Operations
Docker deployment
Run OwnSMTP on a single host with a hardened Compose baseline.
Compose baseline
yaml
services:
smtp-relay:
image: ghcr.io/samirkoirala/ownsmtp:${SMTP_RELAY_VERSION:-1.1.2}
restart: unless-stopped
env_file:
- .env
ports:
- "${PRIVATE_BIND_IP:-127.0.0.1}:8000:8000"
read_only: true
tmpfs:
- /tmp:size=16m,mode=1777
cap_drop:
- ALL
security_opt:
- no-new-privileges:trueThis publishes OwnSMTP on loopback by default, mounts no writable filesystem, and removes Linux capabilities. Put a TLS-terminating reverse proxy in front if the API must cross an untrusted network.
Lifecycle commands
Start and stop
bash
docker compose up -d
docker compose downView logs
bash
docker compose logs -f smtp-relayCheck health
bash
docker compose ps
curl --fail http://127.0.0.1:8000/healthz
curl --fail http://127.0.0.1:8000/readyzUpgrade
Set SMTP_RELAY_VERSION to the new pinned release, pull it, and recreate the service.
bash
docker compose pull smtp-relay
docker compose up -d smtp-relay
docker compose psRollback
Restore the previous version in SMTP_RELAY_VERSION, then pull and recreate again:
bash
SMTP_RELAY_VERSION=1.1.2 docker compose pull smtp-relay
SMTP_RELAY_VERSION=1.1.2 docker compose up -d smtp-relayUse a version you have already tested; the example above simply returns to 1.1.2.