summaryrefslogtreecommitdiff
path: root/manifests/system.pp
blob: 5961f83cac12657ff05bd08a3193e4b2f05d12d5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
class mail::system {
  $postfix_smtp_listen   = "all"
  $postfix_use_amavisd   = "yes"
  $postfix_mydestination = '$myhostname, $mydomain, localhost.$mydomain, localhost'

  case $postfix_mynetworks {
    '': { $postfix_mynetworks = "127.0.0.0/8" }
  }

  case $postfixadmin_database_password {
    '': { fail("You need to define \$postfixadmin_database_password host config") }
  }

  case $postfixadmin_setup_hash {
    '': {
      warning("You need to define \$postfixadmin_setup_hash host config")
      $postfixadmin_setup_hash = 'changeme'
    }
  }
  case $postfixadmin_database_user {
    '': { $postfixadmin_database_user = "postfix" }
  }

  case $postfixadmin_database_host {
    '': { $postfixadmin_database_host = "localhost" }
  }

  case $postfixadmin_database_name {
    '': { $postfixadmin_database_name= "postfix" }
  }

  # Module requirements
  include postfix
  include database
  include ssl::mail

  # Subsystems
  include mail::packages
  include mail::sasl
  include mail::tls
  include mail::dovecot
  include mail::amavisd
  include mail::header_checks
  include mail::postfixadmin
  include mail::web

  # Postfix configuration
  postfix::config {
    "mydomain":             value => "$domain";
    "myhostname":           value => "$fqdn";
    "mydestination":        value => "$postfix_mydestination";
    "mynetworks":           value => "$postfix_mynetworks";
    "relay_domains":        value => "$domain";
    "transport_maps":       value => "hash:/etc/postfix/transport";
    "mailbox_command":      value => '/usr/bin/maildrop -d ${USER}';
    "virtual_mailbox_base": value => '/var/mail/virtual';
  }

  postfix::hash { "/etc/postfix/virtual":
    ensure => present,
  }

  postfix::hash { "/etc/postfix/transport":
    ensure => present,
  }

  # Recipient restrictions
  postfix::config { "smtpd_recipient_restrictions":
    value => 'permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, reject_rbl_client psbl.surriel.com, check_policy_service inet:127.0.0.1:60000' }

  # Virtual mailboxes
  file { '/var/mail/virtual':
    ensure => directory,
    owner  => root,
    group  => mail,
    mode   => 0770,
  }
}