From e00c6950ed2544692dd8fa8f3ca590cdd44bd35e Mon Sep 17 00:00:00 2001 From: Andriy Oblivantsev Date: Tue, 1 Sep 2026 14:21:36 +0100 Subject: [PATCH] feat(webmail): add Roundcube web UI for mail.produktor.io (#74) - webmail service (roundcube/roundcubemail) in compose: IMAP/SMTP STARTTLS against the DMS container via mail.produktor.io FQDN (container alias fails TLS peer-name verification) - NPM proxy host 66 -> 172.17.0.1:19944, port 19944 published on 127.0.0.1 + 172.17.0.1 - ROUNDCUBEMAIL_DES_KEY from .env (required) - README: Web UI section, account list, client settings --- README.md | 68 ++++++++++++++++++++++++++++++++++++++++++++++++++++ compose.yaml | 28 ++++++++++++++++++++++ 2 files changed, 96 insertions(+) create mode 100644 README.md diff --git a/README.md b/README.md new file mode 100644 index 0000000..0fe3d7a --- /dev/null +++ b/README.md @@ -0,0 +1,68 @@ +# mail-server + +Docker Compose mail stack for `mail.produktor.io` on arc-01, based on +[docker-mailserver](https://docker-mailserver.github.io/docker-mailserver/) (DMS). + +| Service | Container | Ports | +|---------|-----------|-------| +| Mail server (DMS) | `mailserver` | 25 (SMTP), 465 (SMTPS), 587 (Submission STARTTLS), 143 (IMAP STARTTLS), 993 (IMAPS) | +| Webmail (Roundcube) | `webmail` | 127.0.0.1:19944 / 172.17.0.1:19944 (HTTP, behind NPM) | + +## Accounts + +Source of truth is file-based: `config/postfix-accounts.cf` (SHA512-CRYPT +hashes). Current mailboxes: + +- `info@produktor.io` +- `andriy.oblivantsev@produktor.io` +- `ano@produktor.io` +- `postmaster@produktor.io` +- `postman@produktor.io` + +Passwords live in `.env` (`INFO_PASSWORD`, `ANDRIY_PASSWORD`; `ano@` uses +`GATOR_MAIL_PASS` in the gator repo `.env`). Do not commit `.env`. + +## Web UI (Roundcube) + +Webmail runs as the `webmail` service (official `roundcube/roundcubemail` +image) and is reachable at **https://mail.produktor.io** (alias +**https://webmail.produktor.io**) via Nginx Proxy Manager (proxy host 66 → +`172.17.0.1:19944`, Let's Encrypt). + +Login: any mailbox address from the table above + its real password. The UI +shows one mailbox per login; to see all accounts, log in with each one. The +account list is the `postfix-accounts.cf` file (see Accounts). + +Connection details used by the webmail (IMAP/SMTP): + +- IMAP: `mail.produktor.io:143` STARTTLS (or `:993` SSL) +- SMTP submission: `mail.produktor.io:587` STARTTLS, AUTH required + +Host note: the webmail must connect to the DMS container via the FQDN +`mail.produktor.io` (Docker embedded DNS resolves it to the `mailserver` +container inside the compose network). Connecting to the bare container alias +`mailserver` fails TLS peer-name verification, because the DMS certificate is +issued for `mail.produktor.io`. + +### Manage + +```bash +docker compose up -d # start mailserver + webmail +docker compose logs -f webmail # webmail logs +docker exec webmail sh # shell into webmail +``` + +The webmail stores its sqlite database (addressbook, settings) in +`data/roundcube/db/`. `ROUNDCUBEMAIL_DES_KEY` (session encryption) must be set +in `.env` — compose fails without it. + +## Reverse proxy (NPM) + +`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container, +see the `gitea` repo): forward `http://172.17.0.1:19944`, Let's Encrypt cert +(SAN: `mail.produktor.io`, `webmail.produktor.io`), SSL forced, HTTP/2. + +## TLS + +DMS uses a Let's Encrypt certificate for `mail.produktor.io` mounted from +`tls/letsencrypt/mail.produktor.io/` (`SSL_TYPE=letsencrypt`). diff --git a/compose.yaml b/compose.yaml index 9fa263a..8ea2fdf 100644 --- a/compose.yaml +++ b/compose.yaml @@ -31,3 +31,31 @@ services: - NET_ADMIN - SYS_PTRACE restart: unless-stopped + + # Webmail UI (Roundcube) — https://mail.produktor.io (NPM proxy host 66 -> 172.17.0.1:19944) + # IMAP STARTTLS 143 / SMTP submission STARTTLS 587 against the DMS container (same compose network). + # Host must be mail.produktor.io (not the container alias `mailserver`): the DMS cert is CN/SAN + # mail.produktor.io and PHP's TLS peer-name verification rejects the bare container name. + # Docker's embedded DNS resolves mail.produktor.io to the mailserver container inside the network. + webmail: + image: docker.io/roundcube/roundcubemail:latest + container_name: webmail + restart: unless-stopped + depends_on: + - mailserver + ports: + - "127.0.0.1:19944:80" + - "172.17.0.1:19944:80" + volumes: + # sqlite (addressbook, settings) survives container recreation + - ./data/roundcube/db:/var/www/db + environment: + - ROUNDCUBEMAIL_DB_TYPE=sqlite + - ROUNDCUBEMAIL_DEFAULT_HOST=tls://mail.produktor.io + - ROUNDCUBEMAIL_DEFAULT_PORT=143 + - ROUNDCUBEMAIL_SMTP_SERVER=tls://mail.produktor.io + - ROUNDCUBEMAIL_SMTP_PORT=587 + - ROUNDCUBEMAIL_SMTP_AUTH=LOGIN + - ROUNDCUBEMAIL_USERNAME_DOMAIN=produktor.io + - ROUNDCUBEMAIL_SKIN=elastic + - ROUNDCUBEMAIL_DES_KEY=${ROUNDCUBEMAIL_DES_KEY:?set ROUNDCUBEMAIL_DES_KEY in .env}