Showing posts with label CentOS. Show all posts
Showing posts with label CentOS. Show all posts

Monday, November 23, 2020

How to Install and Configure Munin Monitoring with Nginx and CGI on CentOS 8

Setting up Munin on CentOS 8 via EPEL 8 provides turnkey server performance graphs. This guide walks through configuring systemd timer units, fastcgi spawners for dynamic graph generation, and integrating the dashboard into an Nginx virtual host.

Packages: munin • munin-node • munin-cgi • spawn-fcgi

1. Installing Packages from EPEL 8

dnf install epel-release -y
dnf install munin munin-cgi munin-node spawn-fcgi nginx -y

2. Enabling Node and Systemd Services

systemctl enable --now munin-node
systemctl enable --now munin-cgi-graph.socket
systemctl enable --now munin-cgi-html.socket

3. Nginx Server Block (/etc/nginx/conf.d/munin.conf)

server {
    listen 80;
    server_name munin.example.com;

    location / {
        root /var/www/html/munin;
        index index.html;
    }

    location ^~ /munin-cgi/munin-cgi-graph/ {
        fastcgi_split_path_info ^(/munin-cgi/munin-cgi-graph)(.*);
        fastcgi_param PATH_INFO $fastcgi_path_info;
        fastcgi_pass unix:/run/munin/fcgi-graph.sock;
        include fastcgi_params;
    }
}

Tuesday, September 22, 2020

How to Deploy BigBlueButton Web Conferencing on CentOS 8 with Docker

BigBlueButton (BBB) is the leading open-source virtual classroom and web conferencing system. While upstream BBB exclusively provides automated installer scripts for Ubuntu LTS, organizations standardized on Enterprise Linux (CentOS 8 / RHEL 8) can deploy BigBlueButton components cleanly using Docker containers.

Stack: CentOS 8 • Docker CE • BigBlueButton Docker Compose • Nginx TLS Reverse Proxy

1. Installing Docker CE on CentOS 8

dnf config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo
dnf install docker-ce docker-ce-cli containerd.io -y
systemctl enable --now docker

2. Deploying BigBlueButton via Docker Compose

git clone https://github.com/bigbluebutton/docker.git bbb-docker
cd bbb-docker
cp .env.example .env

# Configure your FQDN and Let's Encrypt email in .env
./scripts/generate-api-secrets.sh
docker-compose up -d

Thursday, July 9, 2020

How to Install and Configure Icecast 2 Streaming Audio Server on CentOS 8

Icecast is a high-performance, open-source streaming media audio server capable of broadcasting MP3, Ogg Vorbis, and Opus audio streams. Because prebuilt Icecast packages were initially omitted from CentOS 8 and EPEL 8 repositories, compiling from source with Vorbis and Theora audio support is required.

Environment: CentOS 8 / RHEL 8 • Icecast 2.4.x • Ogg / Vorbis / Theora Codecs

1. Install Build Tools and Codec Dependencies

yum groupinstall "Development Tools" -y
yum install curl-devel libtheora-devel libvorbis-devel libxslt-devel speex-devel libshout-devel -y

2. Download and Build Icecast

cd /usr/src
wget http://downloads.xiph.org/releases/icecast/icecast-2.4.4.tar.gz
tar -zxf icecast-2.4.4.tar.gz
cd icecast-2.4.4

./configure --prefix=/usr --sysconfdir=/etc --localstatedir=/var
make && make install

3. Create Service User and Start Daemon

useradd -r -s /sbin/nologin icecast
chown -R icecast:icecast /var/log/icecast

# Launch Icecast as a background daemon
icecast -b -c /etc/icecast.xml

Wednesday, July 8, 2020

How to Rebuild Apache httpd to Change suexec AP_DOC_ROOT from /var/www to /home (CentOS & RHEL)

Standard RPM packages of Apache httpd in CentOS and RHEL compile suexec with a hardcoded document root of /var/www (--with-suexec-docroot=/var/www). However, web control panels like Virtualmin host customer accounts under /home. When suexec executes a user script under /home, it aborts with "command not in docroot". Here is how to rebuild the official upstream httpd SRPM with AP_DOC_ROOT set to /home.

Compilation Flag: --with-suexec-docroot=/home

Rebuilding the RPM

# 1. Install build tools and dependencies
yum install rpm-build redhat-rpm-config gcc make -y
yum-builddep httpd -y

# 2. Download and unpack httpd SRPM
mkdir -p ~/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
cd ~/rpmbuild/SRPMS
yumdownloader --source httpd
rpm -ivh httpd-*.src.rpm

# 3. Edit SPECS/httpd.spec and modify suexec docroot
cd ~/rpmbuild/SPECS
sed -i 's|--with-suexec-docroot=/var/www|--with-suexec-docroot=/home|g' httpd.spec

# 4. Rebuild binary RPM
rpmbuild -bb httpd.spec

# 5. Install the custom suexec binary
rpm -Uvh --force ~/rpmbuild/RPMS/x86_64/httpd-*.rpm

Confirm the new docroot:

suexec -V | grep AP_DOC_ROOT

Wednesday, June 3, 2020

How to Install Virtualmin with Multiple PHP and MySQL Versions on CentOS 8

Deploying a production web hosting stack on CentOS 8 with Virtualmin requires modern multi-PHP support (allowing legacy applications to run PHP 5.6 or 7.2 while modern apps run PHP 7.4 or 8.0) and reliable database server management via Remi repositories.

Stack: CentOS 8 • Virtualmin 6.x • Remi Software Collections (SCL) • MySQL 8.0 • Multi-PHP

1. Fix Perl UTF-8 Locale Warnings

cat << 'EOF' > /etc/environment
LANGUAGE=en_US.utf8
LC_ALL=en_US.utf-8
LANG=en_US.utf8
LC_TYPE=en_US.utf8
EOF

2. Enable EPEL and Remi Repositories

dnf install epel-release -y
dnf install https://rpms.remirepo.net/enterprise/remi-release-8.rpm -y
dnf module reset php -y
dnf module enable php:remi-7.4 -y

3. Installing Parallel PHP Versions

dnf install php56-php-fpm php72-php-fpm php74-php-fpm php80-php-fpm -y

4. Install Virtualmin

wget http://software.virtualmin.com/gpl/scripts/install.sh
sh install.sh

Sunday, March 1, 2020

How to Install XFCE Desktop and RealVNC Server on CentOS 7

XFCE is a lightweight, responsive desktop environment ideal for remote graphical management on headless CentOS 7 servers without consuming excessive RAM. However, launching an XFCE session inside RealVNC Server (vncserver-virtual) on CentOS 7 often fails or displays a blank screen because default Xsession startup scripts target GNOME.

Environment: CentOS 7 • XFCE Desktop • RealVNC Server

1. Installing XFCE and RealVNC

yum groupinstall "Xfce" -y
yum install tigervnc-server -y # Or install RealVNC Server RPM

2. Configuring the VNC Virtual Session (/etc/vnc/xstartup.custom)

To ensure RealVNC launches the XFCE desktop environment properly, create or edit /etc/vnc/xstartup.custom:

#!/bin/sh
[ -x /etc/vnc/xstartup ] && exec /etc/vnc/xstartup
[ -r $HOME/.Xresources ] && xrdb $HOME/.Xresources
startxfce4 &

Make the script executable and launch the VNC virtual display:

chmod +x /etc/vnc/xstartup.custom
vncserver-virtual :1

Thursday, January 17, 2019

How to Install and Configure the Xymon Monitoring Client on CentOS 7 and Debian 9

The Xymon infrastructure monitoring system (formerly Hobbit / Big Brother) provides lightweight, low-overhead system health tracking for servers. While Debian repositories package xymon-client directly via APT, Enterprise Linux distributions like CentOS 7 require building from source.

Supported Platforms: CentOS 7 (Source compilation) • Debian 9 (APT package)

1. Compiling on CentOS 7

# 1. Create dedicated system user
groupadd xymon
useradd -g xymon -m xymon

# 2. Install build dependencies
yum install gcc make fping pcre-devel openssl-devel openldap-devel rrdtool-devel libtirpc-devel -y

# 3. Download and compile client
cd /usr/src
wget https://sourceforge.net/projects/xymon/files/Xymon/4.3.30/xymon-4.3.30.tar.gz
tar -zxf xymon-4.3.30.tar.gz
cd xymon-4.3.30
./configure --client

make && make install

# 4. Install system service script
cp rpm/xymon-client.init /etc/init.d/xymon-client
cp rpm/xymon-client.default /etc/default/xymon-client
chmod +x /etc/init.d/xymon-client

# Configure server IP in /etc/default/xymon-client:
# XYMONSERVERS="YOUR.XYMON.SERVER.IP"

service xymon-client start
chkconfig xymon-client on

2. Installation on Debian 9 / Ubuntu

sudo apt-get update
sudo apt-get install xymon-client -y

Friday, March 17, 2017

How to Build a Dynamic PowerDNS Pipe Backend in Python

The PowerDNS Pipe Backend allows developers to attach custom external scripts (written in Python, Perl, Bash, or Go) to resolve DNS queries dynamically over standard I/O streams. This approach is ideal for dynamically serving CNAME aliases, geo-routing records, or integrating DNS responses with external APIs without rebuilding PowerDNS.

Environment: PowerDNS 3.x / 4.x • pdns-backend-pipe • Python IPC

1. Installing PowerDNS Pipe Backend (CentOS / RHEL)

yum install pdns pdns-backend-pipe -y

Configure /etc/pdns/pdns.conf to launch the pipe backend alongside standard zone providers:

launch=bind,pipe
pipe-command=/etc/pdns/pdns-backend.py

2. The Python Backend Script (/etc/pdns/pdns-backend.py)

The script communicates with PowerDNS via tab-delimited protocol over stdin/stdout. Note the -u flag on Python to ensure unbuffered I/O:

#!/usr/bin/python -u
from sys import stdin, stdout

# Handshake initialization
data = stdin.readline()
stdout.write("OK	My Dynamic Python Backend
")
stdout.flush()

TARGET_CNAME = 'cname-target.example.com'

while True:
    line = stdin.readline()
    if not line:
        break
    data = line.strip()
    kind, qname, qclass, qtype, qid, ip = data.split('	')
    
    if kind == 'Q' and qname not in TARGET_CNAME:
        # Provide SOA record for authoritative delegation
        soa_resp = f"DATA	{qname}	{qclass}	SOA	86400	-1	support.{qname} ns1.example.org 2026010100 1800 3600 604800 3600
"
        stdout.write(soa_resp)
        
        # Respond to ANY or CNAME queries
        if qtype in ('ANY', 'CNAME'):
            cname_resp = f"DATA	{qname}	{qclass}	CNAME	86400	{qid}	{TARGET_CNAME}
"
            stdout.write(cname_resp)
            
    stdout.write("END
")
    stdout.flush()

Make the script executable and restart PowerDNS:

chmod +x /etc/pdns/pdns-backend.py
systemctl restart pdns

Tuesday, November 22, 2016

How to Install Taiga Open Source Agile Project Manager & Kanban on CentOS 7

Taiga is a beautiful, open-source project management platform tailored for agile teams, Scrum sprints, and Kanban workflows. While official documentation primarily targeted Ubuntu, Taiga deploys smoothly on CentOS 7 with PostgreSQL, Python virtualenvs, and Nginx.

Architecture: taiga-back (Django / Python 3.5+) • taiga-front (AngularJS HTML5) • PostgreSQL 9.4+ • Nginx reverse proxy

1. Installing System Packages on CentOS 7

Install prerequisite development libraries and PostgreSQL:

yum install epel-release -y
yum install gcc gcc-c++ make automake git zlib-devel bzip2-devel openssl-devel   ncurses-devel sqlite-devel readline-devel tk-devel gdbm-devel db4-devel   libpcap-devel xz-devel libjpeg-turbo-devel libxml2-devel libxslt-devel   postgresql-server postgresql-devel redis nginx -y

2. PostgreSQL Setup

postgresql-setup initdb
systemctl start postgresql
systemctl enable postgresql

sudo -u postgres createuser -s taiga
sudo -u postgres createdb -O taiga taiga

3. Frontend & Backend Deployment

Deploy taiga-back inside an isolated Python virtual environment, execute database migrations via python manage.py migrate, unpack taiga-front-dist to /home/taiga/taiga-front-dist, and configure Nginx to proxy API endpoints to Gunicorn on port 8001.

Wednesday, October 26, 2016

How to Install a Private Git Server with CGIT Web Frontend on CentOS 7

Self-hosting a lightweight Git web interface like CGIT written in C provides near-instant page loads, minimal RAM footprint, and syntax-highlighted code browsing compared to heavyweight alternatives like GitLab.

Stack: CentOS 7 • CGIT • fcgiwrap • Nginx • highlight syntax engine

1. Installing Prerequisites and fcgiwrap

CGIT operates as a FastCGI binary. Install fcgiwrap to interface between Nginx and the CGIT binary:

yum install epel-release -y
yum install fcgi-devel highlight git autoconf automake libtool -y

cd /usr/src
git clone https://github.com/gnosek/fcgiwrap.git
cd fcgiwrap
autoreconf -i
./configure --prefix=/usr
make && make install

2. Compiling CGIT from Source

cd /usr/src
git clone https://git.zx2c4.com/cgit
cd cgit
git submodule init
git submodule update
make get-git
make && make install

3. Nginx FastCGI Integration

Configure Nginx to route CGIT requests to the fcgiwrap socket:

location / {
    fastcgi_pass unix:/var/run/fcgiwrap.sock;
    fastcgi_param SCRIPT_FILENAME /var/www/htdocs/cgit/cgit.cgi;
    fastcgi_param PATH_INFO $uri;
    fastcgi_param QUERY_STRING $args;
    fastcgi_param HTTP_HOST $server_name;
    include fastcgi_params;
}

Sunday, October 2, 2016

How to Build a Low-Latency HLS & RTMP Live Streaming Server on Linux (Nginx RTMP Module)

Setting up your own live video streaming infrastructure on a Linux VPS or dedicated server provides full control over bitrate, privacy, and latency without third-party platform restrictions. This complete guide walks through configuring an Nginx RTMP + HLS media server on CentOS 7, publishing from OBS Studio / FFmpeg, and embedding the stream in modern web browsers.

Architecture: Nginx with nginx-rtmp-module • HLS fragmenting (Apple HTTP Live Streaming) • Broadcaster: OBS / FFmpeg • Player: HTML5 HLS.js

Part 1: Compiling Nginx with RTMP Support (CentOS 7)

Install development packages and compile Nginx with the RTMP module:

yum install gcc-c++ pcre-devel zlib-devel openssl-devel git -y
cd /usr/src
git clone https://github.com/arut/nginx-rtmp-module.git
wget http://nginx.org/download/nginx-1.12.2.tar.gz
tar -zxf nginx-1.12.2.tar.gz
cd nginx-1.12.2

./configure --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx   --conf-path=/etc/nginx/nginx.conf --pid-path=/var/run/nginx.pid   --with-http_ssl_module --with-http_v2_module   --add-module=/usr/src/nginx-rtmp-module

make && make install

Part 2: Configuring RTMP and HLS Ingestion

Add the RTMP server block to /etc/nginx/nginx.conf:

rtmp {
    server {
        listen 1935;
        chunk_size 4096;

        application live {
            live on;
            hls on;
            hls_path /var/www/hls;
            hls_fragment 3;
            hls_playlist_length 60;
            # Restrict streaming publishing to your IP:
            allow publish 127.0.0.1;
            allow publish YOUR.OFFICE.IP;
            deny publish all;
        }
    }
}

Configure HTTP delivery for the HLS .m3u8 playlists and .ts video segments in /etc/nginx/conf.d/stream.conf:

server {
    listen 80;
    server_name stream.example.com;

    location /hls {
        types {
            application/vnd.apple.mpegurl m3u8;
            video/mp2t ts;
        }
        root /var/www;
        add_header Cache-Control no-cache;
        add_header Access-Control-Allow-Origin *;
    }
}

Part 3: Broadcasting and Playback

In OBS Studio, set the Stream URL to rtmp://YOUR-SERVER-IP/live and choose a Stream Key (e.g. mystream). In your web page, point your HLS video player to http://YOUR-SERVER-IP/hls/mystream.m3u8 for instant, cross-browser live playback.

Tuesday, July 19, 2016

How to Configure Docker with the Btrfs Storage Driver on CentOS 7

On CentOS 7, Docker initially defaulted to the devicemapper storage driver in loop-lvm mode, which suffered from high I/O latency, severe disk fragmentation, and occasional filesystem deadlocks. Configuring Docker to use the Btrfs storage driver provides native copy-on-write subvolumes, instant snapshots, and superior performance for virtualized hosts.

Prerequisites: Dedicated block device or partition formatted as Btrfs (e.g. /dev/sdb1).

1. Create and Mount the Btrfs Filesystem

# Format partition as Btrfs
mkfs.btrfs -f /dev/sdb1

# Mount at Docker root directory
mkdir -p /var/lib/docker
mount -t btrfs /dev/sdb1 /var/lib/docker

Add the mount to /etc/fstab for persistence across reboots:

/dev/sdb1  /var/lib/docker  btrfs  defaults,compress=lzo  0 0

2. Configure Docker Daemon

Specify the Btrfs driver in /etc/docker/daemon.json:

{
  "storage-driver": "btrfs"
}

Start Docker and verify the active storage engine:

systemctl start docker
docker info | grep "Storage Driver"

Wednesday, January 6, 2016

How to Install and Use zerofree on CentOS, RHEL, and Fedora to Compact VM Disks

When shrinking dynamic virtual machine disk images (such as VirtualBox VDI, VMware VMDK, or QEMU QCOW2), zeroing out unused filesystem blocks is essential for effective host compression. Because Enterprise Linux distributions (CentOS 6/7, RHEL) do not ship zerofree in their default package repositories, compiling from source is the quickest solution.

Environment: CentOS 6/7 • RHEL • Fedora • Ext3 / Ext4 Filesystems

1. Installing Build Headers and Compiling zerofree

Install the e2fsprogs development headers and compile:

yum install e2fsprogs-devel gcc make -y
cd /usr/src
wget http://frippery.org/uml/zerofree-1.0.3.tgz
tar -zxf zerofree-1.0.3.tgz
cd zerofree-1.0.3
make
cp zerofree /usr/bin/

2. Zeroing Out Unallocated Blocks

Important: Always remount the target filesystem in read-only mode prior to executing zerofree to prevent filesystem corruption:

# Remount filesystem as read-only:
mount -o remount,ro /

# Run zerofree on the target block partition:
zerofree -v /dev/sda1

Once complete, shut down the VM and run your hypervisor's disk compacting command (e.g. VBoxManage modifymedium --compact disk.vdi) on the host machine.

Tuesday, April 16, 2013

How to Compile the Latest FFmpeg with x264 and libvpx on CentOS 6

Compiling FFmpeg with high-performance H.264 (libx264) and VP8/VP9 (libvpx) encoding support on CentOS 6 often encounters dependency version collisions and compilation errors if older library packages remain installed on the host.

Environment: CentOS 6.x • FFmpeg • x264 • libvpx • faac

1. Removing Conflicting RPM Packages

Before compiling from source, remove older distribution codec libraries to prevent undefined reference linker errors like libx264.c: undefined reference to 'x264_encoder_open_130':

yum remove libvpx libogg libvorbis libtheora libx264 x264 x264-devel x264-libs ffmpeg -y

2. Patching and Compiling faac 1.28

If building the faac AAC encoder, a syntax error occurs in mpeg4ip.h: error: new declaration 'char* strcasestr(const char*, const char*)'. Remove line 126 from ./common/mp4v2/mpeg4ip.h before building:

sed -i '/strcasestr/d' common/mp4v2/mpeg4ip.h
./configure && make && make install

3. Compiling x264 and libvpx

# Build x264
cd x264
./configure --enable-static --enable-shared
make && make install

# Build libvpx
git clone https://chromium.googlesource.com/webm/libvpx
cd libvpx
./configure
make && make install
ldconfig

Once libraries are installed into /usr/local, configure FFmpeg with --enable-gpl --enable-libx264 --enable-libvpx for a fully modern encoding stack.

Friday, December 14, 2012

How to Install Wine with MS Visual C++ and Visual Basic Runtimes on Linux

Running specialized Windows desktop utilities (such as download managers like Orbit Downloader, HiDownload, or Net Transport) on Linux often requires essential Microsoft Visual C++ and Visual Basic runtime libraries that are not packaged by default in vanilla Wine.

Prerequisites: Wine installed via EPEL (CentOS / RHEL) or standard distribution repositories (Ubuntu / Debian).

Step-by-Step Installation

1. Install Cabextract

The cabextract utility is required by Winetricks to unpack Microsoft cabinet files:

# On Debian / Ubuntu:
sudo apt-get install cabextract -y

# On CentOS / RHEL (requires EPEL):
sudo yum install cabextract -y

2. Download and Run Winetricks

Fetch the official winetricks script and install the required core fonts, Visual C++ 6.0, and Visual Basic 6.0 runtimes:

wget https://raw.githubusercontent.com/Winetricks/winetricks/master/src/winetricks
chmod +x winetricks

sh winetricks corefonts vcrun6 vb6run

Once the runtime components are installed into your ~/.wine prefix, your Windows applications will initialize without missing DLL or runtime errors.

Thursday, September 6, 2012

How to Compile and Configure XCache 2.x on CentOS 6 for PHP Optimization

While Memcached is widely recommended for web caching, opcode caches like XCache often deliver significantly better speed improvements and lower load averages for PHP-driven CMS platforms like Joomla on high-traffic servers.

Environment: CentOS 6.x • PHP 5.x • XCache 2.0.1

1. Compile XCache from Source

Install the PHP development headers and compile the XCache module with the optimizer enabled:

yum install php-devel -y
cd /usr/src
wget http://xcache.lighttpd.net/pub/Releases/2.0.1/xcache-2.0.1.tar.gz
tar -zxf xcache-2.0.1.tar.gz
cd xcache-2.0.1
phpize --clean && phpize
./configure --enable-xcache --enable-xcache-optimizer
chown -R nobody /usr/src/xcache-2.0.1
sudo -u nobody make
make install

2. Configure /etc/php.d/xcache.ini

Create the XCache configuration file. Adjust the zend_extension path depending on whether your architecture is 64-bit (/usr/lib64/php/modules/xcache.so) or 32-bit (/usr/lib/php/modules/xcache.so):

cat << 'EOF' > /etc/php.d/xcache.ini
[xcache-common]
zend_extension=/usr/lib64/php/modules/xcache.so

[xcache.admin]
xcache.admin.enable_auth = Off

[xcache]
xcache.shm_scheme        = "mmap"
xcache.size              = 64M
xcache.count             = 1
xcache.slots             = 8K
xcache.ttl               = 0
xcache.gc_interval       = 0
xcache.var_size          = 32M
xcache.var_count         = 1
xcache.var_slots         = 8K
xcache.var_ttl           = 0
xcache.var_maxttl        = 0
xcache.var_gc_interval   = 300
xcache.readonly_protection = Off
xcache.mmap_path         = "/dev/zero"
xcache.coredump_directory = ""
xcache.experimental      = Off
xcache.cacher            = On
xcache.stat              = On
xcache.optimizer         = On

[xcache.coverager]
xcache.coverager         = Off
xcache.coveragedump_directory = ""
EOF

3. Enable the Web Administration Panel

Copy the administrative GUI into your web root to monitor memory usage and cache hit rates:

cp -R admin /var/www/html/xcache-admin
service httpd restart

You can access the admin dashboard at http://your-server-ip/xcache-admin/index.php to monitor real-time hit ratios.

Tuesday, September 4, 2012

How to Losslessly Optimize JPG, PNG, and GIF Images on Linux Using littleutils

Reducing image file sizes without sacrificing visual quality is one of the highest-impact optimizations for production websites. The littleutils package provides a collection of fast, lightweight command-line utilities—including opt-png, opt-jpg, and opt-gif—that losslessly compress images for faster web delivery.

Supported Utilities: opt-png (via pngcrush) • opt-jpg • opt-gif (via gifsicle)

1. Installing Required Prerequisites (CentOS / RHEL)

Install the necessary build tools and image compression libraries:

yum groupinstall "Development Tools" -y
yum install libpng-devel libjpeg-turbo-devel gifsicle -y

Compiling pngcrush:

cd /usr/src
wget https://sourceforge.net/projects/pmt/files/pngcrush/1.8.10/pngcrush-1.8.10.tar.gz
tar -zxf pngcrush-1.8.10.tar.gz
cd pngcrush-1.8.10
make
cp pngcrush /usr/local/bin/

2. Compiling littleutils

Download and build the littleutils suite:

cd /usr/src
wget http://downloads.sourceforge.net/project/littleutils/littleutils-source/1.0.27/littleutils-1.0.27.tar.bz2
tar -jxf littleutils-1.0.27.tar.bz2
cd littleutils-1.0.27
./configure --prefix=/usr/local
make
make install
make install-extra

3. Usage Examples

Optimize individual files or batch-compress entire image directories in place:

# Optimize a single PNG image losslessly
opt-png image.png

# Optimize a single JPEG image
opt-jpg photo.jpg

# Optimize all images in a directory
find /var/www/html/images/ -type f -name "*.png" -exec opt-png {} +
find /var/www/html/images/ -type f -name "*.jpg" -exec opt-jpg {} +

Friday, August 3, 2012

How to Configure PHP-FPM and Apache 2.4 with mod_proxy_fcgi in Virtualmin (CentOS & Debian)

The Apache 2.4 series introduced mod_proxy_fcgi, enabling Apache to communicate directly with PHP-FPM via TCP/IP sockets without requiring older third-party modules like mod_fastcgi or mod_fcgid. This setup provides superior performance and memory isolation for multi-tenant web servers running Virtualmin.

Environment: Apache 2.4.x • PHP-FPM 5.x • Virtualmin • CentOS 6 / Debian 6

1. Installing PHP-FPM

Install the latest PHP-FPM packages using Remi (CentOS) or Dotdeb (Debian):

# On CentOS:
yum install php-fpm -y

# On Debian:
apt-get install php5-fpm -y

2. Compiling Apache 2.4 from Source (CentOS 6)

If your distribution does not ship Apache 2.4 in its default repositories, compile from source with event MPM and mod_proxy_fcgi:

yum install pcre-devel -y
cd /usr/src
wget https://archive.apache.org/dist/httpd/httpd-2.4.25.tar.bz2
wget https://archive.apache.org/dist/apr/apr-1.5.2.tar.bz2
wget https://archive.apache.org/dist/apr/apr-util-1.5.4.tar.bz2

tar -jxf httpd-2.4.25.tar.bz2
tar -jxf apr-1.5.2.tar.bz2
tar -jxf apr-util-1.5.4.tar.bz2

mv apr-1.5.2 httpd-2.4.25/srclib/apr
mv apr-util-1.5.4 httpd-2.4.25/srclib/apr-util

cd httpd-2.4.25
./configure --prefix=/opt/apache2 --with-mpm=event --enable-rewrite --enable-proxy --enable-proxy-fcgi --enable-ssl --with-included-apr
make && make install

3. Virtualmin Apache VirtualHost Integration

To route PHP requests from Virtualmin virtual hosts to their respective PHP-FPM pools via mod_proxy_fcgi, configure the VirtualHost directive:

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /home/example/public_html

    ProxyPassMatch ^/(.*\.php(/.*)?)$ fcgi://127.0.0.1:9000/home/example/public_html/$1

    <Directory /home/example/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

This allows each virtual server in Virtualmin to leverage isolated PHP-FPM user pools with event-driven concurrency.

Tuesday, July 31, 2012

How to Install and Configure Munin 2.0 with Nginx and FastCGI on CentOS 6

Munin 2.0 introduced dynamic CGI graph and HTML generation, allowing monitoring dashboards to scale efficiently without requiring static graph regeneration during every 5-minute cron cycle. Here is how to compile Munin 2.0 from source and integrate it with Nginx using spawn-fcgi on CentOS 6.

Stack: Munin 2.0.x • Nginx • FastCGI (spawn-fcgi) • CentOS 6 / RHEL 6

1. Installing Build Dependencies

Install Perl module prerequisites and development tools:

yum groupinstall 'Development Tools' -y
yum install perl-CGI perl-FCGI perl-File-Copy-Recursive perl-Module-Build perl-Cache-Cache git spawn-fcgi -y
groupadd munin
useradd munin -g munin -s /sbin/nologin -d /var/www/html/munin

2. Compiling Munin 2.0 from Source

cd /usr/src
git clone git://github.com/munin-monitoring/munin.git
cd munin
git checkout tags/2.0.0
make
make install

3. Spawning FastCGI Processes for Graph and HTML Generation

Munin 2.0 relies on two FastCGI workers: one for HTML page rendering and one for real-time RRD graph generation.

spawn-fcgi -s /var/run/munin/fcgi-graph.sock -u munin -g munin -- /var/www/html/munin/cgi/munin-cgi-graph
spawn-fcgi -s /var/run/munin/fcgi-html.sock -u munin -g munin -- /var/www/html/munin/cgi/munin-cgi-html

4. Nginx Server Configuration

Configure Nginx to proxy requests to the Munin FastCGI sockets:

location ^~ /cgi-bin/munin-cgi-graph/ {
    access_log off;
    fastcgi_split_path_info ^(/cgi-bin/munin-cgi-graph)(.*);
    fastcgi_param PATH_INFO $fastcgi_path_info;
    fastcgi_pass unix:/var/run/munin/fcgi-graph.sock;
    include fastcgi_params;
}

location /munin/static/ {
    alias /etc/munin/static/;
}

location /munin/ {
    fastcgi_split_path_info ^(/munin)(.*);
    fastcgi_param PATH_INFO $fastcgi_path_info;
    fastcgi_pass unix:/var/run/munin/fcgi-html.sock;
    include fastcgi_params;
}

5. Testing

Execute the Munin cron job under the munin system user to build the initial state:

sudo -u munin munin-cron

Sunday, July 8, 2012

Setting Up an IKEv2 VPN with StrongSwan Between a NATed Linux Client and Server

Configuring a secure, roadwarrior-style IKEv2 IPsec VPN using StrongSwan allows a client behind a residential NAT router (such as a standard home DSL/Cable modem) to establish an encrypted tunnel to a remote dedicated server.

Topology: Client: Ubuntu (behind NAT) • Server: CentOS with StrongSwan 4.6.x (Public IP) • Protocol: IKEv2 with X.509 certificates

1. Server Configuration (/etc/ipsec.conf)

Define the IKEv2 connection on the server. The server listens on its public IP, provisions virtual IPs to clients from 10.10.3.0/24, and routes default internet traffic:

conn win7
    left=SERVER.IP.ADD.RESS
    leftcert=server.cert
    leftid=@server.domain.com
    leftsubnet=0.0.0.0/0
    right=%any
    rightsourceip=10.10.3.0/24
    keyexchange=ikev2
    auto=add
    leftfirewall=yes

2. Client Configuration (/etc/ipsec.conf)

On the client machine behind NAT, set left=%defaultroute and request an IP dynamically from the server via leftsourceip=%config:

conn ike
    left=%defaultroute
    leftsourceip=%config
    leftcert=client.cert
    leftid=@client.domain.com
    leftfirewall=yes
    right=SERVER.IP.ADD.RESS
    rightsubnet=0.0.0.0/0
    rightid=@server.domain.com
    auto=add

3. Initiating the Connection

Start the IPsec tunnel from the client:

ipsec up ike

Check the status to verify security associations (SAs):

ipsec statusall

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...