Friday, August 3, 2012

How to Configure PHP-FPM and Apache 2.4 with mod_proxy_fcgi in Virtualmin (CentOS & Debian)

The Apache 2.4 series introduced mod_proxy_fcgi, enabling Apache to communicate directly with PHP-FPM via TCP/IP sockets without requiring older third-party modules like mod_fastcgi or mod_fcgid. This setup provides superior performance and memory isolation for multi-tenant web servers running Virtualmin.

Environment: Apache 2.4.x • PHP-FPM 5.x • Virtualmin • CentOS 6 / Debian 6

1. Installing PHP-FPM

Install the latest PHP-FPM packages using Remi (CentOS) or Dotdeb (Debian):

# On CentOS:
yum install php-fpm -y

# On Debian:
apt-get install php5-fpm -y

2. Compiling Apache 2.4 from Source (CentOS 6)

If your distribution does not ship Apache 2.4 in its default repositories, compile from source with event MPM and mod_proxy_fcgi:

yum install pcre-devel -y
cd /usr/src
wget https://archive.apache.org/dist/httpd/httpd-2.4.25.tar.bz2
wget https://archive.apache.org/dist/apr/apr-1.5.2.tar.bz2
wget https://archive.apache.org/dist/apr/apr-util-1.5.4.tar.bz2

tar -jxf httpd-2.4.25.tar.bz2
tar -jxf apr-1.5.2.tar.bz2
tar -jxf apr-util-1.5.4.tar.bz2

mv apr-1.5.2 httpd-2.4.25/srclib/apr
mv apr-util-1.5.4 httpd-2.4.25/srclib/apr-util

cd httpd-2.4.25
./configure --prefix=/opt/apache2 --with-mpm=event --enable-rewrite --enable-proxy --enable-proxy-fcgi --enable-ssl --with-included-apr
make && make install

3. Virtualmin Apache VirtualHost Integration

To route PHP requests from Virtualmin virtual hosts to their respective PHP-FPM pools via mod_proxy_fcgi, configure the VirtualHost directive:

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /home/example/public_html

    ProxyPassMatch ^/(.*\.php(/.*)?)$ fcgi://127.0.0.1:9000/home/example/public_html/$1

    <Directory /home/example/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

This allows each virtual server in Virtualmin to leverage isolated PHP-FPM user pools with event-driven concurrency.

19 comments:

  1. Thanks for the steps and confirming this works.

    Is there any reason why not to just overwrite the existing copy of apache so it can be managed directly by virtualmin/webmin?

    Since you use /opt/ I assume this was originally done in debian and then you converted the script to centos.

    ReplyDelete
    Replies
    1. The version of default apache package on debian and centos is 2.2 which doesn't support tcp/ip fcgi to work with php-fpm.
      2.4.x introduces new mod_proxy_fcgi so it can contact php-fpm pools directly.

      I've installed httpd 2.4.x in /opt folder ( no matter what os ) and integrated it to virtualmin in step #3 so you'll be able to manage it directly using both webmin/virtualmin.

      Delete
  2. Please note that using PHP-FPM with TCP/IP or a socket with too open permissions is a severe security fuck-up waiting to happen.

    ReplyDelete
    Replies
    1. You're right ...
      I've asked apache developers for socket connection fpm support :
      http://httpd.apache.org/docs/2.4/mod/mod_proxy_fcgi.html

      See comments ...

      Delete
  3. Great Tutorial,

    But there is a problem with /script/php-fpm it show an error when it come to the step of applying configuration to existing domains, it show:
    /script/php-fpm: 18: /script/php-fpm: [[: not found
    /script/php-fpm: 19: /script/php-fpm: [[: not found
    /script/php-fpm: 48: /script/php-fpm: [[: not found
    /script/php-fpm: 49: /script/php-fpm: [[: not found

    thanx for your help

    ReplyDelete
    Replies
    1. I think you need to ask the question on a linux forum, I've tested the script on centos and debian.
      '[[' is something like 'if statement' but I don't have any idea why it's not working for you !

      Delete
    2. I changed #/bin/sh to #/bin/bash and this is fixed.

      Delete
  4. Any chance of getting the php-fpm script somewhere? Can't download it anymore

    ReplyDelete
  5. I cannot get scripts to install in virtualmin following this guide: "This script cannot be installed, as this virtual server does not meet its requirements : Could not work out exact PHP version" I followed the part about script install.. any suggestions.. everything else seems fine but I really like to fix this part?

    ReplyDelete
  6. I see /opt/apache2/conf/httpd.conf for editing conf file first but then it is /opt/apache24/conf/httpd.conf. Is this a typo?
    I cannot find /opt/apache24/conf/httpd.conf

    ReplyDelete
  7. What directory should we mkdir /script? root? src? init.d?

    ReplyDelete
  8. Thanks a lot for guide. I think we should keep error log location same.

    ReplyDelete
  9. I am going to give this a go with Centos 7 so Apache 2.4 should already be there and good to go. I am thinking I can just skip step 3 and change the file path to httpd.conf where needed.

    ReplyDelete
  10. Hello, I am going to try this on Ubuntu 16.04 lts.

    I notice you don't turn off mpm-prefork/mod-php, and turn on mpm-worker (or mpm-event)? Why? You would significantly cut down on your Apache overhead...

    ReplyDelete
    Replies
    1. You are right, Ive now updated this post and replaced mpm_prefork with mpm_event.

      Delete

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...