Securing shared hosting environments and multi-tenant web servers requires preventing unauthorized symlink traversals and isolating application processes. Here are two powerful security features in Nginx and PHP-FPM that significantly harden your stack against cross-account directory traversal attacks.
Security Highlights: Prevent unauthorized symlink following in Nginx • Isolate execution pools in dedicated chroot jails with required pseudo-devices
1. Restricting Symlink Traversal in Nginx
By default, Nginx follows symbolic links without verifying ownership. The disable_symlinks directive allows you to strictly control link traversal:
# Allowed options: off | on | if_not_owner
disable_symlinks if_not_owner;
When set to if_not_owner, Nginx verifies that the symlink and the target file/directory belong to the same owner, effectively blocking unauthorized access to system files or other users' web roots.
2. PHP-FPM Chroot Jails
To provide true isolation, you can lock each PHP-FPM worker pool into its own chroot directory. A quick way to bootstrap a clean environment is by extracting a minimal OS template (such as an OpenVZ minimal template matching your host distribution) into the jail root.
Creating Essential Device Nodes in the Jail
For PHP and system libraries to function correctly (especially DNS resolution, random entropy, and error logging), create the necessary character devices inside the jail directory:
cd /path/to/jail
mkdir -p dev etc usr/share/zoneinfo
mknod -m 666 dev/null c 1 3
mknod -m 666 dev/zero c 1 5
mknod -m 666 dev/random c 1 8
mknod -m 666 dev/urandom c 1 9
Also copy /etc/resolv.conf and /etc/hosts into the jail's etc/ folder so PHP can perform external network queries and DNS resolution.