## ## Mailbox locations and namespaces @@ -168,7 +168,7 @@ plugin { } service quota-warning { - executable = script /usr/local/lib/chatmaild/venv/bin/chatmail-quota-expire + executable = script {{ quota_expire_bin }} user = vmail unix_listener quota-warning { user = vmail @@ -179,7 +179,7 @@ service quota-warning { # push_notification configuration plugin { # - push_notification_driver = lua:file=/etc/dovecot/push_notification.lua + push_notification_driver = lua:file={{ config_dir }}/push_notification.lua } service lmtp { @@ -254,7 +254,7 @@ service anvil { ssl = required ssl_cert = <{{ config.tls_cert_path }} ssl_key = <{{ config.tls_key_path }} -ssl_dh = smtp_tls_servername = hostname smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache -smtp_tls_policy_maps = regexp:/etc/postfix/smtp_tls_policy_map +smtp_tls_policy_maps = regexp:{{ config_dir }}/smtp_tls_policy_map smtp_tls_protocols = >=TLSv1.2 smtp_tls_mandatory_protocols = >=TLSv1.2 @@ -83,7 +83,7 @@ inet_protocols = ipv4 inet_protocols = all {% endif %} -lmtp_header_checks = regexp:/etc/postfix/lmtp_header_cleanup +lmtp_header_checks = regexp:{{ config_dir }}/lmtp_header_cleanup # Do not apply header checks to MIME headers # and other headers that are actually part of the message body. @@ -98,7 +98,7 @@ mua_sender_restrictions = reject_sender_login_mismatch, permit_sasl_authenticate mua_helo_restrictions = permit_mynetworks, reject_invalid_helo_hostname, reject_non_fqdn_helo_hostname, permit # 1:1 map MAIL FROM to SASL login name. -smtpd_sender_login_maps = regexp:/etc/postfix/login_map +smtpd_sender_login_maps = regexp:{{ config_dir }}/login_map # Do not lookup SMTP client hostnames to reduce delays # and avoid unnecessary DNS requests. diff --git a/cmdeploy/src/cmdeploy/postfix/master.cf.j2 b/cmdeploy/src/cmdeploy/postfix/master.cf.j2 index bd599f5c..13b39e53 100644 --- a/cmdeploy/src/cmdeploy/postfix/master.cf.j2 +++ b/cmdeploy/src/cmdeploy/postfix/master.cf.j2 @@ -102,7 +102,7 @@ postlog unix-dgram n - n - 1 postlogd # to make sure the users # cannot send unprotected Subject. authclean unix n - - - 0 cleanup - -o header_checks=regexp:/etc/postfix/submission_header_cleanup + -o header_checks=regexp:{{ config_dir }}/submission_header_cleanup # Reducing `maxproc` here may result in a head of line blocking # when there are many messages sent to unreachable destinations