1
0
Fork 0

add php config and glue caddy to ttrss

This commit is contained in:
ibizaman 2022-09-14 20:46:14 -07:00
parent 66c20993a9
commit dccf16115b
8 changed files with 184 additions and 17 deletions

View file

@ -20,6 +20,8 @@ let
CaddySiteConfig = callPackage ./caddy/siteconfig.nix {inherit utils;}; CaddySiteConfig = callPackage ./caddy/siteconfig.nix {inherit utils;};
mkCaddySiteConfig = callPackage ./caddy/mksiteconfig.nix {inherit CaddySiteConfig;}; mkCaddySiteConfig = callPackage ./caddy/mksiteconfig.nix {inherit CaddySiteConfig;};
PHPConfig = callPackage ./php/config.nix {inherit utils;};
PHPFPMConfig = callPackage ./php-fpm/config.nix {inherit utils;}; PHPFPMConfig = callPackage ./php-fpm/config.nix {inherit utils;};
PHPFPMService = callPackage ./php-fpm/unit.nix {inherit utils;}; PHPFPMService = callPackage ./php-fpm/unit.nix {inherit utils;};
PHPFPMSiteConfig = callPackage ./php-fpm/siteconfig.nix {inherit utils;}; PHPFPMSiteConfig = callPackage ./php-fpm/siteconfig.nix {inherit utils;};
@ -29,6 +31,7 @@ let
TtrssConfig = callPackage ./ttrss/config.nix {}; TtrssConfig = callPackage ./ttrss/config.nix {};
TtrssUpdateService = callPackage ./ttrss/update.nix {inherit utils;}; TtrssUpdateService = callPackage ./ttrss/update.nix {inherit utils;};
TtrssUpgradeDBService = callPackage ./ttrss/dbupgrade.nix {}; TtrssUpgradeDBService = callPackage ./ttrss/dbupgrade.nix {};
TtrssPHPNormalizeHeaders = callPackage ./ttrss/normalize-headers.nix {inherit utils;};
}; };
in in
self self

View file

@ -6,19 +6,19 @@
, port , port
, siteName , siteName
, siteRoot , siteRoot
, siteSocket ? "" , phpFpmSiteSocket ? ""
}: }:
rec { rec {
inherit name; inherit name;
caddySocket = "${CaddyService.runtimeDirectory}/${siteName}.sock"; caddySocket = "${CaddyService.runtimeDirectory}/${siteName}.sock";
pkg = CaddySiteConfig rec { pkg = CaddySiteConfig rec {
inherit (CaddyConfig) siteConfigDir; inherit (CaddyConfig) siteConfigDir;
inherit phpFpmSiteSocket;
portBinding = port; portBinding = port;
bindService = siteName; bindService = siteName;
siteSocket = caddySocket; siteSocket = caddySocket;
serviceRoot = siteRoot; serviceRoot = siteRoot;
phpFpmSiteSocket = siteSocket;
}; };
type = "fileset"; type = "fileset";
} }

View file

@ -7,6 +7,8 @@
, siteConfigDir ? "${configFile}/conf.d" , siteConfigDir ? "${configFile}/conf.d"
, logLevel ? "notice" , logLevel ? "notice"
}: }:
{ ... # Depends on whatever
}:
utils.mkConfigFile { utils.mkConfigFile {
name = configFile; name = configFile;

View file

@ -3,18 +3,20 @@
{ PHPFPMConfig { PHPFPMConfig
, PHPFPMService , PHPFPMService
, name , name
, phpConfigDir
, siteName , siteName
, siteRoot , siteRoot
, socketUser , socketUser
, socketGroup , socketGroup
, dependsOn
}: }:
rec { rec {
inherit name; inherit name dependsOn;
siteSocket = "/run/php-fpm/${name}.sock"; siteSocket = "/run/php-fpm/${siteName}.sock";
pkg = PHPFPMSiteConfig { pkg = PHPFPMSiteConfig {
inherit (PHPFPMConfig) siteConfigDir; inherit (PHPFPMConfig) siteConfigDir;
inherit (PHPFPMService) user group; inherit (PHPFPMService) user group;
inherit siteSocket socketUser socketGroup; inherit siteSocket phpConfigDir socketUser socketGroup;
service = siteName; service = siteName;
serviceRoot = siteRoot; serviceRoot = siteRoot;

View file

@ -2,7 +2,8 @@
, pkgs , pkgs
, utils , utils
}: }:
{ siteConfigDir { phpConfigDir
, siteConfigDir
, service , service
, serviceRoot ? "/usr/share/webapps/${service}" , serviceRoot ? "/usr/share/webapps/${service}"
, user , user
@ -18,12 +19,8 @@
, minSpareServers ? 1 , minSpareServers ? 1
, maxSpareServers ? 3 , maxSpareServers ? 3
}: }:
{ ... # Depends on whatever
# user = ${user} }:
# group = ${group}
#
# listen.owner = ${socketUser}
# listen.group = ${socketGroup}
utils.mkConfigFile { utils.mkConfigFile {
name = "${service}.conf"; name = "${service}.conf";
@ -31,8 +28,12 @@ utils.mkConfigFile {
content = '' content = ''
[${service}] [${service}]
user = ${user}
group = ${group}
listen = ${siteSocket} listen = ${siteSocket}
listen.allowed_clients = ${allowedClients} listen.allowed_clients = ${allowedClients}
listen.owner = ${socketUser}
listen.group = ${socketGroup}
env[PATH] = /usr/local/bin:/usr/bin:/bin env[PATH] = /usr/local/bin:/usr/bin:/bin
env[TMP] = /tmp env[TMP] = /tmp

View file

@ -4,8 +4,8 @@
}: }:
{ user ? "http" { user ? "http"
, group ? "http" , group ? "http"
, configDir ? "/etc/php" , configFile ? "/etc/php/php-fpm.conf"
, configFile ? "php-fpm.conf" , phpIni ? "/etc/php/php.ini"
}: }:
{...}: {...}:
@ -19,10 +19,10 @@ utils.systemd.mkService rec {
[Service] [Service]
Type=notify Type=notify
User=${user} # User=${user}
Group=${group} # Group=${group}
PIDFile=/run/php-fpm/php-fpm.pid PIDFile=/run/php-fpm/php-fpm.pid
ExecStart=${pkgs.php}/bin/php-fpm --nodaemonize --fpm-config ${configDir}/${configFile} ExecStart=${pkgs.php}/bin/php-fpm --nodaemonize --fpm-config ${configFile} --php-ini ${phpIni}
ExecReload=/bin/kill -USR2 $MAINPID ExecReload=/bin/kill -USR2 $MAINPID
RuntimeDirectory=php-fpm RuntimeDirectory=php-fpm
# ReadWritePaths=/usr/share/webapps/nextcloud/apps # ReadWritePaths=/usr/share/webapps/nextcloud/apps

105
php/config.nix Normal file
View file

@ -0,0 +1,105 @@
{ stdenv
, pkgs
, lib
, utils
}:
{ configDir ? "/etc/php"
, configFile ? "php.ini"
, prependFile ? null
}:
{ ... # Depends on whatever
}:
let
extensions = [
# "bcmath"
# "curl"
# "gd"
# "gmp"
# "iconv"
# "imagick"
# "intl"
# "ldap"
# "pdo_pgsql"
# "pdo_sqlite"
# "pgsql"
# "soap"
# "sqlite3"
# "zip"
];
zend_extensions = [
# "opcache"
];
concatWithPrefix = prefix: content:
lib.strings.concatMapStrings
(x: prefix + x + "\n")
content;
in
utils.mkConfigFile {
name = configFile;
dir = configDir;
content = ''
[PHP]
engine = On
short_open_tag = Off
precision = 14
output_buffering = 4096
zlib.output_compression = Off
implicit_flush = Off
serialize_precision = -1
zend.enable_gc = On
zend.exception_ignore_args = On
expose_php = Off
max_execution_time = 30 ; seconds
max_input_time = 60
memory_limit = 1024M
error_reporting = E_ALL & ~E_DEPRECATED & ~E_STRICT
display_errors = Off
display_startup_errors = Off
log_errors = On
log_errors_max_len = 1024
ignore_repeated_errors = On
ignore_repeated_source = On
report_memleaks = On
error_log = syslog
syslog.ident = php
post_max_size = 8M
auto_prepend_file = "${if prependFile == null then "" else prependFile}"
auto_append_file =
extension_dir = "/usr/lib/php/modules/"
${concatWithPrefix "extension=" extensions}
${concatWithPrefix "zend_extension=" zend_extensions}
[CLI Server]
cli_server.color = On
; [PostgreSQL]
; pgsql.allow_persistent = On
; pgsql.auto_reset_persistent = Off
; pgsql.max_persistent = -1
; pgsql.max_links = -1
; pgsql.ignore_notice = 0
; pgsql.log_notice = 0
; [Session]
; session.save_handler = redis
; session.save_path = "unix:///run/redis/redis.sock?database=1"
; session.use_strict_mode = 1
; session.use_cookies = 1
; session.use_only_cookies = 1
; [opcache]
; opcache.enable=1
; opcache.memory_consumption=128
; opcache.interned_strings_buffer=16
; opcache.max_accelerated_files=20000
'';
}

View file

@ -0,0 +1,54 @@
{ stdenv
, pkgs
, utils
}:
{ configDir ? "/etc/php"
, configFile ? "normalize-headers.php"
}:
utils.mkConfigFile {
name = configFile;
dir = configDir;
content = ''
<?php
$trustedProxies = array(
'127.0.0.1',
'@'
);
# phpinfo(INFO_VARIABLES);
if (isSet($_SERVER['REMOTE_ADDR'])) {
$remote = $_SERVER['REMOTE_ADDR'];
$allowedHeaders = array(
'HTTP_X_FORWARDED_FOR' => 'REMOTE_ADDR',
'HTTP_X_REAL_IP' => 'REMOTE_HOST',
'HTTP_X_FORWARDED_PORT' => 'REMOTE_PORT',
'HTTP_X_FORWARDED_HTTPS' => 'HTTPS',
'HTTP_X_FORWARDED_SERVER_ADDR' => 'SERVER_ADDR',
'HTTP_X_FORWARDED_SERVER_NAME' => 'SERVER_NAME',
'HTTP_X_FORWARDED_SERVER_PORT' => 'SERVER_PORT',
'HTTP_X_FORWARDED_PREFERRED_USERNAME' => 'REMOTE_USER',
);
if(in_array($remote, $trustedProxies)) {
foreach($allowedHeaders as $header => $serverVar) {
if(isSet($_SERVER[$header])) {
if(isSet($_SERVER[$serverVar])) {
$_SERVER["ORIGINAL_$serverVar"] = $_SERVER[$serverVar];
}
$_SERVER[$serverVar] = explode(',', $_SERVER[$header], 2)[0];
}
}
}
}
# print_r($_REQUEST);
'';
}