feat(webmail): add Roundcube web UI for mail.produktor.io (#74)
- webmail service (roundcube/roundcubemail) in compose: IMAP/SMTP STARTTLS against the DMS container via mail.produktor.io FQDN (container alias fails TLS peer-name verification) - NPM proxy host 66 -> 172.17.0.1:19944, port 19944 published on 127.0.0.1 + 172.17.0.1 - ROUNDCUBEMAIL_DES_KEY from .env (required) - README: Web UI section, account list, client settings
This commit is contained in:
@@ -0,0 +1,68 @@
|
|||||||
|
# mail-server
|
||||||
|
|
||||||
|
Docker Compose mail stack for `mail.produktor.io` on arc-01, based on
|
||||||
|
[docker-mailserver](https://docker-mailserver.github.io/docker-mailserver/) (DMS).
|
||||||
|
|
||||||
|
| Service | Container | Ports |
|
||||||
|
|---------|-----------|-------|
|
||||||
|
| Mail server (DMS) | `mailserver` | 25 (SMTP), 465 (SMTPS), 587 (Submission STARTTLS), 143 (IMAP STARTTLS), 993 (IMAPS) |
|
||||||
|
| Webmail (Roundcube) | `webmail` | 127.0.0.1:19944 / 172.17.0.1:19944 (HTTP, behind NPM) |
|
||||||
|
|
||||||
|
## Accounts
|
||||||
|
|
||||||
|
Source of truth is file-based: `config/postfix-accounts.cf` (SHA512-CRYPT
|
||||||
|
hashes). Current mailboxes:
|
||||||
|
|
||||||
|
- `info@produktor.io`
|
||||||
|
- `andriy.oblivantsev@produktor.io`
|
||||||
|
- `ano@produktor.io`
|
||||||
|
- `postmaster@produktor.io`
|
||||||
|
- `postman@produktor.io`
|
||||||
|
|
||||||
|
Passwords live in `.env` (`INFO_PASSWORD`, `ANDRIY_PASSWORD`; `ano@` uses
|
||||||
|
`GATOR_MAIL_PASS` in the gator repo `.env`). Do not commit `.env`.
|
||||||
|
|
||||||
|
## Web UI (Roundcube)
|
||||||
|
|
||||||
|
Webmail runs as the `webmail` service (official `roundcube/roundcubemail`
|
||||||
|
image) and is reachable at **https://mail.produktor.io** (alias
|
||||||
|
**https://webmail.produktor.io**) via Nginx Proxy Manager (proxy host 66 →
|
||||||
|
`172.17.0.1:19944`, Let's Encrypt).
|
||||||
|
|
||||||
|
Login: any mailbox address from the table above + its real password. The UI
|
||||||
|
shows one mailbox per login; to see all accounts, log in with each one. The
|
||||||
|
account list is the `postfix-accounts.cf` file (see Accounts).
|
||||||
|
|
||||||
|
Connection details used by the webmail (IMAP/SMTP):
|
||||||
|
|
||||||
|
- IMAP: `mail.produktor.io:143` STARTTLS (or `:993` SSL)
|
||||||
|
- SMTP submission: `mail.produktor.io:587` STARTTLS, AUTH required
|
||||||
|
|
||||||
|
Host note: the webmail must connect to the DMS container via the FQDN
|
||||||
|
`mail.produktor.io` (Docker embedded DNS resolves it to the `mailserver`
|
||||||
|
container inside the compose network). Connecting to the bare container alias
|
||||||
|
`mailserver` fails TLS peer-name verification, because the DMS certificate is
|
||||||
|
issued for `mail.produktor.io`.
|
||||||
|
|
||||||
|
### Manage
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose up -d # start mailserver + webmail
|
||||||
|
docker compose logs -f webmail # webmail logs
|
||||||
|
docker exec webmail sh # shell into webmail
|
||||||
|
```
|
||||||
|
|
||||||
|
The webmail stores its sqlite database (addressbook, settings) in
|
||||||
|
`data/roundcube/db/`. `ROUNDCUBEMAIL_DES_KEY` (session encryption) must be set
|
||||||
|
in `.env` — compose fails without it.
|
||||||
|
|
||||||
|
## Reverse proxy (NPM)
|
||||||
|
|
||||||
|
`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container,
|
||||||
|
see the `gitea` repo): forward `http://172.17.0.1:19944`, Let's Encrypt cert
|
||||||
|
(SAN: `mail.produktor.io`, `webmail.produktor.io`), SSL forced, HTTP/2.
|
||||||
|
|
||||||
|
## TLS
|
||||||
|
|
||||||
|
DMS uses a Let's Encrypt certificate for `mail.produktor.io` mounted from
|
||||||
|
`tls/letsencrypt/mail.produktor.io/` (`SSL_TYPE=letsencrypt`).
|
||||||
@@ -31,3 +31,31 @@ services:
|
|||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
- SYS_PTRACE
|
- SYS_PTRACE
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
|
||||||
|
# Webmail UI (Roundcube) — https://mail.produktor.io (NPM proxy host 66 -> 172.17.0.1:19944)
|
||||||
|
# IMAP STARTTLS 143 / SMTP submission STARTTLS 587 against the DMS container (same compose network).
|
||||||
|
# Host must be mail.produktor.io (not the container alias `mailserver`): the DMS cert is CN/SAN
|
||||||
|
# mail.produktor.io and PHP's TLS peer-name verification rejects the bare container name.
|
||||||
|
# Docker's embedded DNS resolves mail.produktor.io to the mailserver container inside the network.
|
||||||
|
webmail:
|
||||||
|
image: docker.io/roundcube/roundcubemail:latest
|
||||||
|
container_name: webmail
|
||||||
|
restart: unless-stopped
|
||||||
|
depends_on:
|
||||||
|
- mailserver
|
||||||
|
ports:
|
||||||
|
- "127.0.0.1:19944:80"
|
||||||
|
- "172.17.0.1:19944:80"
|
||||||
|
volumes:
|
||||||
|
# sqlite (addressbook, settings) survives container recreation
|
||||||
|
- ./data/roundcube/db:/var/www/db
|
||||||
|
environment:
|
||||||
|
- ROUNDCUBEMAIL_DB_TYPE=sqlite
|
||||||
|
- ROUNDCUBEMAIL_DEFAULT_HOST=tls://mail.produktor.io
|
||||||
|
- ROUNDCUBEMAIL_DEFAULT_PORT=143
|
||||||
|
- ROUNDCUBEMAIL_SMTP_SERVER=tls://mail.produktor.io
|
||||||
|
- ROUNDCUBEMAIL_SMTP_PORT=587
|
||||||
|
- ROUNDCUBEMAIL_SMTP_AUTH=LOGIN
|
||||||
|
- ROUNDCUBEMAIL_USERNAME_DOMAIN=produktor.io
|
||||||
|
- ROUNDCUBEMAIL_SKIN=elastic
|
||||||
|
- ROUNDCUBEMAIL_DES_KEY=${ROUNDCUBEMAIL_DES_KEY:?set ROUNDCUBEMAIL_DES_KEY in .env}
|
||||||
|
|||||||
Reference in New Issue
Block a user