Single bookworm-slim image running opendkim + panel + postfix under supervisord with enforced start ordering (spec 4): - build/Dockerfile: multi-stage static Go build; runtime installs postfix, opendkim, cyrus-sasl, supervisor, logrotate; unprivileged panel user (7.6.8). - build/supervisord.conf: priority ordering opendkim -> panel -> postfix; crashexit event listener terminates the container on any FATAL process. - build/postfix-wrapper.sh: waits for both milter sockets (test -S, 30s timeout) before `postfix start-fg`, exits non-zero on timeout. - panel: HTTP :8080 stub + /healthz, journal-milter socket stub (so the wrapper's readiness probe passes), log-tailer stub; SIGTERM graceful stop. Verified on the dev server: image builds, three processes live, panel serves the stub, wrapper waits for sockets, and an unrecoverable panel failure brings the container down cleanly. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
SelfPost
Self-hosted outbound SMTP relay with a web control panel, shipped as a single
Docker image. Postfix + OpenDKIM + a small Go panel run together under
supervisord; the panel manages multiple sending domains, per-domain DKIM keys
and SASL-authenticated applications bound to their domain.
SelfPost sends mail straight to the internet from your own IP, with DKIM signing, and is configured once through the panel. It is outbound only — it does not receive mail, provide mailboxes, or offer webmail.
Status: under active development. See docs/specification.md for the full requirements and docs/implementation-plan.md for the phased build plan.
Requirements (site prerequisites)
SelfPost assumes the host already provides the conditions for sending from your own IP — an unblocked outbound port 25, a static IP, configurable PTR/rDNS and a reasonable IP reputation. Providing these is the operator's job, not a feature of SelfPost. Detailed deployment docs land in a later phase.
Repository
- Primary: https://codeberg.org/mix/selfpost
- Mirror: https://github.com/mixeme/selfpost
License
AGPL-3.0. The AGPL closes the "SaaS loophole": if you run a modified version as a network-accessible service, you must make the modified source available to its users — not only when you distribute copies of the code.