feat(webmail): add Roundcube web UI for mail.produktor.io (#74)

- webmail service (roundcube/roundcubemail) in compose: IMAP/SMTP
  STARTTLS against the DMS container via mail.produktor.io FQDN
  (container alias fails TLS peer-name verification)
- NPM proxy host 66 -> 172.17.0.1:19944, port 19944 published on
  127.0.0.1 + 172.17.0.1
- ROUNDCUBEMAIL_DES_KEY from .env (required)
- README: Web UI section, account list, client settings
This commit is contained in:
2026-09-01 14:21:36 +01:00
parent f3ea090501
commit e00c6950ed
2 changed files with 96 additions and 0 deletions
+28
View File
@@ -31,3 +31,31 @@ services:
- NET_ADMIN
- SYS_PTRACE
restart: unless-stopped
# Webmail UI (Roundcube) — https://mail.produktor.io (NPM proxy host 66 -> 172.17.0.1:19944)
# IMAP STARTTLS 143 / SMTP submission STARTTLS 587 against the DMS container (same compose network).
# Host must be mail.produktor.io (not the container alias `mailserver`): the DMS cert is CN/SAN
# mail.produktor.io and PHP's TLS peer-name verification rejects the bare container name.
# Docker's embedded DNS resolves mail.produktor.io to the mailserver container inside the network.
webmail:
image: docker.io/roundcube/roundcubemail:latest
container_name: webmail
restart: unless-stopped
depends_on:
- mailserver
ports:
- "127.0.0.1:19944:80"
- "172.17.0.1:19944:80"
volumes:
# sqlite (addressbook, settings) survives container recreation
- ./data/roundcube/db:/var/www/db
environment:
- ROUNDCUBEMAIL_DB_TYPE=sqlite
- ROUNDCUBEMAIL_DEFAULT_HOST=tls://mail.produktor.io
- ROUNDCUBEMAIL_DEFAULT_PORT=143
- ROUNDCUBEMAIL_SMTP_SERVER=tls://mail.produktor.io
- ROUNDCUBEMAIL_SMTP_PORT=587
- ROUNDCUBEMAIL_SMTP_AUTH=LOGIN
- ROUNDCUBEMAIL_USERNAME_DOMAIN=produktor.io
- ROUNDCUBEMAIL_SKIN=elastic
- ROUNDCUBEMAIL_DES_KEY=${ROUNDCUBEMAIL_DES_KEY:?set ROUNDCUBEMAIL_DES_KEY in .env}