mirror of
https://github.com/chatmail/relay.git
synced 2026-09-27 01:30:11 +00:00
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
33f925caa7 | ||
|
|
4435864779 |
@@ -133,6 +133,9 @@ def _configure_dovecot(deployer, config: Config, debug: bool = False):
|
||||
config=config,
|
||||
debug=debug,
|
||||
disable_ipv6=config.disable_ipv6,
|
||||
config_dir="/etc/dovecot",
|
||||
dh_path="/usr/share/dovecot/dh.pem",
|
||||
quota_expire_bin="/usr/local/lib/chatmaild/venv/bin/chatmail-quota-expire",
|
||||
)
|
||||
deployer.put_template("dovecot/auth.lua.j2", "/etc/dovecot/auth.lua", config=config)
|
||||
deployer.remove_file("/etc/dovecot/auth.conf")
|
||||
|
||||
@@ -62,11 +62,11 @@ imap_capability = +XDELTAPUSH XCHATMAIL
|
||||
# Authentication for system users.
|
||||
passdb {
|
||||
driver = lua
|
||||
args = file=/etc/dovecot/auth.lua blocking=yes
|
||||
args = file={{ config_dir }}/auth.lua blocking=yes
|
||||
}
|
||||
userdb {
|
||||
driver = lua
|
||||
args = file=/etc/dovecot/auth.lua blocking=yes
|
||||
args = file={{ config_dir }}/auth.lua blocking=yes
|
||||
}
|
||||
##
|
||||
## Mailbox locations and namespaces
|
||||
@@ -168,7 +168,7 @@ plugin {
|
||||
}
|
||||
|
||||
service quota-warning {
|
||||
executable = script /usr/local/lib/chatmaild/venv/bin/chatmail-quota-expire
|
||||
executable = script {{ quota_expire_bin }}
|
||||
user = vmail
|
||||
unix_listener quota-warning {
|
||||
user = vmail
|
||||
@@ -179,7 +179,7 @@ service quota-warning {
|
||||
# push_notification configuration
|
||||
plugin {
|
||||
# <https://doc.dovecot.org/2.3/configuration_manual/push_notification/#lua-lua>
|
||||
push_notification_driver = lua:file=/etc/dovecot/push_notification.lua
|
||||
push_notification_driver = lua:file={{ config_dir }}/push_notification.lua
|
||||
}
|
||||
|
||||
service lmtp {
|
||||
@@ -254,7 +254,7 @@ service anvil {
|
||||
ssl = required
|
||||
ssl_cert = <{{ config.tls_cert_path }}
|
||||
ssl_key = <{{ config.tls_key_path }}
|
||||
ssl_dh = </usr/share/dovecot/dh.pem
|
||||
ssl_dh = <{{ dh_path }}
|
||||
ssl_min_protocol = TLSv1.3
|
||||
ssl_prefer_server_ciphers = yes
|
||||
|
||||
|
||||
@@ -55,6 +55,10 @@ def _configure_nginx(deployer, config: Config, debug: bool = False):
|
||||
"/etc/nginx/nginx.conf",
|
||||
config=config,
|
||||
disable_ipv6=config.disable_ipv6,
|
||||
config_dir="/etc/nginx",
|
||||
stream_module="modules/ngx_stream_module.so",
|
||||
www_root="/var/www/html",
|
||||
cgi_dir="/usr/lib/cgi-bin",
|
||||
)
|
||||
|
||||
deployer.put_template(
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
load_module modules/ngx_stream_module.so;
|
||||
{% if stream_module %}load_module {{ stream_module }};{% endif %}
|
||||
|
||||
user www-data;
|
||||
worker_processes auto;
|
||||
@@ -54,7 +54,7 @@ http {
|
||||
# Do not emit nginx version on error pages.
|
||||
server_tokens off;
|
||||
|
||||
include /etc/nginx/mime.types;
|
||||
include {{ config_dir }}/mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
@@ -68,7 +68,7 @@ http {
|
||||
|
||||
listen 127.0.0.1:8443 ssl default_server;
|
||||
|
||||
root /var/www/html;
|
||||
root {{ www_root }};
|
||||
|
||||
index index.html index.htm;
|
||||
|
||||
@@ -96,8 +96,8 @@ http {
|
||||
{% endif %}
|
||||
|
||||
fastcgi_pass unix:/run/fcgiwrap.socket;
|
||||
include /etc/nginx/fastcgi_params;
|
||||
fastcgi_param SCRIPT_FILENAME /usr/lib/cgi-bin/newemail.py;
|
||||
include {{ config_dir }}/fastcgi_params;
|
||||
fastcgi_param SCRIPT_FILENAME {{ cgi_dir }}/newemail.py;
|
||||
}
|
||||
|
||||
# Old URL for compatibility with e.g. printed QR codes.
|
||||
@@ -114,8 +114,8 @@ http {
|
||||
{% endif %}
|
||||
|
||||
fastcgi_pass unix:/run/fcgiwrap.socket;
|
||||
include /etc/nginx/fastcgi_params;
|
||||
fastcgi_param SCRIPT_FILENAME /usr/lib/cgi-bin/newemail.py;
|
||||
include {{ config_dir }}/fastcgi_params;
|
||||
fastcgi_param SCRIPT_FILENAME {{ cgi_dir }}/newemail.py;
|
||||
}
|
||||
|
||||
# Proxy to iroh-relay service.
|
||||
|
||||
@@ -1 +1 @@
|
||||
{{ config.opendkim_selector }}._domainkey.{{ config.domain_name }} {{ config.domain_name }}:{{ config.opendkim_selector }}:/etc/dkimkeys/{{ config.opendkim_selector }}.private
|
||||
{{ config.opendkim_selector }}._domainkey.{{ config.domain_name }} {{ config.domain_name }}:{{ config.opendkim_selector }}:{{ keys_dir }}/{{ config.opendkim_selector }}.private
|
||||
|
||||
@@ -30,6 +30,8 @@ class OpendkimDeployer(Deployer):
|
||||
"opendkim/opendkim.conf",
|
||||
"/etc/opendkim.conf",
|
||||
config={"domain_name": domain, "opendkim_selector": dkim_selector},
|
||||
keys_dir="/etc/dkimkeys",
|
||||
trust_anchor="/usr/share/dns/root.key",
|
||||
)
|
||||
|
||||
self.remove_file("/etc/opendkim/screen.lua")
|
||||
@@ -46,6 +48,7 @@ class OpendkimDeployer(Deployer):
|
||||
"/etc/dkimkeys/KeyTable",
|
||||
owner="opendkim",
|
||||
config={"domain_name": domain, "opendkim_selector": dkim_selector},
|
||||
keys_dir="/etc/dkimkeys",
|
||||
)
|
||||
|
||||
self.put_template(
|
||||
|
||||
@@ -21,9 +21,9 @@ DNSTimeout 60
|
||||
# setup options can be found in /usr/share/doc/opendkim/README.opendkim.
|
||||
Domain {{ config.domain_name }}
|
||||
Selector {{ config.opendkim_selector }}
|
||||
KeyFile /etc/dkimkeys/{{ config.opendkim_selector }}.private
|
||||
KeyTable /etc/dkimkeys/KeyTable
|
||||
SigningTable refile:/etc/dkimkeys/SigningTable
|
||||
KeyFile {{ keys_dir }}/{{ config.opendkim_selector }}.private
|
||||
KeyTable {{ keys_dir }}/KeyTable
|
||||
SigningTable refile:{{ keys_dir }}/SigningTable
|
||||
|
||||
# Sign Autocrypt header in addition to the default specified in RFC 6376.
|
||||
#
|
||||
@@ -58,7 +58,7 @@ PidFile /run/opendkim/opendkim.pid
|
||||
|
||||
# The trust anchor enables DNSSEC. In Debian, the trust anchor file is provided
|
||||
# by the package dns-root-data.
|
||||
TrustAnchorFile /usr/share/dns/root.key
|
||||
TrustAnchorFile {{ trust_anchor }}
|
||||
|
||||
# Sign messages when `-o milter_macro_daemon_name=ORIGINATING` is set.
|
||||
MTA ORIGINATING
|
||||
|
||||
@@ -24,6 +24,8 @@ class PostfixDeployer(Deployer):
|
||||
"/etc/postfix/main.cf",
|
||||
config=config,
|
||||
disable_ipv6=config.disable_ipv6,
|
||||
config_dir="/etc/postfix",
|
||||
ca_path="/etc/ssl/certs",
|
||||
)
|
||||
|
||||
self.put_template(
|
||||
@@ -31,6 +33,7 @@ class PostfixDeployer(Deployer):
|
||||
"/etc/postfix/master.cf",
|
||||
debug=False,
|
||||
config=config,
|
||||
config_dir="/etc/postfix",
|
||||
)
|
||||
|
||||
self.put_file(
|
||||
|
||||
@@ -19,13 +19,13 @@ smtpd_tls_cert_file={{ config.tls_cert_path }}
|
||||
smtpd_tls_key_file={{ config.tls_key_path }}
|
||||
smtpd_tls_security_level=may
|
||||
|
||||
smtp_tls_CApath=/etc/ssl/certs
|
||||
smtp_tls_CApath={{ ca_path }}
|
||||
smtp_tls_security_level=verify
|
||||
# Send SNI extension when connecting to other servers.
|
||||
# <https://www.postfix.org/postconf.5.html#smtp_tls_servername>
|
||||
smtp_tls_servername = hostname
|
||||
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
|
||||
smtp_tls_policy_maps = regexp:/etc/postfix/smtp_tls_policy_map
|
||||
smtp_tls_policy_maps = regexp:{{ config_dir }}/smtp_tls_policy_map
|
||||
smtp_tls_protocols = >=TLSv1.2
|
||||
smtp_tls_mandatory_protocols = >=TLSv1.2
|
||||
|
||||
@@ -83,7 +83,7 @@ inet_protocols = ipv4
|
||||
inet_protocols = all
|
||||
{% endif %}
|
||||
|
||||
lmtp_header_checks = regexp:/etc/postfix/lmtp_header_cleanup
|
||||
lmtp_header_checks = regexp:{{ config_dir }}/lmtp_header_cleanup
|
||||
|
||||
# Do not apply header checks to MIME headers
|
||||
# and other headers that are actually part of the message body.
|
||||
@@ -98,7 +98,7 @@ mua_sender_restrictions = reject_sender_login_mismatch, permit_sasl_authenticate
|
||||
mua_helo_restrictions = permit_mynetworks, reject_invalid_helo_hostname, reject_non_fqdn_helo_hostname, permit
|
||||
|
||||
# 1:1 map MAIL FROM to SASL login name.
|
||||
smtpd_sender_login_maps = regexp:/etc/postfix/login_map
|
||||
smtpd_sender_login_maps = regexp:{{ config_dir }}/login_map
|
||||
|
||||
# Do not lookup SMTP client hostnames to reduce delays
|
||||
# and avoid unnecessary DNS requests.
|
||||
|
||||
@@ -102,7 +102,7 @@ postlog unix-dgram n - n - 1 postlogd
|
||||
# to make sure the users
|
||||
# cannot send unprotected Subject.
|
||||
authclean unix n - - - 0 cleanup
|
||||
-o header_checks=regexp:/etc/postfix/submission_header_cleanup
|
||||
-o header_checks=regexp:{{ config_dir }}/submission_header_cleanup
|
||||
|
||||
# Reducing `maxproc` here may result in a head of line blocking
|
||||
# when there are many messages sent to unreachable destinations
|
||||
|
||||
+11
-3
@@ -63,9 +63,17 @@ and run the following commands:
|
||||
scripts/initenv.sh
|
||||
scripts/cmdeploy run
|
||||
|
||||
If you don't want the latest development version,
|
||||
but a specific tagged release like `1.10.0 <https://github.com/chatmail/relay/releases/tag/1.10.0>`_,
|
||||
run ``git pull origin 1.10.0`` instead.
|
||||
To upgrade to the latest tag,
|
||||
``cd`` into your local checkout of https://github.com/chatmail/relay/
|
||||
and run the following commands:
|
||||
|
||||
::
|
||||
|
||||
git fetch --tags
|
||||
latestTag=$(git describe --tags "$(git rev-list --tags --max-count=1)")
|
||||
git checkout $latestTag
|
||||
scripts/initenv.sh
|
||||
scripts/cmdeploy run
|
||||
|
||||
If you made local changes for your setup,
|
||||
they will be reapplied as long as they don't conflict with the upgrade.
|
||||
|
||||
Reference in New Issue
Block a user