Browse Source
Merge pull request #2177 from vbrandl/feature/deploy-mailcow
Add deploy hook for mailcow
dnsconf
neil
6 years ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with
78 additions and
0 deletions
-
deploy/README.md
-
deploy/mailcow.sh
|
|
@ -391,3 +391,23 @@ acme.sh --deploy --deploy-hook mydevil -d example.com |
|
|
|
``` |
|
|
|
|
|
|
|
That will remove old certificate and install new one. |
|
|
|
|
|
|
|
## 15. Deploy your cert to local mailcow server |
|
|
|
|
|
|
|
You can install your certificates to a local [mailcow](https://github.com/mailcow/mailcow-dockerized/) instance. The |
|
|
|
deploy hook will copy the certificates and reload the containers, that use the certificates (`postfix-mailcow` |
|
|
|
`dovecot-mailcow` and `nginx-mailcow`). |
|
|
|
|
|
|
|
```sh |
|
|
|
$ export DEPLOY_MAILCOW_PATH="/path/to/mailcow" |
|
|
|
$ acme.sh --deploy -d example.com --deploy-hook mailcow |
|
|
|
``` |
|
|
|
|
|
|
|
The default command to restart is `docker-compose restart postfix-mailcow dovecot-mailcow nginx-mailcow`, if you want a |
|
|
|
custom restart command, specify it by setting `DEPLOY_MAILCOW_RELOAD`: |
|
|
|
|
|
|
|
```sh |
|
|
|
$ export DEPLOY_MAILCOW_PATH="/path/to/mailcow" |
|
|
|
$ export DEPLOY_MAILCOW_RELOAD="docker-compose restart" |
|
|
|
$ acme.sh --deploy -d example.com --deploy-hook mailcow |
|
|
|
``` |
|
|
@ -0,0 +1,58 @@ |
|
|
|
#!/usr/bin/env sh |
|
|
|
|
|
|
|
#Here is a script to deploy cert to mailcow. |
|
|
|
|
|
|
|
#returns 0 means success, otherwise error. |
|
|
|
|
|
|
|
######## Public functions ##################### |
|
|
|
|
|
|
|
#domain keyfile certfile cafile fullchain |
|
|
|
mailcow_deploy() { |
|
|
|
_cdomain="$1" |
|
|
|
_ckey="$2" |
|
|
|
_ccert="$3" |
|
|
|
_cca="$4" |
|
|
|
_cfullchain="$5" |
|
|
|
|
|
|
|
_debug _cdomain "$_cdomain" |
|
|
|
_debug _ckey "$_ckey" |
|
|
|
_debug _ccert "$_ccert" |
|
|
|
_debug _cca "$_cca" |
|
|
|
_debug _cfullchain "$_cfullchain" |
|
|
|
|
|
|
|
_mailcow_path="${DEPLOY_MAILCOW_PATH}" |
|
|
|
|
|
|
|
if [ -z "$_mailcow_path" ]; then |
|
|
|
_err "Mailcow path is not found, please define DEPLOY_MAILCOW_PATH." |
|
|
|
return 1 |
|
|
|
fi |
|
|
|
|
|
|
|
_ssl_path="${_mailcow_path}/data/assets/ssl/" |
|
|
|
if [ ! -d "$_ssl_path" ]; then |
|
|
|
_err "Cannot find mailcow ssl path: $_ssl_path" |
|
|
|
return 1 |
|
|
|
fi |
|
|
|
|
|
|
|
_info "Copying key and cert" |
|
|
|
_real_key="$_ssl_path/key.pem" |
|
|
|
if ! cat "$_ckey" >"$_real_key"; then |
|
|
|
_err "Error: write key file to: $_real_key" |
|
|
|
return 1 |
|
|
|
fi |
|
|
|
|
|
|
|
_real_fullchain="$_ssl_path/cert.pem" |
|
|
|
if ! cat "$_cfullchain" >"$_real_fullchain"; then |
|
|
|
_err "Error: write cert file to: $_real_fullchain" |
|
|
|
return 1 |
|
|
|
fi |
|
|
|
|
|
|
|
DEFAULT_MAILCOW_RELOAD="cd ${_mailcow_path} && docker-compose restart postfix-mailcow dovecot-mailcow nginx-mailcow" |
|
|
|
_reload="${DEPLOY_MAILCOW_RELOAD:-$DEFAULT_MAILCOW_RELOAD}" |
|
|
|
|
|
|
|
_info "Run reload: $_reload" |
|
|
|
if eval "$_reload"; then |
|
|
|
_info "Reload success!" |
|
|
|
fi |
|
|
|
return 0 |
|
|
|
|
|
|
|
} |