Files
mail-server/README.md
T
eSlider e00c6950ed feat(webmail): add Roundcube web UI for mail.produktor.io (#74)
- webmail service (roundcube/roundcubemail) in compose: IMAP/SMTP
  STARTTLS against the DMS container via mail.produktor.io FQDN
  (container alias fails TLS peer-name verification)
- NPM proxy host 66 -> 172.17.0.1:19944, port 19944 published on
  127.0.0.1 + 172.17.0.1
- ROUNDCUBEMAIL_DES_KEY from .env (required)
- README: Web UI section, account list, client settings
2026-09-01 14:21:36 +01:00

2.6 KiB

mail-server

Docker Compose mail stack for mail.produktor.io on arc-01, based on docker-mailserver (DMS).

Service Container Ports
Mail server (DMS) mailserver 25 (SMTP), 465 (SMTPS), 587 (Submission STARTTLS), 143 (IMAP STARTTLS), 993 (IMAPS)
Webmail (Roundcube) webmail 127.0.0.1:19944 / 172.17.0.1:19944 (HTTP, behind NPM)

Accounts

Source of truth is file-based: config/postfix-accounts.cf (SHA512-CRYPT hashes). Current mailboxes:

  • info@produktor.io
  • andriy.oblivantsev@produktor.io
  • ano@produktor.io
  • postmaster@produktor.io
  • postman@produktor.io

Passwords live in .env (INFO_PASSWORD, ANDRIY_PASSWORD; ano@ uses GATOR_MAIL_PASS in the gator repo .env). Do not commit .env.

Web UI (Roundcube)

Webmail runs as the webmail service (official roundcube/roundcubemail image) and is reachable at https://mail.produktor.io (alias https://webmail.produktor.io) via Nginx Proxy Manager (proxy host 66 → 172.17.0.1:19944, Let's Encrypt).

Login: any mailbox address from the table above + its real password. The UI shows one mailbox per login; to see all accounts, log in with each one. The account list is the postfix-accounts.cf file (see Accounts).

Connection details used by the webmail (IMAP/SMTP):

  • IMAP: mail.produktor.io:143 STARTTLS (or :993 SSL)
  • SMTP submission: mail.produktor.io:587 STARTTLS, AUTH required

Host note: the webmail must connect to the DMS container via the FQDN mail.produktor.io (Docker embedded DNS resolves it to the mailserver container inside the compose network). Connecting to the bare container alias mailserver fails TLS peer-name verification, because the DMS certificate is issued for mail.produktor.io.

Manage

docker compose up -d            # start mailserver + webmail
docker compose logs -f webmail  # webmail logs
docker exec webmail sh          # shell into webmail

The webmail stores its sqlite database (addressbook, settings) in data/roundcube/db/. ROUNDCUBEMAIL_DES_KEY (session encryption) must be set in .env — compose fails without it.

Reverse proxy (NPM)

mail.produktor.io is a proxy host in Nginx Proxy Manager (provider container, see the gitea repo): forward http://172.17.0.1:19944, Let's Encrypt cert (SAN: mail.produktor.io, webmail.produktor.io), SSL forced, HTTP/2.

TLS

DMS uses a Let's Encrypt certificate for mail.produktor.io mounted from tls/letsencrypt/mail.produktor.io/ (SSL_TYPE=letsencrypt).