Skip to content
OwnSMTP

Operations

Docker deployment

Run OwnSMTP on a single host with a hardened Compose baseline.

Compose baseline

yaml
services:
  smtp-relay:
    image: ghcr.io/samirkoirala/ownsmtp:${SMTP_RELAY_VERSION:-1.1.2}
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${PRIVATE_BIND_IP:-127.0.0.1}:8000:8000"
    read_only: true
    tmpfs:
      - /tmp:size=16m,mode=1777
    cap_drop:
      - ALL
    security_opt:
      - no-new-privileges:true

This publishes OwnSMTP on loopback by default, mounts no writable filesystem, and removes Linux capabilities. Put a TLS-terminating reverse proxy in front if the API must cross an untrusted network.

Lifecycle commands

Start and stop

bash
docker compose up -d
docker compose down

View logs

bash
docker compose logs -f smtp-relay

Check health

bash
docker compose ps
curl --fail http://127.0.0.1:8000/healthz
curl --fail http://127.0.0.1:8000/readyz

Upgrade

Set SMTP_RELAY_VERSION to the new pinned release, pull it, and recreate the service.

bash
docker compose pull smtp-relay
docker compose up -d smtp-relay
docker compose ps

Rollback

Restore the previous version in SMTP_RELAY_VERSION, then pull and recreate again:

bash
SMTP_RELAY_VERSION=1.1.2 docker compose pull smtp-relay
SMTP_RELAY_VERSION=1.1.2 docker compose up -d smtp-relay

Use a version you have already tested; the example above simply returns to 1.1.2.