Running Drupal on Debian 8 with Apache 2.4, event MPM and PHP-FPM (via socks and proxy)
apachephpplanetdrupalserverdrupalperformancedebianDevelopment
I’m building a new Ansible playbook for setting up web servers with Debian 8. I have always used mod_php before and it has been very stable but have some well known drawbacks. Since Debian 8 comes with Apache 2.4 and PHP 5.6 I wanted to implement PHP-FPM that seems very promising.
With mod_php every Apache process will need to load PHP and therefor use a lot more RAM than needed, even for just serving static content like images and css. I have been running Lighttpd as a static file server to mitigate this problem.
With event MPM + PHP-FPM a plain Apache processes will deal with all static content and hand of PHP request to separate PHP-FPM processes. This will allow a server to handle more visitors with the same amount of RAM and I can skip Lighttpd.
I found surprisingly little information on how to get this working well for serving things like Drupal. So here are what I have found out from manuals, post on the Internet as well as my own testing.
This setup has not been tested in production yet! When it has I will try to remember to update this article. In local testing on a VirtualBox image with Debian 8 and 512 MB RAM it seems to work fine. I also run the same setup locally on OS X with good results.
Here are some performance test done with ab. These doesn’t say much more than that it seems to work and most likely can handle some load.
ab -k -l -n 1000 -c 10 -H "Accept-Encoding: gzip,deflate" http://xdeb.dev/<br><br>Requests per second: 526.01 [#/sec] (mean)
This was the front page of a local version of xdeb.org running Drupal 7, with page cache of course. I also tested with plain Drupal 8 and got around 300 request/sec, more or less what one would expect.
A plain html page looks like this.
ab -k -l -n 1000 -c 10 -H "Accept-Encoding: gzip,deflate" http://localhost/<br><br>Requests per second: 2466.39 [#/sec] (mean)
Installation
Start by installing needed packages.
apt-get install apache2 apache2-dev php5-fpm mariadb-server
You most likely want some more php extensions as well, here are the ones I normally install for running Drupal.
apt-get install php5-cli php5-apcu php5-curl php5-dev php5-gd php5-imagick php5-json php5-mysql php5-mcrypt php5-twig php-pear graphicsmagick graphicsmagick-imagemagick-compat
As suggested in http://wiki.apache.org/httpd/PHP-FPM I will run PHP-FPM via mod_proxy_fcgi so lets activate that module.
a2enmod proxy_fcgi
This will automatically activate the proxy module as well since it is a dependency. I also activate auth_digest, expires, rewrite and ssl on my servers. Rewrite is needed for Drupal to get clean URLs.
Apache and PHP-FPM configurations
Debian by default set up PHP-FPM to listen on a unix socket and since that should perform a bit better than a TCP socket I will use that. The most important setting is “max_children”. With Drupal each PHP process will use something like 20-40 MB typically, can be a lot more for some site so you simply need to test and see.
If your Drupal site use 30 MB per process setting “max_children” to 10 means that PHP will use up to about 10 * 30 MB = 300 MB of RAM. A good resource for figuring out what is the best settings is this blog post Adjusting child processes for PHP-FPM (Nginx) · MYSHELL.CO.UK
listen = /var/run/php5-fpm.sock<br>pm = dynamic<br>pm.max_children = 10<br>pm.start_servers = 4<br>pm.min_spare_servers = 2<br>pm.max_spare_servers = 6<br>pm.max_requests = 2000
The default MPM for Apache 2.4 (at least on Debian) is event MPM and since that is the most modern and best performing MPM there is no reason not to use it. I run with default setting and that should work well for most small servers. If needed I may up the value on ThreadsPerChild but I don’t think that will be needed on my servers.
# event MPM<br># ServerLimit: upper limit on configurable number of processes (default = 16)<br># StartServers: initial number of server processes to start (default = 3)<br># MinSpareThreads: minimum number of worker threads which are kept spare (default = 25)<br># MaxSpareThreads: maximum number of worker threads which are kept spare (default = 75)<br># ThreadLimit: upper limit on the configurable number of threads per child process (default = 64)<br># ThreadsPerChild: constant number of worker threads in each server process (default = 25)<br># MaxRequestWorkers: maximum number of worker threads (default = ServerLimit x ThreadsPerChild)<br># MaxConnectionsPerChild: maximum number of requests a server process serves (default = 0)<br><IfModule mpm_event_module><br> ServerLimit 16<br> StartServers 3<br> MinSpareThreads 25<br> MaxSpareThreads 75<br> ThreadLimit 64<br> ThreadsPerChild 25<br> MaxConnectionsPerChild 2000<br></IfModule>
Apache vhost setup
Here we then come to the part that caused me the biggest problem. How to get PHP-FPM to only run the php files I wanted and not everything. The Apache wiki page above suggest using ProxyPassMatch but it turns out that that overrides any restrictions set in e.g. a Files/FilesMatch directive. For Drupal I want to block access to files like update.php and cron.php so another solution was needed.
I found the solution in a post from Mattias Geniar Apache 2.4: ProxyPass (For PHP) Taking Precedence Over Files/FilesMatch In Htaccess. His suggestion to use a SetHandle in a FileMatch directive seems to work very well.
This is how I set up a vhost for serving Drupal.
<VirtualHost *:80><br> DocumentRoot /var/www/customers/example/web<br> ServerName example.com<br> ServerAlias www.example.com<br> ErrorLog /var/www/customers/example/logs/error_log<br> CustomLog /var/www/customers/example/logs/access_log combined<br> <Directory "/var/www/customers/example/web"><br> Options FollowSymLinks<br> AllowOverride None<br> Include /var/www/customers/example/web/.htaccess<br> <IfModule mod_proxy_fcgi.c><br> # Run php-fpm via proxy_fcgi<br> <FilesMatch \.php$><br> SetHandler "proxy:unix:/var/run/php5-fpm.sock|fcgi://localhost"<br> </FilesMatch><br> </IfModule><br> # Only allow access to cron.php etc. from localhost<br> <FilesMatch "^(cron|install|update|xmlrpc)\.php"><br> Require local<br> </FilesMatch><br> </Directory><br></VirtualHost>
Notice that I include the .htaccess file. I have set “AllowOverride None” to prevent Apache from looking for and automatically include any .htaccess files it finds. This improves performance a bit but one needs to remember to reload Apache when changes are made to the .htaccess file.
Extra security configurations in Apache for Drupal
Drupal put .htaccess in the files folder and some other places for security reasons. The following is an example how to add the same security configurations directly in an Apache conf file. The DirectoryMatch regex most likely needs adjustment for your directory structure.
# Security setting for files folder in Drupal.<br><DirectoryMatch "^/var/www/.*/web/(.+/)?(files|tmp)"><br> # Turn off all options we don't need.<br> Options -Indexes -ExecCGI -Includes -MultiViews<br><br> # Set the catch-all handler to prevent scripts from being executed.<br> SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006<br> <Files *><br> # Override the handler again if we're run later in the evaluation list.<br> SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003<br> </Files><br><br> # If we know how to do it safely, disable the PHP engine entirely.<br> <IfModule mod_php5.c><br> php_flag engine off<br> </IfModule><br></DirectoryMatch><br><br># Security setting for config folder in Drupal.<br><DirectoryMatch "^/var/www/.*/web/(.+/)?(private|config|sync|translations|twig)"><br> <IfModule mod_authz_core.c><br> Require all denied<br> </IfModule><br><br> # Deny all requests from Apache 2.0-2.2.<br> <IfModule !mod_authz_core.c><br> Deny from all<br> </IfModule><br> # Turn off all options we don't need.<br> Options -Indexes -ExecCGI -Includes -MultiViews<br><br> # Set the catch-all handler to prevent scripts from being executed.<br> SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006<br> <Files *><br> # Override the handler again if we're run later in the evaluation list.<br> SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003<br> </Files><br><br> # If we know how to do it safely, disable the PHP engine entirely.<br> <IfModule mod_php5.c><br> php_flag engine off<br> </IfModule><br></DirectoryMatch>