Skip to content

1. The mail server

inbuxa-server is the whole mail system in one program: JMAP, IMAP, POP3, SMTP, CalDAV, CardDAV and WebDAV, the store, the filters and the administration API. Install it first — the console and the webmail both need it running.

This page ends with a server in bootstrap mode, waiting for the console to complete its first boot.

Before you start

  • A Linux machine with Docker, or a Rust toolchain if you would rather build it.
  • A hostname for the server, pointed at that machine. It does not have to resolve yet, but certificates cannot be issued until it does.
  • Somewhere to keep two directories: one for configuration, one for data.
mail.example.com.  A  198.51.100.10

Install

The image is public and built for linux/amd64 and linux/arm64:

docker pull registry.coffeylabs.org/inbuxa/inbuxa-server:2026.9.29

It runs as an unprivileged user and keeps configuration in /etc/inbuxa and data in /var/lib/inbuxa, both of which should be volumes:

docker run -d --name inbuxa-server \
  -v inbuxa-config:/etc/inbuxa \
  -v inbuxa-data:/var/lib/inbuxa \
  -p 25:25 -p 465:465 -p 587:587 -p 993:993 -p 443:443 \
  -p 127.0.0.1:8080:8080 \
  registry.coffeylabs.org/inbuxa/inbuxa-server:2026.9.29

Port 8080 is the setup port, and it is bound to loopback here on purpose: reach it over an SSH tunnel rather than exposing it. Add -p 995:995 and -p 4190:4190 if you want POP3 and ManageSieve.

git clone https://git.coffeylabs.org/inbuxa/inbuxa-server.git
cd inbuxa-server
cargo build --release -p inbuxa

The binary lands at target/release/inbuxa. It takes the path its configuration will live at, and creates nothing until it is set up:

./target/release/inbuxa --config /etc/inbuxa/config.json

Or build the same image the release publishes:

docker build -t inbuxa .

The server always needs --config <PATH> (or CONFIG_PATH in the environment). The image supplies it already. What decides the mode is whether a file exists at that path, not whether you passed the option.

What bootstrap mode is

With no configuration file at that path, the server starts in bootstrap mode: it opens port 8080 and nothing else, and prints a temporary administrator to its log, once.

════════════════════════════════════════════════════════════
🔑 INBUXA bootstrap mode - temporary administrator account

   username: admin
   password  <shown once, here>

This password is shown only once. To pin a credential
instead, set INBUXA_RECOVERY_ADMIN=admin:<password> in the
env file.
════════════════════════════════════════════════════════════

Copy that password before you do anything else. If you lose it, stop the server, set INBUXA_RECOVERY_ADMIN=admin:<password> in its environment and start it again.

No mail ports are open yet, and there is no web interface on this host at any point: the console is what completes setup, over JMAP.

Check it worked

docker logs inbuxa-server 2>&1 | grep -i "bootstrap mode"
curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8080/healthz/live

You want the bootstrap line, and 200 from the health check:

Server started in bootstrap mode ... details = "No configuration file was
found. Port 8080 is open for initial setup." version = "2026.9.29 (upstream 0.16.24)"

A DNSSEC warning in the log at this point is normal on a machine whose resolver cannot validate: DANE is disabled rather than deferring mail. Fix the resolver before you carry real mail.

If instead the server printed its --help and exited, it was given no configuration path at all.

Next

Install the console, point it at this server, and complete first boot. Until that is done the server carries no mail.

Undoing it

Nothing has been written outside the two volumes, so removing them is a clean slate:

docker rm -f inbuxa-server
docker volume rm inbuxa-config inbuxa-data

Once the server is set up, those volumes are your installation: back them up before an upgrade, and keep them if you ever rebuild the container.