]> git.openstreetmap.org Git - chef.git/commitdiff
Switch mediawiki cookbook to use FPM for PHP
authorTom Hughes <tom@compton.nu>
Mon, 13 Jul 2020 16:29:00 +0000 (17:29 +0100)
committerTom Hughes <tom@compton.nu>
Mon, 13 Jul 2020 16:29:00 +0000 (17:29 +0100)
cookbooks/mediawiki/recipes/default.rb
cookbooks/mediawiki/templates/default/apache.erb

index f6cea2d269bdd4626972b21b36fb8f952ab7cafb..a27056dd99de23fbbe439d2c0b712296b7987af7 100644 (file)
@@ -23,7 +23,7 @@ include_recipe "apt"
 include_recipe "git"
 include_recipe "memcached"
 include_recipe "mysql"
-include_recipe "php::apache"
+include_recipe "php::apache-fpm"
 
 # Mediawiki Base Requirements
 package %w[
index d5485a6204bb46b713cced32ad4b66c18486ad3d..586f2391e6ede6d9f5a23408929758b0f95c5794 100644 (file)
 
   DocumentRoot <%= @directory %>
 
-  php_admin_value open_basedir <%= @directory %>/:/usr/share/php/:/dev/null:/tmp/
-  #php_admin_value disable_functions "exec,shell_exec,system,passthru,popen,proc_open"
-  php_value memory_limit 500M
-  php_value max_execution_time 240
-  php_value upload_max_filesize 70M
-  php_value post_max_size 100M
+  ProxyFCGISetEnvIf "true" PHP_ADMIN_VALUE "open_basedir=<%= @directory %>/:/usr/share/php/:/dev/null:/tmp/"
+  ProxyFCGISetEnvIf "true" PHP_VALUE "memory_limit=500M\nmax_execution_time=240\nupload_max_filesize=70M\npost_max_size=100M"
 
   RewriteCond %{SERVER_NAME} !=<%= @name %>
   RewriteRule ^/(.*)$ https://<%= @name %>/$1 [R=permanent]
   </Directory>
 
   <Directory <%= @directory %>/w/images/>
-    # No php execution in the upload area
-    php_admin_flag engine off
     Options -ExecCGI -Includes -Indexes
     AllowOverride None
     AddType text/plain .html .htm .shtml
 <% if @private_site -%>
     Require all denied
 <% end -%>
+    <FilesMatch ".+\.ph(ar|p|tml)$">
+      SetHandler None
+    </FilesMatch>
   </Directory>
 
   <Directory <%= @directory %>/w/images/thumb/>
     Options -ExecCGI -Includes -Indexes
     AllowOverride None
     AddType text/plain .html .htm .shtml
-    php_admin_flag engine off
+    <FilesMatch ".+\.ph(ar|p|tml)$">
+      SetHandler None
+    </FilesMatch>
   </Directory>
 
   <Directory <%= @directory %>/dump/>