mirror of
https://github.com/chatmail/relay.git
synced 2026-06-17 09:01:06 +00:00
Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| da38753995 | |||
| d8f2129e78 |
@@ -29,7 +29,7 @@ jobs:
|
||||
ref: ${{ github.event.pull_request.head.sha }}
|
||||
persist-credentials: false
|
||||
- name: download filtermail
|
||||
run: curl -L https://github.com/chatmail/filtermail/releases/download/v0.7.1/filtermail-x86_64 -o /usr/local/bin/filtermail && chmod +x /usr/local/bin/filtermail
|
||||
run: curl -L https://github.com/chatmail/filtermail/releases/download/v0.7.0/filtermail-x86_64 -o /usr/local/bin/filtermail && chmod +x /usr/local/bin/filtermail
|
||||
- name: run chatmaild tests
|
||||
working-directory: chatmaild
|
||||
run: pipx run tox
|
||||
|
||||
@@ -8,7 +8,7 @@ Chatmail relay servers are interoperable Mail Transport Agents (MTAs) designed f
|
||||
- **Instant/Realtime:** sub-second message delivery, realtime P2P
|
||||
streaming, privacy-preserving Push Notifications for Apple, Google, and Huawei;
|
||||
|
||||
- **Security Enforcement**: only connections with strict TLS are accepted; all messages must be corrently signed with DKIM and OpenPGP-encrypted with minimized metadata
|
||||
- **Security Enforcement**: only strict TLS, DKIM and OpenPGP with minimized metadata accepted
|
||||
|
||||
- **Reliable Federation and Decentralization:** No spam or IP reputation checks, federating
|
||||
depends on established IETF standards and protocols.
|
||||
|
||||
@@ -9,7 +9,7 @@ dependencies = [
|
||||
"iniconfig",
|
||||
"filelock",
|
||||
"requests",
|
||||
"crypt-r >= 3.13.1 ; python_version >= '3.13'",
|
||||
"crypt-r >= 3.13.1 ; python_version >= '3.11'",
|
||||
]
|
||||
|
||||
[tool.setuptools]
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import ipaddress
|
||||
from pathlib import Path
|
||||
from random import randint
|
||||
|
||||
import iniconfig
|
||||
|
||||
@@ -41,6 +42,11 @@ class Config:
|
||||
self.username_max_length = int(params.pop("username_max_length", 9))
|
||||
self.password_min_length = int(params.pop("password_min_length", 9))
|
||||
self.www_folder = params.pop("www_folder", "")
|
||||
|
||||
self.imap_port = int(params.pop("imap_port", 143))
|
||||
self.imaps_port = int(params.pop("imaps_port", 993))
|
||||
self.smtp_port = int(params.pop("smtp_port", 587))
|
||||
self.smtps_port = int(params.pop("smtps_port", 465))
|
||||
self.filtermail_smtp_port = int(params.pop("filtermail_smtp_port", "10080"))
|
||||
self.filtermail_smtp_port_incoming = int(
|
||||
params.pop("filtermail_smtp_port_incoming", "10081")
|
||||
@@ -138,8 +144,15 @@ def parse_size_mb(limit):
|
||||
|
||||
def write_initial_config(inipath, mail_domain, overrides):
|
||||
"""Write out default config file, using the specified config value overrides."""
|
||||
content = get_default_config_content(mail_domain, **overrides)
|
||||
inipath.write_text(content)
|
||||
content = get_default_config_content(mail_domain, **overrides).splitlines()
|
||||
used_ports = [25, 53, 80, 143, 402, 443, 465, 587, 993, 3340, 3903, 3904, 8443, 10080, 10081, 10082, 10083, 10025, 10026]
|
||||
for config_key in ["smtp_port", "imap_port", "smtps_port", "imaps_port"]:
|
||||
value = randint(1, 65536)
|
||||
while value in used_ports:
|
||||
value = randint(65535)
|
||||
used_ports.append(value)
|
||||
content.append(f"{config_key} = {value}")
|
||||
inipath.write_text("\n".join(content))
|
||||
|
||||
|
||||
def get_default_config_content(mail_domain, **overrides):
|
||||
|
||||
@@ -166,7 +166,7 @@ class Deployer:
|
||||
return self.put_template(src, dest, **kwargs)
|
||||
return self.put_file(src, dest)
|
||||
|
||||
def put_file(self, src, dest, mode="644", **kwargs):
|
||||
def put_file(self, src, dest, mode="644"):
|
||||
if isinstance(src, str):
|
||||
src = get_resource(src)
|
||||
res = files.put(
|
||||
@@ -176,7 +176,6 @@ class Deployer:
|
||||
user="root",
|
||||
group="root",
|
||||
mode=mode,
|
||||
**kwargs,
|
||||
)
|
||||
|
||||
return self._update_restart_signals(dest, res)
|
||||
|
||||
@@ -164,7 +164,6 @@ class UnboundDeployer(Deployer):
|
||||
self.put_file(
|
||||
src=BytesIO(b"nameserver 127.0.0.1\nnameserver 9.9.9.9\n"),
|
||||
dest="/etc/resolv.conf",
|
||||
force=True,
|
||||
)
|
||||
server.shell(
|
||||
name="Generate root keys for validating DNSSEC",
|
||||
@@ -496,15 +495,15 @@ def deploy_chatmail(config_path: Path, disable_mail: bool, website_only: bool) -
|
||||
if config.tls_cert_mode == "acme":
|
||||
port_services.append(("acmetool", 402))
|
||||
port_services += [
|
||||
(["imap-login", "dovecot"], 143),
|
||||
(["imap-login", "dovecot", "nginx"], config.imap_port),
|
||||
# acmetool previously listened on port 80,
|
||||
# so don't complain during upgrade that moved it to port 402
|
||||
# and gave the port to nginx.
|
||||
(["acmetool", "nginx"], 80),
|
||||
("nginx", 443),
|
||||
(["master", "smtpd"], 465),
|
||||
(["master", "smtpd"], 587),
|
||||
(["imap-login", "dovecot"], 993),
|
||||
(["master", "smtpd", "nginx"], config.smtp_port),
|
||||
(["master", "smtpd", "nginx"], config.smtps_port),
|
||||
(["imap-login", "dovecot", "nginx"], config.imaps_port),
|
||||
("iroh-relay", 3340),
|
||||
("mtail", 3903),
|
||||
("stats", 3904),
|
||||
|
||||
@@ -20,10 +20,10 @@ class FiltermailDeployer(Deployer):
|
||||
return
|
||||
|
||||
arch = host.get_fact(facts.server.Arch)
|
||||
url = f"https://github.com/chatmail/filtermail/releases/download/v0.7.1/filtermail-{arch}"
|
||||
url = f"https://github.com/chatmail/filtermail/releases/download/v0.7.0/filtermail-{arch}"
|
||||
sha256sum = {
|
||||
"x86_64": "fc2d8141166f8561b9711fb68c5327fc9421f814c46dc69671a4605a95b175c0",
|
||||
"aarch64": "37e52c5ddb373ef29b5ead89658407c53f48d10ce055a2dbd9c606fa1ebd5f7f",
|
||||
"x86_64": "451f295a85b3b12dbb0f89e18ec319f742ee46dec218f20f7923bfb017a248bd",
|
||||
"aarch64": "6833061b2a2028264fdeb32f0a6123e1ff73de57dace125364016300b748452e",
|
||||
}[arch]
|
||||
self.download_executable(url, self.bin_path, sha256sum)
|
||||
|
||||
|
||||
@@ -7,14 +7,14 @@
|
||||
<displayShortName>{{ config.mail_domain }}</displayShortName>
|
||||
<incomingServer type="imap">
|
||||
<hostname>{{ config.mail_domain }}</hostname>
|
||||
<port>993</port>
|
||||
<port>{{ config.imaps_port }}</port>
|
||||
<socketType>SSL</socketType>
|
||||
<authentication>password-cleartext</authentication>
|
||||
<username>%EMAILADDRESS%</username>
|
||||
</incomingServer>
|
||||
<incomingServer type="imap">
|
||||
<hostname>{{ config.mail_domain }}</hostname>
|
||||
<port>143</port>
|
||||
<port>{{ config.imap_port }}</port>
|
||||
<socketType>STARTTLS</socketType>
|
||||
<authentication>password-cleartext</authentication>
|
||||
<username>%EMAILADDRESS%</username>
|
||||
@@ -28,14 +28,14 @@
|
||||
</incomingServer>
|
||||
<outgoingServer type="smtp">
|
||||
<hostname>{{ config.mail_domain }}</hostname>
|
||||
<port>465</port>
|
||||
<port>{{ config.smtps_port }}</port>
|
||||
<socketType>SSL</socketType>
|
||||
<authentication>password-cleartext</authentication>
|
||||
<username>%EMAILADDRESS%</username>
|
||||
</outgoingServer>
|
||||
<outgoingServer type="smtp">
|
||||
<hostname>{{ config.mail_domain }}</hostname>
|
||||
<port>587</port>
|
||||
<port>{{ config.smtp_port }}</port>
|
||||
<socketType>STARTTLS</socketType>
|
||||
<authentication>password-cleartext</authentication>
|
||||
<username>%EMAILADDRESS%</username>
|
||||
|
||||
@@ -31,6 +31,26 @@ stream {
|
||||
~\bimap\b 127.0.0.1:993;
|
||||
}
|
||||
|
||||
server {
|
||||
listen {{ config.smtp_port }};
|
||||
proxy_pass 127.0.0.1:587;
|
||||
}
|
||||
|
||||
server {
|
||||
listen {{ config.imap_port }};
|
||||
proxy_pass 127.0.0.1:143;
|
||||
}
|
||||
|
||||
server {
|
||||
listen {{ config.smtps_port }};
|
||||
proxy_pass 127.0.0.1:465;
|
||||
}
|
||||
|
||||
server {
|
||||
listen {{ config.imaps_port }};
|
||||
proxy_pass 127.0.0.1:993;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443;
|
||||
{% if not disable_ipv6 %}
|
||||
|
||||
@@ -225,6 +225,21 @@ Accepting and delivering mail
|
||||
nginx -.SMTP inet:465.-> smtpd-smtps
|
||||
mta2[Remote relay] -.SMTP inet:25.-> smtpd-smtp
|
||||
mta2 -.HTTPS /mxdeliv.-> nginx
|
||||
style postfix fill:#363
|
||||
style qmgr fill:#252
|
||||
style authclean fill:#252
|
||||
style cleanup fill:#252
|
||||
style lmtp-filtermail fill:#252
|
||||
style lmtp fill:#252
|
||||
style bounce fill:#252
|
||||
style smtpd-submission fill:#252
|
||||
style smtpd-smtps fill:#252
|
||||
style smtpd-reinject-outgoing fill:#252
|
||||
style smtpd-reinject-incoming fill:#252
|
||||
style smtpd-smtp fill:#252
|
||||
style filtermail-outgoing fill:#225
|
||||
style filtermail-incoming fill:#225
|
||||
style filtermail-transport fill:#225
|
||||
|
||||
Operational details of a chatmail relay
|
||||
----------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user