Author SHA1 Message Date
eSlider 6e8a9dc963 feat(mail): share oleksandra.svitelska mailbox with info@ (read-only)
Add oleksandra.svitelska@produktor.io to PRODUCTION_OWNERS so info@
sees it under Shared/ (lookup read), same class as the other production
mailboxes. Applied live via user-patches.sh (idempotent); no container
recreation needed.
2026-09-23 19:37:56 +01:00
eSlider e1208be24e chore(mail): pinned-version update check off, Gmail postscreen whitelist, docs
- compose: ENABLE_UPDATE_CHECK=0 (image intentionally pinned to DMS v15.1.0).

- postscreen: permit Google SMTP outbound ranges (Gmail retries from rotating IPs,

  '450 PASS NEW' never completes) — keeps LinkedIn/Gmail mail out of the tarpit.

- README: DNS/ops notes; user-patches: whitelist copy path.
2026-09-16 14:59:45 +01:00
eSlider 4b3af3fad3 fix(mail): only $mydomain is a local virtual mailbox domain
gmail.com and the other historical/incubator domains (gmx.de, gridfactor.de,

rpf.de, viscreation.de, wheregroup.com) were in /etc/postfix/vhost, so mail to

those addresses short-circuited into the local incubator archive via dovecot

lmtp and never left the host — e.g. a campaign test from info@produktor.io to

eslider@gmail.com. DMS appends postfix-main.cf last, so this override wins.

Dovecot accounts stay for IMAP/doveadm import; only local delivery changes.

Verified: v19 EML relayed to gmail-smtp-in.l.google.com, status=sent, dkim=pass.
2026-09-16 14:51:36 +01:00
eSlider 5cd74b09bd Merge pull request 'fix(mail): pin DMS image to v15.1.0 (dovecot 2.3) to match config (gator #101)' (#9) from fix/dms-pin-v15#101 into main 2026-09-06 02:43:40 +01:00
eSlider 37bd8a7e45 fix(mail): pin DMS image to v15.1.0 (dovecot 2.3) to match config (gator #101) 2026-09-06 02:43:32 +01:00
eSlider 417e9960c1 Merge pull request 'feat(mail): raise message size cap to 200M for archive import (gator #101)' (#8) from feat/mail-size-limit-archive#101 into main 2026-09-06 02:04:14 +01:00
eSlider c729e026b2 feat(mail): raise message size cap to 200M for archive import (gator #101) 2026-09-06 02:04:08 +01:00
eSlider 58e34615da Merge pull request 'feat(dovecot): incubator owners defacto (gator #101)' (#7) from feat/dovecot-defacto-owners#101 into main 2026-09-06 01:19:16 +01:00
eSlider 8dbfba6be3 feat(dovecot): incubator owners defacto (gator #101) 2026-09-06 01:19:00 +01:00
eSlider 58a57e890e fix(mail): postscreen whitelist LinkedIn senders (450 reject of verification mail) 2026-09-04 09:37:18 +01:00
eSlider 717348db6c feat(dovecot): incubator owner eslider@gmail.com (G-10.3 #100) 2026-09-02 19:22:21 +01:00
eSlider 4e20a92885 Merge pull request 'feat(dovecot): historical-account andriy.oblivantsev@wheregroup.com for wheregroup incubator (#252)' (#6) from feat/historical-wheregroup-account#252 into main 2026-09-02 13:54:29 +01:00
eSlider d2724ec727 chore(dovecot): drop deleted wheregroup@produktor.io A1 pilot box from owner lists (#252) 2026-09-02 13:50:54 +01:00
eSlider 6cdd704aef feat(dovecot): historical-account andriy.oblivantsev@wheregroup.com for wheregroup incubator (#252) 2026-09-02 13:42:58 +01:00
eSlider 8041ab3962 Merge pull request 'feat(dovecot): incubator owner wheregroup@produktor.io + info@ delete access (#251)' (#5) from feat/incubator-wheregroup#251 into main 2026-09-02 12:12:53 +01:00
eSlider a4ab96d025 feat(dovecot): incubator owner wheregroup@ + info@ delete access (#251) 2026-09-02 12:10:51 +01:00
Andriy OblivantsevandeSlider b0dd75b0ff fix(webmail): persist Roundcube sqlite in volume (/var/roundcube/db) 2026-09-01 16:33:40 +01:00
eSlider f424b9d324 Merge pull request 'feat(dovecot): shared mailboxes — info@ reads all accounts (#79)' (#4) from feat/shared-mailboxes#79 into main 2026-09-01 16:03:41 +01:00
eSlider 2bb6ed310e feat(dovecot): shared mailboxes — info@ reads all accounts (#79)
Dovecot ACL + shared namespace (shared/%%u/), acl_shared_dict in mail-state,
idempotent user-patches.sh grants info@ read-only (lookup read) on every
mailbox of ano@, andriy.oblivantsev@, postmaster@ and pre-subscribes the
shared folders so Roundcube's subscribed folder list shows them. Delivery and
passwords untouched; other accounts see no shared folders.
2026-09-01 16:02:52 +01:00
Andriy OblivantsevandeSlider c9bc594031 chore(mail): remove mail-admin (superseded by Dovecot shared folders) (#76) 2026-09-01 15:35:07 +01:00
eSlider 403c79c3e4 Merge pull request 'feat(webmail): Roundcube web UI (#74)' (#2) from feat/webmail#74 into main 2026-09-01 15:09:01 +01:00
eSlider 5a46ba4b33 feat(mail-admin): read-only account view for mail.produktor.io (#74)
- admin/: Go stdlib-only HTTP viewer, lists accounts from
  config/postfix-accounts.cf with per-mailbox message counts (INBOX and
  total, same numbers doveadm reports) and storage; quota from
  dovecot-quotas.cf; Basic Auth from .env; offline tests vs fixtures
  (go test -race ./...)
- compose: mail-admin service, build admin/Dockerfile, publishes
  127.0.0.1:19945 / 172.17.0.1:19945; config and mail-data mounted :ro,
  no docker socket
- NPM proxy host 66: location /admin/ -> 172.17.0.1:19945
- README: account admin section
2026-09-01 15:07:55 +01:00
eSlider e00c6950ed feat(webmail): add Roundcube web UI for mail.produktor.io (#74)
- webmail service (roundcube/roundcubemail) in compose: IMAP/SMTP
  STARTTLS against the DMS container via mail.produktor.io FQDN
  (container alias fails TLS peer-name verification)
- NPM proxy host 66 -> 172.17.0.1:19944, port 19944 published on
  127.0.0.1 + 172.17.0.1
- ROUNDCUBEMAIL_DES_KEY from .env (required)
- README: Web UI section, account list, client settings
2026-09-01 14:21:36 +01:00
eSlider f3ea090501 Merge pull request 'fix(fail2ban): ignoreip docker subnet /20 (#113)' (#1) from fix/fail2ban-ignoreip#113 into main 2026-08-25 22:01:37 +01:00
6 changed files with 421 additions and 1 deletions
+219
View File
@@ -0,0 +1,219 @@
# mail-server
Docker Compose mail stack for `mail.produktor.io` on arc-01, based on
[docker-mailserver](https://docker-mailserver.github.io/docker-mailserver/) (DMS).
| Service | Container | Ports |
|---------|-----------|-------|
| Mail server (DMS) | `mailserver` | 25 (SMTP), 465 (SMTPS), 587 (Submission STARTTLS), 143 (IMAP STARTTLS), 993 (IMAPS) |
| Webmail (Roundcube) | `webmail` | 127.0.0.1:19944 / 172.17.0.1:19944 (HTTP, behind NPM) |
| Account admin | — (removed) | — |
## Accounts
Source of truth is file-based: `config/postfix-accounts.cf` (SHA512-CRYPT
hashes). The file is gitignored (secrets) — it lives on the host only. Current
mailboxes:
- `info@produktor.io` — human reader (Roundcube login for the whole list)
- `andriy.oblivantsev@produktor.io`
- `oleksandra.svitelska@produktor.io`
- `ano@produktor.io`
- `postmaster@produktor.io`
- `postman@produktor.io`
- `andriy.oblivantsev@wheregroup.com` — incubator mailbox of the гдеgroup
period (issue #252): the owner's **historical address**, not an abstract
source box. Nobody logs in; legacy `.eml` corpus is imported via doveadm by
the ETL connector (`bin/mail/incubator.go`, 2dph), routed to
`Sent`/`INBOX`/`INBOX/Unmatched` by the recipient headers.
- ~~`wheregroup@produktor.io`~~ — deleted: superseded A1 pilot box of the old
abstract-"source" model (issue #251); its 1000 messages were migrated to
`andriy.oblivantsev@wheregroup.com` and the account was removed (issue #252).
Passwords live in `.env` (`INFO_PASSWORD`, `ANDRIY_PASSWORD`; `ano@` uses
`GATOR_MAIL_PASS` in the gator repo `.env`; `andriy.oblivantsev@wheregroup.com`
uses `ANDRIY_WG_PASSWORD`, random — no interactive login). Do not commit
`.env`.
## Web UI (Roundcube)
Webmail runs as the `webmail` service (official `roundcube/roundcubemail`
image) and is reachable at **https://mail.produktor.io** (alias
**https://webmail.produktor.io**) via Nginx Proxy Manager (proxy host 66 →
`172.17.0.1:19944`, Let's Encrypt).
Login: any mailbox address from the table above + its real password. The UI
shows one mailbox per login; the account list is the `postfix-accounts.cf`
file (see Accounts).
Since the shared-mailbox setup (below) `info@` additionally sees every other
mailbox under `Shared/` — one login covers the whole account list. Rights
differ per owner class: read-only for production mailboxes, read + delete for
incubator mailboxes (see Shared mailboxes).
Connection details used by the webmail (IMAP/SMTP):
- IMAP: `mail.produktor.io:143` STARTTLS (or `:993` SSL)
- SMTP submission: `mail.produktor.io:587` STARTTLS, AUTH required
Host note: the webmail must connect to the DMS container via the FQDN
`mail.produktor.io` (Docker embedded DNS resolves it to the `mailserver`
container inside the compose network). Connecting to the bare container alias
`mailserver` fails TLS peer-name verification, because the DMS certificate is
issued for `mail.produktor.io`.
### Manage
```bash
docker compose up -d # start mailserver + webmail
docker compose logs -f webmail # webmail logs
docker exec webmail sh # shell into webmail
```
The webmail stores its sqlite database (addressbook, settings) in
`data/roundcube/db/`. `ROUNDCUBEMAIL_DES_KEY` (session encryption) must be set
in `.env` — compose fails without it.
### Manage: adding a mailbox without recreating the container
A new account is applied live without `docker compose up -d` — DMS's
changedetector (`check-for-changes.sh`, polls every 2 s) picks up the edited
`config/postfix-accounts.cf` and regenerates `/etc/postfix/vmailbox`,
`/etc/dovecot/userdb` and `/etc/postfix/vhost`, then reloads Postfix and
Dovecot. No mail is lost, no container recreation.
```bash
# 1. random password for the new historical-address mailbox (stored in .env only)
PW=$(openssl rand -base64 24 | tr -dc 'A-Za-z0-9' | head -c 32)
printf 'ANDRIY_WG_PASSWORD=%s\n' "$PW" >> .env # never commit .env
# 2. add the account — password is read from stdin, never from argv/ps.
# DMS accepts any virtual user: the domain need not be serviced by
# mail.produktor.io (verified live with wheregroup.com, issue #252) — the
# account only serves IMAP/doveadm, no inbound delivery.
printf '%s\n%s\n' "$PW" "$PW" |
docker exec -i mailserver setup email add andriy.oblivantsev@wheregroup.com
# 3. changedetector applies within ~5 s; verify
docker exec mailserver doveadm user andriy.oblivantsev@wheregroup.com
# 4. give the fresh mailbox an INBOX (a brand-new owner has none — without it
# `doveadm mailbox list -u <owner>` is empty and user-patches.sh cannot
# record any share), then apply the shared/ACL policy
docker exec mailserver doveadm mailbox create -u andriy.oblivantsev@wheregroup.com INBOX
docker exec mailserver /bin/bash /tmp/docker-mailserver/user-patches.sh
```
On a **fresh deployment** (empty `postfix-accounts.cf`), add the account line
*before* the first `docker compose up -d`: user-patches.sh runs on the
container's first start and would otherwise skip owners that do not exist yet
(it logs `skip <owner>` and continues).
## Shared mailboxes (единый вход info@)
`info@produktor.io` sees every other mailbox under `Shared/` — one login in
Roundcube covers the whole account list. Delivery is unchanged (no aliases, no
redirects); other accounts keep their own passwords. Two owner classes, two
right sets for `info@`:
- **production owners** (`ano@`, `andriy.oblivantsev@`, `oleksandra.svitelska@`,
`postmaster@`): read-only — `lookup read` (issue #79);
- **incubator owners** (one account per historical address of the owner:
`andriy.oblivantsev@wheregroup.com` for the гдеgroup period; later
`eslider@gmail.com`, `...@viscreation.de`, ...): read **and delete** —
`lookup read delete expunge write-deleted` (issue #251). The owner never
logs in; mail arrives via `doveadm import`. Deleting a message in
Roundcube = filter/exclusion from the corpus (auto-sync, epic B), so the
delete button must work in `Shared/`.
Verified on live: `write-deleted` is sufficient for the `\Deleted` flag
Roundcube sets (no extra `write` right needed), `expunge` is also what
Dovecot MOVE needs on the source side when Roundcube moves a deleted message
to the reader's Trash.
How it works (Dovecot 2.3 ACL + shared namespace):
- `config/dovecot.cf` (→ `/etc/dovecot/local.conf`) enables the `acl` plugin,
adds a shared namespace `shared/%%u/` (`list=children`, read index per
reader via `INDEXPVT`), and points `acl_shared_dict` to
`/var/lib/dovecot/db/shared-mailboxes.db` (persistent via `mail-state`).
- `config/user-patches.sh` re-applies the ACLs from each shared owner's
mailboxes to `user=info@produktor.io` via `doveadm acl set` — the
only way Dovecot records the share in the shared dictionary — and
pre-subscribes the shared folders for `info@`. DMS runs it on the first
start of each container instance (plain `docker compose restart` skips the
setup step by design); ACLs, the shared dict and subscriptions persist in
`mail-state`/maildirs, so nothing is lost on restarts. Idempotent — safe to
run manually: `docker exec mailserver /bin/bash /tmp/docker-mailserver/user-patches.sh`.
The script skips owners that do not exist yet and creates a missing owner
INBOX itself (the share maps to the owner's INBOX and is only recorded if
the INBOX exists).
Upgrade behavior (image `:latest`): the config survives container recreation
because both files live in the mounted `config/`. On image upgrade the
entrypoint re-applies `dovecot.cf` and runs `user-patches.sh` again on the new
container's first start, so ACLs and subscriptions are recreated. The only
state kept outside the repo is `shared-mailboxes.db` (inside
`data/mail-state/`); if it is lost, the next (re)creation rebuilds it via
`doveadm acl set`.
Limitation (Dovecot semantics): new mailboxes created by an owner *after* the
last start do not inherit the share (no ACL inheritance); they appear for
`info@` after the next container start.
## Reverse proxy (NPM)
`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container,
see the `gitea` repo): forward `http://172.17.0.1:19944`, Let's Encrypt cert
(SAN: `mail.produktor.io`, `webmail.produktor.io`), SSL forced, HTTP/2.
## TLS
DMS uses a Let's Encrypt certificate for `mail.produktor.io` mounted from
`tls/letsencrypt/mail.produktor.io/` (`SSL_TYPE=letsencrypt`).
## DNS (live zone, arc-01)
Outbound IP is dynamic (Orange residential). SPF follows the Dynu hostname
instead of a fixed `ip4:` — `ddclient` on arc-01 keeps
`produktor.mywire.org` pointed at the current address
(`produktor/duckdns/dyndns/config/ddclient.conf`).
### produktor.io — Dynadot
| Type | Host | Value |
|------|------|-------|
| CNAME | `mail` | `produktor.mywire.org` |
| MX | `@` | `10 mail.produktor.io` |
| TXT | `@` | `v=spf1 a:produktor.mywire.org ~all` |
| TXT | `_dmarc` | `v=DMARC1; p=quarantine; adkim=r; aspf=r; pct=100` |
| TXT | `mail._domainkey` | `v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8P5kdq57uAD9r9XSxvDViVbvOaQfVEIHwS99G5PYFHcoLdhm6sAHaE94pw27BBVweed+TjevhoEaD77RV+uwsE9E+zHepnoLYcCql7vLtRy7QLrSKzNJonCin6g+kzw/2swZ+022w1W27kZgLc3LwUFaTerRI8xDOtbEUmcWGsMPW52JaKVmU3UhFMDVLpH/t1OrbZeCEReM8iK5Cc1jPno9nf3F7ang9x9o0Gyw1CP6takDQiS4X6UK23vjymaauO9PrQQpkAydhkHODq3Sxm3rgSnYjWgPl7BrVr9ujN+K12OObzquj0/Zol1Da1d0IPdzEOAa4SkpLt5FUOgQ7wIDAQAB` |
DKIM private key: `config/opendkim/keys/produktor.io/mail.private` (gitignored
on live host). Re-publish the TXT from `mail.txt` after key rotation:
`docker exec mailserver cat /etc/opendkim/keys/produktor.io/mail.txt`.
ACME DNS-01 for `mail.produktor.io` uses `scripts/dynadot-dns.sh` (Dynadot API).
### produktor.mywire.org — Dynu (dynamic A)
| Type | Host | Value |
|------|------|-------|
| A | `@` | current WAN IP (ddclient → Dynu API, ~5 min) |
As of last check: `90.169.228.16`.
### Verify
```bash
dig @1.1.1.1 +short A mail.produktor.io
dig @1.1.1.1 +short MX produktor.io
dig @1.1.1.1 +short TXT produktor.io
dig @1.1.1.1 +short TXT _dmarc.produktor.io
dig @1.1.1.1 +short TXT mail._domainkey.produktor.io
dig @1.1.1.1 +short A produktor.mywire.org
```
External deliverability smoke test: `scripts/mail-outlook-test.sh`.
**PTR** is not under our control (Orange pool) — expected mismatch; see
`~/.config/opencode/skill/mails/SKILL.md`.
+42 -1
View File
@@ -1,6 +1,10 @@
services: services:
mailserver: mailserver:
image: docker.io/mailserver/docker-mailserver:latest # Pinned to v15.1.0: the config (dovecot.cf nameless shared namespace,
# dovecot-quotas.cf) targets the Dovecot 2.3 of v15. docker.io:latest now
# pulls v16 (Dovecot 2.4) which rejects the config — deliberate upgrade to
# v16 is a separate task (migrate dovecot.cf first).
image: docker.io/mailserver/docker-mailserver:v15.1.0
container_name: mailserver container_name: mailserver
hostname: mail.produktor.io hostname: mail.produktor.io
ports: ports:
@@ -27,7 +31,44 @@ services:
- PERMIT_DOCKER=none - PERMIT_DOCKER=none
- ONE_DIR=1 - ONE_DIR=1
- SPOOF_PROTECTION=1 - SPOOF_PROTECTION=1
# No update nag: intentionally pinned to v15 (see header comment); v16 is a
# separate migration task. Disables the periodic docker-mailserver update check.
- ENABLE_UPDATE_CHECK=0
# Historical-archive mailboxes hold legacy .eml up to ~57 MB (gator #101
# defacto import) — raise the 10M Dovecot/Postfix message cap to 200M
# (POSTFIX_MESSAGE_SIZE_LIMIT sets both quota_max_mail_size and postfix
# message_size_limit in DMS).
- POSTFIX_MESSAGE_SIZE_LIMIT=200000000
cap_add: cap_add:
- NET_ADMIN - NET_ADMIN
- SYS_PTRACE - SYS_PTRACE
restart: unless-stopped restart: unless-stopped
# Webmail UI (Roundcube) — https://mail.produktor.io (NPM proxy host 66 -> 172.17.0.1:19944)
# IMAP STARTTLS 143 / SMTP submission STARTTLS 587 against the DMS container (same compose network).
# Host must be mail.produktor.io (not the container alias `mailserver`): the DMS cert is CN/SAN
# mail.produktor.io and PHP's TLS peer-name verification rejects the bare container name.
# Docker's embedded DNS resolves mail.produktor.io to the mailserver container inside the network.
webmail:
image: docker.io/roundcube/roundcubemail:latest
container_name: webmail
restart: unless-stopped
depends_on:
- mailserver
ports:
- "127.0.0.1:19944:80"
- "172.17.0.1:19944:80"
volumes:
# sqlite (addressbook, settings, identities) survives container recreation
- ./data/roundcube/db:/var/roundcube/db
environment:
- ROUNDCUBEMAIL_DB_TYPE=sqlite
- ROUNDCUBEMAIL_DEFAULT_HOST=tls://mail.produktor.io
- ROUNDCUBEMAIL_DEFAULT_PORT=143
- ROUNDCUBEMAIL_SMTP_SERVER=tls://mail.produktor.io
- ROUNDCUBEMAIL_SMTP_PORT=587
- ROUNDCUBEMAIL_SMTP_AUTH=LOGIN
- ROUNDCUBEMAIL_USERNAME_DOMAIN=produktor.io
- ROUNDCUBEMAIL_SKIN=elastic
- ROUNDCUBEMAIL_DES_KEY=${ROUNDCUBEMAIL_DES_KEY:?set ROUNDCUBEMAIL_DES_KEY in .env}
+40
View File
@@ -0,0 +1,40 @@
# Dovecot hardening (E2 D3).
auth_failure_delay = 2s
mail_max_userip_connections = 10
# --- Dovecot shared mailboxes (issue #79): info@ reads all mailboxes. ---
# Canonical Dovecot 2.3 shared-mailbox scheme: acl plugin + shared namespace +
# acl_shared_dict. The imap plugin list is explicit: inside a `protocol imap {}`
# filter $mail_plugins expands to the filter-level value from DMS's 20-imap.conf
# (which shadows the global), so a `$mail_plugins acl` line would silently drop
# `acl`. Keep DMS's imap_quota to not regress quota IMAP commands.
mail_plugins = " quota acl"
protocol imap {
mail_plugins = " quota acl imap_quota"
}
# Dovecot merges namespace blocks with the same identity (type+prefix); this
# makes the default (maildir) "." separator explicit "/" so it matches the
# shared namespace below ("All list=yes namespaces must use the same separator").
namespace inbox {
separator = /
}
namespace {
type = shared
separator = /
prefix = shared/%%u/
location = maildir:/var/mail/%%d/%%n:INDEXPVT=~/shared/%%u
# subscriptions=yes: Roundcube's folder list is subscribed-based (LIST-EXTENDED
# SUBSCRIBED / LSUB); without per-user subscriptions shared folders would be
# invisible in the web UI. user-patches.sh pre-subscribes them for info@.
subscriptions = yes
list = children
}
plugin {
acl = vfile
# Required for the shared namespace LIST to work: tracks "who shared to whom".
# /var/lib/dovecot is a symlink to /var/mail-state/lib-dovecot (persistent).
acl_shared_dict = file:/var/lib/dovecot/db/shared-mailboxes.db
}
+12
View File
@@ -0,0 +1,12 @@
108.174.0.0/16 PERMIT
144.2.0.0/15 PERMIT
# Google SMTP outbound (Gmail retries from rotating 74.125/209.85/...; postscreen 450 PASS NEW never completes)
74.125.0.0/16 PERMIT
209.85.128.0/17 PERMIT
64.233.160.0/19 PERMIT
66.102.0.0/20 PERMIT
66.249.80.0/20 PERMIT
72.14.192.0/18 PERMIT
173.194.0.0/16 PERMIT
207.126.144.0/20 PERMIT
216.239.32.0/19 PERMIT
+24
View File
@@ -0,0 +1,24 @@
# Postfix rate-limits + postscreen tarpit (E2 D3, soft mode, no DNSBL).
# NOTE: smtpd_client_error_rate_limit / smtpd_slow_connection_rate_limit do not
# exist in Postfix; mapped to the real anvil params smtpd_client_recipient_rate_limit
# and smtpd_client_auth_rate_limit (same values).
smtpd_client_connection_rate_limit = 10
smtpd_client_message_rate_limit = 20
smtpd_client_recipient_rate_limit = 10
smtpd_client_auth_rate_limit = 5
smtpd_hard_error_limit = 20
smtpd_soft_error_limit = 10
smtpd_error_sleep_time = 1s
smtpd_junk_command_limit = 2
postscreen_greet_action = enforce
postscreen_bare_newline_enable = yes
# Only $mydomain (produktor.io) is a LOCAL virtual mailbox domain (inbound).
# Historical / incubator addresses (gmail.com, gmx.de, gridfactor.de, rpf.de,
# viscreation.de, wheregroup.com) keep their Dovecot accounts for IMAP +
# doveadm import, but must NOT be local delivery domains: otherwise outbound
# mail to those domains short-circuits into the incubator archive (dovecot
# lmtp "Saved") and never leaves the host — e.g. a campaign test from
# info@produktor.io to eslider@gmail.com. Overridden last (DMS appends
# postfix-main.cf after its own setup). See mailing skill, Gitea #115.
virtual_mailbox_domains = $mydomain
+84
View File
@@ -0,0 +1,84 @@
#!/bin/bash
# Dovecot shared mailboxes. info@produktor.io gets access to the mailboxes of
# two owner classes (issue #79, issue #251 / epic #250):
# - production owners (ano@, andriy.oblivantsev@, oleksandra.svitelska@,
# postmaster@): read-only
# (`lookup read`) — one login in Roundcube covers the whole account list;
# - incubator owners: read + delete (`lookup read delete expunge
# write-deleted`) — the mailbox owner never logs in, mail is imported via
# doveadm; deleting a message in Roundcube = filter/exclusion from the
# corpus (autosync, epic B).
# Incubator model (corrected 2026-09-02, issue #252): the incubator mailbox IS
# the owner's HISTORICAL ADDRESS per period, not an abstract "source" mailbox.
# The wheregroup period = andriy.oblivantsev@wheregroup.com; later periods get
# their own account (eslider@gmail.com, ...@viscreation.de, ...). The A1 pilot
# box wheregroup@produktor.io (abstract "source" model) was deleted after its
# 1000 messages were migrated to the historical account — grant_share skips
# owners that are not (yet) in postfix-accounts.cf, so a not-yet-created
# account is a silent no-op.
# DMS runs this only on the FIRST start of each container instance (plain
# `docker compose restart` skips the setup step by design — /CONTAINER_START
# marker), so it must stay idempotent. ACLs, the shared dict and subscriptions
# persist in mail-state / maildirs across restarts.
set -euo pipefail
# 1. acl_shared_dict directory: must exist and be writable by the mail user.
SHARED_DB_DIR=/var/lib/dovecot/db
mkdir -p "${SHARED_DB_DIR}"
chown docker:docker "${SHARED_DB_DIR}"
chmod 0770 "${SHARED_DB_DIR}"
# 2. Grant info@ rights on every current mailbox of the shared owners.
# doveadm acl set is the only way Dovecot records the share in acl_shared_dict
# (manual dovecot-acl files do NOT populate the dictionary — Dovecot docs).
# NOTE: this Dovecot build accepts full right NAMES ("lookup read"), single
# letters ("lr") are rejected with "Invalid right". The incubator set below
# was verified on live (issue #251): `write-deleted` is enough for the
# \Deleted flag that Roundcube sets on Delete — the extra `write` right is
# NOT required; `expunge` is also what Dovecot MOVE needs on the source side
# when Roundcube moves a deleted message to Trash.
READER='info@produktor.io'
PRODUCTION_OWNERS='ano@produktor.io andriy.oblivantsev@produktor.io postmaster@produktor.io oleksandra.svitelska@produktor.io'
INCUBATOR_OWNERS='andriy.oblivantsev@wheregroup.com eslider@gmail.com viscreation@gmail.com viscreation@gmx.de andriy.oblivantsev@gridfactor.de ao@rpf.de andriy.oblivantsev@gmail.com viscreation@viscreation.de'
grant_share() { # $1=owner, remaining=right names
local owner=$1
shift
# Skip owners not (yet) in postfix-accounts.cf — e.g. right after a fresh
# clone, before `setup email add` was run for the incubator source.
if ! doveadm mailbox list -u "${owner}" >/dev/null 2>&1; then
echo "user-patches: skip ${owner}: account does not exist yet (run 'setup email add ${owner}')"
return 0
fi
# The shared mailbox "shared/<owner>" maps to the owner's INBOX (Dovecot
# shared-storage semantics) — subscribe it explicitly so Roundcube's
# subscribed folder list shows it.
doveadm mailbox subscribe -u "${READER}" "shared/${owner}"
# A brand-new mailbox owner has no INBOX yet and `doveadm mailbox list`
# above would be empty, so no share would be recorded. Ensure INBOX exists
# first (issue #251); "Mailbox already exists" is fine.
doveadm mailbox create -u "${owner}" INBOX >/dev/null 2>&1 || true
for mb in $(doveadm mailbox list -u "${owner}"); do
doveadm acl set -u "${owner}" "${mb}" "user=${READER}" "$@"
if [ "${mb}" != "INBOX" ]; then
doveadm mailbox subscribe -u "${READER}" "shared/${owner}/${mb}"
fi
done
}
# Production owners stay read-only for info@ (regression guard for #79).
for owner in ${PRODUCTION_OWNERS}; do
grant_share "${owner}" lookup read
done
# Incubator owners: info@ can read AND delete (filter semantics, epic #250).
for owner in ${INCUBATOR_OWNERS}; do
grant_share "${owner}" lookup read delete expunge write-deleted
done
# LinkedIn sender whitelist for postscreen (2026-09-04): LinkedIn mail to
# produktor.io was rejected with 450 by postscreen (new sender IPs). Keep the
# cidr file in sync with config/linkedin_whitelist.cidr.
cp /tmp/docker-mailserver/linkedin_whitelist.cidr /etc/postfix/linkedin_whitelist.cidr 2>/dev/null
chown postfix:postfix /etc/postfix/linkedin_whitelist.cidr 2>/dev/null
postconf -e 'postscreen_access_list = permit_mynetworks, cidr:/etc/postfix/linkedin_whitelist.cidr'