Files
mail-server/README.md
T

70 lines
2.6 KiB
Markdown

# mail-server
Docker Compose mail stack for `mail.produktor.io` on arc-01, based on
[docker-mailserver](https://docker-mailserver.github.io/docker-mailserver/) (DMS).
| Service | Container | Ports |
|---------|-----------|-------|
| Mail server (DMS) | `mailserver` | 25 (SMTP), 465 (SMTPS), 587 (Submission STARTTLS), 143 (IMAP STARTTLS), 993 (IMAPS) |
| Webmail (Roundcube) | `webmail` | 127.0.0.1:19944 / 172.17.0.1:19944 (HTTP, behind NPM) |
| Account admin | — (removed) | — |
## Accounts
Source of truth is file-based: `config/postfix-accounts.cf` (SHA512-CRYPT
hashes). Current mailboxes:
- `info@produktor.io`
- `andriy.oblivantsev@produktor.io`
- `ano@produktor.io`
- `postmaster@produktor.io`
- `postman@produktor.io`
Passwords live in `.env` (`INFO_PASSWORD`, `ANDRIY_PASSWORD`; `ano@` uses
`GATOR_MAIL_PASS` in the gator repo `.env`). Do not commit `.env`.
## Web UI (Roundcube)
Webmail runs as the `webmail` service (official `roundcube/roundcubemail`
image) and is reachable at **https://mail.produktor.io** (alias
**https://webmail.produktor.io**) via Nginx Proxy Manager (proxy host 66 →
`172.17.0.1:19944`, Let's Encrypt).
Login: any mailbox address from the table above + its real password. The UI
shows one mailbox per login; to see all accounts, log in with each one. The
account list is the `postfix-accounts.cf` file (see Accounts).
Connection details used by the webmail (IMAP/SMTP):
- IMAP: `mail.produktor.io:143` STARTTLS (or `:993` SSL)
- SMTP submission: `mail.produktor.io:587` STARTTLS, AUTH required
Host note: the webmail must connect to the DMS container via the FQDN
`mail.produktor.io` (Docker embedded DNS resolves it to the `mailserver`
container inside the compose network). Connecting to the bare container alias
`mailserver` fails TLS peer-name verification, because the DMS certificate is
issued for `mail.produktor.io`.
### Manage
```bash
docker compose up -d # start mailserver + webmail
docker compose logs -f webmail # webmail logs
docker exec webmail sh # shell into webmail
```
The webmail stores its sqlite database (addressbook, settings) in
`data/roundcube/db/`. `ROUNDCUBEMAIL_DES_KEY` (session encryption) must be set
in `.env` — compose fails without it.
## Reverse proxy (NPM)
`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container,
see the `gitea` repo): forward `http://172.17.0.1:19944`, Let's Encrypt cert
(SAN: `mail.produktor.io`, `webmail.produktor.io`), SSL forced, HTTP/2.
## TLS
DMS uses a Let's Encrypt certificate for `mail.produktor.io` mounted from
`tls/letsencrypt/mail.produktor.io/` (`SSL_TYPE=letsencrypt`).