Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 546c49767f | |||
| a5deb07a66 | |||
| 9fd3d7142d | |||
| c185b80b4f |
@@ -1,16 +1,22 @@
|
|||||||
# Global log redirection to stdout and stderr
|
|
||||||
ErrorLog "|/usr/bin/tee -a /var/log/apache2/error.log"
|
|
||||||
CustomLog "|/usr/bin/tee -a /var/log/apache2/access.log" combined
|
|
||||||
|
|
||||||
<VirtualHost *:80>
|
<VirtualHost *:80>
|
||||||
|
ServerName localhost
|
||||||
|
|
||||||
DocumentRoot /data/public
|
DocumentRoot /data/public
|
||||||
|
|
||||||
<Directory /data/public>
|
<Directory /data/public>
|
||||||
Options Indexes FollowSymLinks
|
Options FollowSymLinks
|
||||||
AllowOverride All
|
AllowOverride All
|
||||||
Require all granted
|
Require all granted
|
||||||
</Directory>
|
</Directory>
|
||||||
|
|
||||||
# Remote IP configuration
|
DirectoryIndex index.php index.html
|
||||||
RemoteIPHeader X-Forwarded-For
|
|
||||||
RemoteIPTrustedProxy 127.0.0.1
|
# PHP-FPM handler
|
||||||
|
<FilesMatch \.php$>
|
||||||
|
SetHandler "proxy:unix:/run/php/php8.5-fpm.sock|fcgi://localhost/"
|
||||||
|
</FilesMatch>
|
||||||
|
|
||||||
|
# Docker-friendly logging
|
||||||
|
ErrorLog /proc/self/fd/2
|
||||||
|
CustomLog /proc/self/fd/1 combined
|
||||||
</VirtualHost>
|
</VirtualHost>
|
||||||
127
Dockerfile
127
Dockerfile
@@ -1,23 +1,92 @@
|
|||||||
FROM debian:bookworm-20250224
|
FROM debian:trixie-20260316
|
||||||
|
|
||||||
WORKDIR /data
|
WORKDIR /data
|
||||||
|
|
||||||
# Install necessary packages and configure PHP repository
|
# Install base packages + Apache + PHP repo
|
||||||
RUN apt-get update && apt-get install -y \
|
RUN apt-get update && apt-get install -y \
|
||||||
lsb-release ca-certificates curl apt-transport-https logrotate ssl-cert apache2 && \
|
lsb-release \
|
||||||
echo "ServerName localhost" >> /etc/apache2/apache2.conf && \
|
ca-certificates \
|
||||||
curl -sSLo /tmp/debsuryorg-archive-keyring.deb https://packages.sury.org/debsuryorg-archive-keyring.deb && \
|
curl \
|
||||||
dpkg -i /tmp/debsuryorg-archive-keyring.deb && \
|
logrotate \
|
||||||
sh -c 'echo "deb [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] https://packages.sury.org/php/ $(lsb_release -sc) main" > /etc/apt/sources.list.d/php.list' && \
|
ssl-cert \
|
||||||
apt-get update && \
|
apache2 \
|
||||||
apt-get install -y \
|
&& echo "ServerName localhost" >> /etc/apache2/apache2.conf \
|
||||||
php8.4 php8.4-cli php8.4-fpm php8.4-mysql php8.4-xml php8.4-mbstring php8.4-curl php8.4-zip php8.4-redis libapache2-mod-php8.4 && \
|
\
|
||||||
apt-get autoremove -y && \
|
# Add Sury PHP repo
|
||||||
apt-get clean && \
|
&& curl -sSLo /tmp/debsuryorg-archive-keyring.deb https://packages.sury.org/debsuryorg-archive-keyring.deb \
|
||||||
rm -rf /var/lib/apt/lists/* /tmp/*
|
&& dpkg -i /tmp/debsuryorg-archive-keyring.deb \
|
||||||
|
&& echo "deb [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] https://packages.sury.org/php/ $(lsb_release -sc) main" > /etc/apt/sources.list.d/php.list \
|
||||||
|
\
|
||||||
|
&& apt-get update \
|
||||||
|
\
|
||||||
|
# Install PHP 8.5 + extensions
|
||||||
|
&& apt-get install -y \
|
||||||
|
php8.5 \
|
||||||
|
php8.5-cli \
|
||||||
|
php8.5-fpm \
|
||||||
|
php8.5-mysql \
|
||||||
|
php8.5-xml \
|
||||||
|
php8.5-mbstring \
|
||||||
|
php8.5-curl \
|
||||||
|
php8.5-zip \
|
||||||
|
php8.5-redis \
|
||||||
|
\
|
||||||
|
# Cleanup
|
||||||
|
&& apt-get autoremove -y \
|
||||||
|
&& apt-get clean \
|
||||||
|
&& rm -rf /var/lib/apt/lists/* /tmp/*
|
||||||
|
|
||||||
# log management
|
# Apache + PHP-FPM configuration + performance tuning
|
||||||
RUN cat <<EOF > /etc/logrotate.d/apache2
|
RUN \
|
||||||
|
# Enable modules
|
||||||
|
a2enmod proxy_fcgi setenvif expires headers rewrite remoteip socache_shmcb ssl deflate \
|
||||||
|
\
|
||||||
|
# Switch to MPM event
|
||||||
|
&& a2dismod mpm_prefork \
|
||||||
|
&& a2enmod mpm_event \
|
||||||
|
\
|
||||||
|
# Enable PHP-FPM
|
||||||
|
&& a2enconf php8.5-fpm \
|
||||||
|
\
|
||||||
|
# Remote IP config
|
||||||
|
&& echo 'RemoteIPHeader X-Forwarded-For' > /etc/apache2/conf-available/remoteip.conf \
|
||||||
|
&& echo 'RemoteIPTrustedProxy 127.0.0.1' >> /etc/apache2/conf-available/remoteip.conf \
|
||||||
|
&& a2enconf remoteip \
|
||||||
|
&& sed -ri 's/([[:space:]]*LogFormat[[:space:]]+"[^"]*)%h([^"]*")/\1%a\2/g' /etc/apache2/*.conf \
|
||||||
|
\
|
||||||
|
# Security headers
|
||||||
|
&& echo 'Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"' >> /etc/apache2/conf-available/security.conf \
|
||||||
|
&& echo 'Header always set X-Content-Type-Options "nosniff"' >> /etc/apache2/conf-available/security.conf \
|
||||||
|
&& echo 'Header always set X-Frame-Options "SAMEORIGIN"' >> /etc/apache2/conf-available/security.conf \
|
||||||
|
\
|
||||||
|
# Compression
|
||||||
|
&& echo 'AddOutputFilterByType DEFLATE text/html text/plain text/xml text/css application/javascript application/json' > /etc/apache2/conf-available/compression.conf \
|
||||||
|
&& a2enconf compression \
|
||||||
|
\
|
||||||
|
# KeepAlive tuning
|
||||||
|
&& cat <<EOF > /etc/apache2/conf-available/keepalive.conf
|
||||||
|
KeepAlive On
|
||||||
|
MaxKeepAliveRequests 100
|
||||||
|
KeepAliveTimeout 2
|
||||||
|
EOF \
|
||||||
|
&& a2enconf keepalive \
|
||||||
|
\
|
||||||
|
# MPM Event tuning
|
||||||
|
&& cat <<EOF > /etc/apache2/conf-available/mpm-event-tuning.conf
|
||||||
|
<IfModule mpm_event_module>
|
||||||
|
StartServers 2
|
||||||
|
MinSpareThreads 25
|
||||||
|
MaxSpareThreads 75
|
||||||
|
ThreadLimit 64
|
||||||
|
ThreadsPerChild 25
|
||||||
|
MaxRequestWorkers 150
|
||||||
|
MaxConnectionsPerChild 1000
|
||||||
|
</IfModule>
|
||||||
|
EOF \
|
||||||
|
&& a2enconf mpm-event-tuning \
|
||||||
|
\
|
||||||
|
# Logrotate
|
||||||
|
&& cat <<EOF > /etc/logrotate.d/apache2
|
||||||
/var/log/apache2/*.log {
|
/var/log/apache2/*.log {
|
||||||
weekly
|
weekly
|
||||||
missingok
|
missingok
|
||||||
@@ -29,25 +98,23 @@ RUN cat <<EOF > /etc/logrotate.d/apache2
|
|||||||
}
|
}
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
RUN echo 'RemoteIPHeader X-Forwarded-For' > /etc/apache2/conf-available/remoteip.conf && \
|
# PHP-FPM tuning
|
||||||
echo 'RemoteIPTrustedProxy 127.0.0.1' >> /etc/apache2/conf-available/remoteip.conf && \
|
RUN sed -i 's/^pm = .*/pm = dynamic/' /etc/php/8.5/fpm/pool.d/www.conf && \
|
||||||
a2enconf remoteip && \
|
sed -i 's/^pm.max_children = .*/pm.max_children = 20/' /etc/php/8.5/fpm/pool.d/www.conf && \
|
||||||
sed -ri 's/([[:space:]]*LogFormat[[:space:]]+"[^"]*)%h([^"]*")/\1%a\2/g' /etc/apache2/*.conf
|
sed -i 's/^pm.start_servers = .*/pm.start_servers = 2/' /etc/php/8.5/fpm/pool.d/www.conf && \
|
||||||
|
sed -i 's/^pm.min_spare_servers = .*/pm.min_spare_servers = 2/' /etc/php/8.5/fpm/pool.d/www.conf && \
|
||||||
|
sed -i 's/^pm.max_spare_servers = .*/pm.max_spare_servers = 5/' /etc/php/8.5/fpm/pool.d/www.conf
|
||||||
|
|
||||||
|
# PHP custom config
|
||||||
RUN mkdir -p /php && echo "PHP_INI_SCAN_DIR=/php" > /etc/environment
|
RUN mkdir -p /php && echo "PHP_INI_SCAN_DIR=/php" > /etc/environment
|
||||||
|
|
||||||
COPY php.ini /php/php.ini
|
COPY php.ini /php/php.ini
|
||||||
COPY 000-default.conf /etc/apache2/sites-available/000-default.conf
|
COPY 000-default.conf /etc/apache2/sites-available/000-default.conf
|
||||||
|
|
||||||
# Security headers for Apache
|
|
||||||
RUN echo 'Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"' >> /etc/apache2/conf-available/security.conf && \
|
|
||||||
echo 'Header always set X-Content-Type-Options "nosniff"' >> /etc/apache2/conf-available/security.conf && \
|
|
||||||
echo 'Header always set X-XSS-Protection "1; mode=block"' >> /etc/apache2/conf-available/security.conf && \
|
|
||||||
echo 'Header always set X-Frame-Options "SAMEORIGIN"' >> /etc/apache2/conf-available/security.conf
|
|
||||||
|
|
||||||
RUN a2enmod expires headers rewrite remoteip socache_shmcb ssl
|
|
||||||
|
|
||||||
EXPOSE 80
|
EXPOSE 80
|
||||||
CMD ["apachectl", "-D", "FOREGROUND"]
|
|
||||||
|
|
||||||
HEALTHCHECK --interval=30s --timeout=10s --retries=3 \
|
# Startup
|
||||||
CMD curl --silent --fail localhost:80 || exit 1
|
COPY start.sh /start.sh
|
||||||
|
RUN chmod +x /start.sh
|
||||||
|
|
||||||
|
CMD ["/start.sh"]
|
||||||
24
README.md
24
README.md
@@ -2,15 +2,14 @@
|
|||||||
|
|
||||||
# CORXN - The Core Foundation of Novaconium
|
# CORXN - The Core Foundation of Novaconium
|
||||||
|
|
||||||
Dockerhub: https://hub.docker.com/r/4lights/phpcontainer
|
Links: [Dockerhub](https://hub.docker.com/r/4lights/corxn), [Git Repo](https://git.4lt.ca/4lt/CORXN)
|
||||||
Git Repo: https://git.4lt.ca/4lt/phpcontainer
|
|
||||||
|
|
||||||
CORXN (core-ex-en) is a lightweight yet powerful Docker-based environment designed as the core foundation for the [Novaconium PHP Framework](https://git.4lt.ca/4lt/novaconium).
|
CORXN (core-ex-en) is a lightweight yet powerful Docker-based environment designed as the core foundation for the [Novaconium PHP Framework](https://git.4lt.ca/4lt/novaconium).
|
||||||
It provides a streamlined stack featuring Apache, the latest PHP version, Redis, and MariaDB, optimized for high performance.
|
It provides a streamlined stack featuring Apache, the latest PHP version, Redis, and MariaDB, optimized for high performance.
|
||||||
|
|
||||||
## Features
|
## Features
|
||||||
|
|
||||||
- **PHP Version**: 8.4.5
|
- **PHP Version**: 8.5.3
|
||||||
- **Apache Web Server**: Configured to run PHP applications
|
- **Apache Web Server**: Configured to run PHP applications
|
||||||
- **Support for**:
|
- **Support for**:
|
||||||
- `remoteip` (reverse proxy)
|
- `remoteip` (reverse proxy)
|
||||||
@@ -34,12 +33,21 @@ cd corxn
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
sudo su
|
sudo su
|
||||||
docker buildx build --no-cache -t 4lights/corxn:6.0.0 -t 4lights/corxn:latest --load .
|
docker buildx build --no-cache -t 4lights/corxn:8.5.3 -t 4lights/corxn:latest --load .
|
||||||
docker login
|
docker login -u <username>
|
||||||
docker push 4lights/corxn:6.0.0
|
docker push 4lights/corxn:8.5.3
|
||||||
docker push 4lights/corxn:latest
|
docker push 4lights/corxn:latest
|
||||||
```
|
```
|
||||||
|
# Testing
|
||||||
|
|
||||||
# References And Notes
|
Here is how to text the build:
|
||||||
|
```bash
|
||||||
|
mkdir -p data/uploads && sudo chown -R 33:33 data/uploads && chmod 775 data/uploads
|
||||||
|
docker compose up -d
|
||||||
|
# Visit: http://localhost:8000/test.php
|
||||||
|
# Test: file upload and that green checkmarks exist
|
||||||
|
```
|
||||||
|
|
||||||
Test using test.php
|
# Logs
|
||||||
|
|
||||||
|
```docker logs corxn```
|
||||||
|
|||||||
@@ -1,31 +1,31 @@
|
|||||||
# Sample Docker Compose
|
# Sample Docker Compose
|
||||||
services:
|
services:
|
||||||
php-apache:
|
corxn:
|
||||||
image: 4lights/phpcontainer:6.0.0
|
image: 4lights/corxn:latest
|
||||||
ports:
|
ports:
|
||||||
- "8000:80"
|
- "8000:80"
|
||||||
volumes:
|
volumes:
|
||||||
- ./:/data # looks for /data/public
|
- ./test:/data # looks for /data/public
|
||||||
- ./php.ini:/php/php.ini # Optional override php.ini
|
- ./php.ini:/php/php.ini:ro # Optional override php.ini
|
||||||
- ./data/logs:/var/log/apache2 # Optional Logs
|
- ./data/uploads:/data/public/uploads
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
- internal
|
- internal
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
image: redis:latest
|
image: redis:7
|
||||||
networks:
|
networks:
|
||||||
- internal
|
- internal
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
|
||||||
mariadb:
|
mariadb:
|
||||||
image: mariadb:latest
|
image: mariadb:11
|
||||||
environment:
|
environment:
|
||||||
MYSQL_ROOT_PASSWORD: rootpassword
|
- MYSQL_ROOT_PASSWORD=rootpassword
|
||||||
MYSQL_DATABASE: dbname
|
- MYSQL_DATABASE=dbname
|
||||||
MYSQL_USER: user
|
- MYSQL_USER=user
|
||||||
MYSQL_PASSWORD: password
|
- MYSQL_PASSWORD=password
|
||||||
volumes:
|
volumes:
|
||||||
- ./data/db:/var/lib/mysql
|
- ./data/db:/var/lib/mysql
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
5
docs/phpmyadmin.md
Normal file
5
docs/phpmyadmin.md
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
# PHPMYADMIN
|
||||||
|
|
||||||
|
You may want to use PHPmyAdmin for testing.
|
||||||
|
|
||||||
|
Checkout [Docker Cookbooks](https://github.com/nickyeoman/docker-compose-cookbooks/blob/master/phpmyadmin/docker-compose.yml) for an example.
|
||||||
64
php.ini
64
php.ini
@@ -1,55 +1,53 @@
|
|||||||
[PHP]
|
[PHP]
|
||||||
; Basic PHP settings
|
; Performance
|
||||||
max_execution_time = 30
|
max_execution_time = 30
|
||||||
memory_limit = 500M
|
max_input_time = 60
|
||||||
|
memory_limit = 512M
|
||||||
|
|
||||||
|
; Uploads
|
||||||
upload_max_filesize = 100M
|
upload_max_filesize = 100M
|
||||||
post_max_size = 100M
|
post_max_size = 100M
|
||||||
max_input_time = 60
|
|
||||||
|
; Timezone
|
||||||
date.timezone = America/Vancouver
|
date.timezone = America/Vancouver
|
||||||
|
|
||||||
; Error handling
|
; Errors (production-safe)
|
||||||
display_errors = On
|
display_errors = Off
|
||||||
display_startup_errors = On
|
display_startup_errors = Off
|
||||||
log_errors = On
|
log_errors = On
|
||||||
error_log = /var/log/php_errors.log
|
error_log = /proc/self/fd/2
|
||||||
|
|
||||||
; Session settings
|
; Sessions
|
||||||
session.save_path = "/var/lib/php/sessions"
|
session.save_path = "/var/lib/php/sessions"
|
||||||
session.gc_maxlifetime = 1440
|
session.gc_maxlifetime = 1440
|
||||||
session.cookie_lifetime = 0
|
session.cookie_lifetime = 0
|
||||||
session.use_strict_mode = 1
|
session.use_strict_mode = 1
|
||||||
|
|
||||||
|
; File handling
|
||||||
|
file_uploads = On
|
||||||
|
allow_url_fopen = On
|
||||||
|
|
||||||
; Realpath cache
|
; Realpath cache
|
||||||
realpath_cache_size = 4096k
|
realpath_cache_size = 4096k
|
||||||
realpath_cache_ttl = 120
|
realpath_cache_ttl = 120
|
||||||
|
|
||||||
; File upload settings
|
; cURL
|
||||||
file_uploads = On
|
|
||||||
allow_url_fopen = On
|
|
||||||
|
|
||||||
; Redis settings (ensure Redis extension is loaded)
|
|
||||||
extension=redis.so
|
|
||||||
|
|
||||||
; mbstring settings (useful for multi-byte encoding handling)
|
|
||||||
mbstring.language = Japanese
|
|
||||||
mbstring.internal_encoding = UTF-8
|
|
||||||
mbstring.http_input = auto
|
|
||||||
mbstring.http_output = UTF-8
|
|
||||||
mbstring.detect_order = auto
|
|
||||||
mbstring.substitute_character = none
|
|
||||||
|
|
||||||
; cURL settings
|
|
||||||
curl.cainfo = "/etc/ssl/certs/ca-certificates.crt"
|
curl.cainfo = "/etc/ssl/certs/ca-certificates.crt"
|
||||||
|
|
||||||
; SMTP settings (for sending mail, if needed)
|
; Mail (optional)
|
||||||
SMTP = localhost
|
SMTP = localhost
|
||||||
sendmail_path = /usr/sbin/sendmail -t -i
|
sendmail_path = /usr/sbin/sendmail -t -i
|
||||||
|
|
||||||
; Extension loading
|
; OPcache (IMPORTANT)
|
||||||
extension=curl
|
opcache.enable=1
|
||||||
extension=mbstring
|
opcache.enable_cli=1
|
||||||
extension=redis
|
opcache.memory_consumption=192
|
||||||
extension=xml
|
opcache.interned_strings_buffer=16
|
||||||
extension=mysqli
|
opcache.max_accelerated_files=20000
|
||||||
extension=pdo_mysql
|
opcache.validate_timestamps=0
|
||||||
extension=zip
|
opcache.revalidate_freq=0
|
||||||
|
opcache.fast_shutdown=1
|
||||||
|
|
||||||
|
; Redis
|
||||||
|
session.save_handler = redis
|
||||||
|
session.save_path = "tcp://redis:6379"
|
||||||
|
|||||||
6
start.sh
Normal file
6
start.sh
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
service php8.5-fpm start
|
||||||
|
|
||||||
|
exec apachectl -D FOREGROUND
|
||||||
@@ -74,7 +74,7 @@
|
|||||||
|
|
||||||
<div class="container">
|
<div class="container">
|
||||||
<h1>PHP Container Test Script</h1>
|
<h1>PHP Container Test Script</h1>
|
||||||
<p><a href="https://git.4lt.ca/4lt/phpcontainer">Four Lights PHP Container</a></p>
|
<p><a href="https://git.4lt.ca/4lt/CORXN">Four Lights PHP Container: CORXN</a></p>
|
||||||
|
|
||||||
|
|
||||||
<h2>Server Information</h2>
|
<h2>Server Information</h2>
|
||||||
@@ -129,11 +129,7 @@
|
|||||||
<?php
|
<?php
|
||||||
if ($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_FILES['testfile'])) {
|
if ($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_FILES['testfile'])) {
|
||||||
if ($_FILES['testfile']['error'] === UPLOAD_ERR_OK) {
|
if ($_FILES['testfile']['error'] === UPLOAD_ERR_OK) {
|
||||||
$uploadDir = '/data/public/uploads/';
|
$uploadDir = __DIR__ . '/uploads/';
|
||||||
|
|
||||||
if (!is_dir($uploadDir)) {
|
|
||||||
mkdir($uploadDir, 0777, true);
|
|
||||||
}
|
|
||||||
|
|
||||||
$destination = $uploadDir . basename($_FILES['testfile']['name']);
|
$destination = $uploadDir . basename($_FILES['testfile']['name']);
|
||||||
|
|
||||||
Reference in New Issue
Block a user