Skip to main content
Version: 0.5.5

Mailcow on Aruba Cloud

Deploy Mailcow — a complete dockerized email server suite — on Aruba Cloud using Terraform and cloud-init. Mailcow bundles Postfix, Dovecot, Rspamd, ClamAV, SOGo, and a web admin panel in a single Docker Compose stack.

Provider version: arubacloud/arubacloud ~> 0.5 | Terraform: ≥ 1.9


Introduction​

Mailcow is the most widely-deployed self-hosted email solution with a polished web UI (SOGo), built-in anti-spam (Rspamd), anti-virus (ClamAV), and automatic TLS via Let's Encrypt. This example deploys:

  • Mailcow dockerized via the official install script on a single VM
  • All required ports open: SMTP (25), SMTPS (465), submission (587), IMAPS (993), POP3S (995), Sieve (4190), HTTP (80), HTTPS (443)
  • TLS certificates auto-provisioned by Let's Encrypt (DNS must resolve before apply)

DNS first: Mailcow's Let's Encrypt integration runs at container start. Set your A record for mail_hostname → VM public IP before running terraform apply.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectmail-prodProject container
arubacloud_vpcmail-prod-vpcVirtual Private Cloud
arubacloud_subnetmail-prod-subnetBasic subnet
arubacloud_securitygroupmail-prod-vm-sgSecurity group
arubacloud_securityrulemail-prod-vm-sshSSH ingress (22)
arubacloud_securityrulemail-prod-vm-smtpSMTP ingress (25)
arubacloud_securityrulemail-prod-vm-httpHTTP ingress (80)
arubacloud_securityrulemail-prod-vm-httpsHTTPS ingress (443)
arubacloud_securityrulemail-prod-vm-smtpsSMTPS ingress (465)
arubacloud_securityrulemail-prod-vm-subSubmission ingress (587)
arubacloud_securityrulemail-prod-vm-imapsIMAPS ingress (993)
arubacloud_securityrulemail-prod-vm-pop3sPOP3S ingress (995)
arubacloud_securityrulemail-prod-vm-sieveSieve ingress (4190)
arubacloud_elasticipmail-prod-vm-eipVM public IP
arubacloud_blockstoragemail-prod-boot80 GB boot disk (Performance)
arubacloud_keypairmail-prod-keypairSSH public key
arubacloud_cloudservermail-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO4A8 — 4 vCPU / 8 GB~€40
Boot disk80 GB Performance~€12
Elastic IP—~€3
Total~€55/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 0.5
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair
  • A domain name with DNS control (required for TLS)

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
mail_hostnamePrimary mail FQDN (e.g. mail.example.com)

Optional​

VariableDefaultDescription
app_name"mail"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO4A8"CloudServer flavor
vm_disk_size_gb80Boot disk size in GB (min 40)
ssh_cidr"0.0.0.0/0"CIDR for SSH access
mailcow_branch"master"Mailcow Git branch

Outputs​

OutputDescription
mailcow_urlMailcow web UI URL (HTTPS)
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM

Deployment Instructions​

1. Set up DNS first​

Point your mail hostname A record at the Elastic IP address. Since the IP is only known after apply, you have two options:

  • Pre-create the Elastic IP resource separately and get its IP, or
  • Deploy with DNS disabled temporarily, then update DNS and run terraform apply again.

2. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/mailcow

3. Configure variables​

cp terraform.tfvars.example terraform.tfvars

4. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 5–10 minutes.

5. First login​

Navigate to https://mail.example.com and log in with:

  • Username: admin
  • Password: moohoo

Change the admin password immediately after first login.


Post-deploy Checklist​

  • Change admin password
  • Configure your domain's MX, SPF, DKIM, and DMARC records
  • Verify PTR (reverse DNS) record matches mail_hostname
  • Test mail delivery with mail-tester.com

References​