The installer knew one distribution: Debian, with docker, on a new enough release. Everything else it would have offered and then failed at. Three facts now decide what the matrix offers, and each is read from the machine rather than assumed: - The container runtime. Docker where the machine has one, podman on the Red Hat family, which ships no docker at all. Both go through the same compose plugin: compose speaks the Docker API and podman serves it, so there is one compose file and one deployment path, not two. Telling a Fedora operator to add Docker's own repository to a machine that already has a container runtime would have been the wrong trade. - glibc. The server binary is downloaded, not built here, and it is linked against 2.39. Rocky 9 (2.34), Debian 12 and Ubuntu 22.04 cannot run it, so the host shape is refused there with the version found and the container shape named as the answer -- rather than installing a file that cannot start. - The operating system itself. This compiles for macOS and Windows because Go compiles anything, and on either it would read no os-release, find no systemd, and describe a machine that does not exist. It now says what it is and exits. Two bugs the other distributions found, both of which Debian could not have: - The survey reported the first thing in the way and stopped, so on Fedora it asked to start podman.socket, and then -- having done it -- asked for the compose plugin. Needs are named now, not described, and reported together. - apply used the survey taken before dependencies were installed, so on a machine that had no runtime at all it installed podman and then reached for docker. It re-surveys after resolving, and stops if containers still are not usable. The lab takes DISTRO now: debian13, debian12, ubuntu2404, fedora, rocky9, arch, each with its own disk and ssh port so several can be up at once. The cases no longer say "docker" either. install-local passes on Debian 13, Fedora 43 and Rocky 9 -- 20 checks each, ending with a sign-in to the webmail the installer put there.
84 lines
4.0 KiB
Markdown
84 lines
4.0 KiB
Markdown
# inbuxa-installer
|
|
|
|
One program that installs the **inbuxa** suite on the machine you run it on:
|
|
the mail server, the administration console and the webmail, each as a
|
|
container or on the host, in any mixture.
|
|
|
|
inbuxa survey what this machine is, as the installer sees it
|
|
inbuxa install --dry-run … what would happen, before any of it does
|
|
inbuxa install … do it
|
|
|
|
It only ever installs here. A second machine runs it too, and `inbuxa join`
|
|
points that machine at a server already running elsewhere.
|
|
|
|
Linux only, and it says so on any other system rather than reporting a
|
|
machine that does not exist. Debian, Red Hat and Arch families, and the
|
|
derivatives people run: Ubuntu, Fedora, Rocky, CentOS, CachyOS. It uses
|
|
whichever container runtime the distribution ships -- docker where there is
|
|
one, podman on the Red Hat family -- and refuses a shape the machine cannot
|
|
deliver, with the reason.
|
|
|
|
## What works today
|
|
|
|
This is early. What is built:
|
|
|
|
- **`survey`** -- the machine's facts: distribution, init, whether Docker is
|
|
usable *by this user*, Node's version, which of the suite's ports are free
|
|
and what holds the ones that are not, memory, disk, and whether an install
|
|
is already recorded here. It changes nothing.
|
|
- **`install --dry-run`** -- the whole plan: every file, unit, container,
|
|
port, DNS record and credential, and a refusal with a reason when the
|
|
machine cannot carry out what was asked.
|
|
- **`deps`** -- what a shape needs that this machine has not got, and, with
|
|
`--install`, the doing of it: the Docker daemon from the distribution's own
|
|
archive, the Compose plugin and Node from their official builds, both
|
|
pinned by version and checked against a checksum in the source before
|
|
anything is put in place. `install --install-deps` does the same as part of
|
|
a run. A missing dependency is an offer, not a refusal.
|
|
|
|
- **`install --yes`** -- carries the plan out, for container shapes: writes
|
|
the deployment, fetches the images, brings the mail server up in bootstrap
|
|
mode with a credential that exists only for that step, completes bootstrap,
|
|
brings the rest up without it, exempts the front ends from the auto-ban,
|
|
creates the first mailbox, writes `credentials.txt` and `dns.zone`, and
|
|
then checks that all three answer.
|
|
|
|
Not built yet: host installs, the terminal interface, `join`, `status`,
|
|
`upgrade`, `uninstall`. The design is in the inbuxa specification (§6.1 and
|
|
the installer draft); the phases are there too.
|
|
|
|
inbuxa install --local --domain example.test --install-deps --yes
|
|
|
|
is the shortest thing that works today: the whole suite on loopback, with no
|
|
DNS and no certificates, on a machine that starts with nothing. Without
|
|
`--local` it takes the real ports, puts Caddy in front and obtains
|
|
certificates -- which `e2e/cases/install-public.sh` proves against a private
|
|
CA, with no internet and no public name involved.
|
|
|
|
## Building and testing
|
|
|
|
go build ./cmd/inbuxa
|
|
|
|
The installer writes units, creates users and takes ports 25 and 443, so it
|
|
is tested on a throwaway virtual machine rather than on anybody's desk:
|
|
|
|
e2e/vm/up.sh a Debian 13 machine, in qemu, as you
|
|
DISTRO=fedora e2e/vm/up.sh or fedora, rocky9, ubuntu2404, arch, debian12
|
|
e2e/vm/run.sh e2e/cases/survey.sh what it says about a machine
|
|
e2e/vm/run.sh e2e/cases/deps.sh the offer, and taking it
|
|
e2e/vm/run.sh e2e/cases/install-local.sh a whole suite, and signing in to it
|
|
e2e/vm/run.sh e2e/cases/install-public.sh the same with real ports and certificates
|
|
e2e/vm/down.sh remove it
|
|
|
|
Each case starts from a copy of the machine taken when it was new, so a run
|
|
is free to break it and a failure is the installer's rather than the last
|
|
run's leftovers. `e2e/vm/up.sh` needs qemu, KVM and xorriso; nothing needs
|
|
root on your machine.
|
|
|
|
## License
|
|
|
|
AGPL-3.0-or-later. Some of this began as [ihasmail-oneshot], which is ours
|
|
and under the same license.
|
|
|
|
[ihasmail-oneshot]: https://git.coffeylabs.org/inbuxa/ihasmail-oneshot
|