4 Commits

Author SHA1 Message Date
546c49767f Upgraded to Trixie and php8.5.3 2026-03-20 08:49:15 -07:00
a5deb07a66 fixed env format and added phpmyadmin doc 2025-06-08 18:15:16 -07:00
9fd3d7142d fixed the readme links 2025-03-26 18:19:10 -07:00
c185b80b4f updated name in docker-compose 2025-03-21 18:21:19 -07:00
8 changed files with 185 additions and 99 deletions

View File

@@ -1,16 +1,22 @@
# Global log redirection to stdout and stderr
ErrorLog "|/usr/bin/tee -a /var/log/apache2/error.log"
CustomLog "|/usr/bin/tee -a /var/log/apache2/access.log" combined
<VirtualHost *:80> <VirtualHost *:80>
ServerName localhost
DocumentRoot /data/public DocumentRoot /data/public
<Directory /data/public> <Directory /data/public>
Options Indexes FollowSymLinks Options FollowSymLinks
AllowOverride All AllowOverride All
Require all granted Require all granted
</Directory> </Directory>
# Remote IP configuration DirectoryIndex index.php index.html
RemoteIPHeader X-Forwarded-For
RemoteIPTrustedProxy 127.0.0.1 # PHP-FPM handler
</VirtualHost> <FilesMatch \.php$>
SetHandler "proxy:unix:/run/php/php8.5-fpm.sock|fcgi://localhost/"
</FilesMatch>
# Docker-friendly logging
ErrorLog /proc/self/fd/2
CustomLog /proc/self/fd/1 combined
</VirtualHost>

View File

@@ -1,23 +1,92 @@
FROM debian:bookworm-20250224 FROM debian:trixie-20260316
WORKDIR /data WORKDIR /data
# Install necessary packages and configure PHP repository # Install base packages + Apache + PHP repo
RUN apt-get update && apt-get install -y \ RUN apt-get update && apt-get install -y \
lsb-release ca-certificates curl apt-transport-https logrotate ssl-cert apache2 && \ lsb-release \
echo "ServerName localhost" >> /etc/apache2/apache2.conf && \ ca-certificates \
curl -sSLo /tmp/debsuryorg-archive-keyring.deb https://packages.sury.org/debsuryorg-archive-keyring.deb && \ curl \
dpkg -i /tmp/debsuryorg-archive-keyring.deb && \ logrotate \
sh -c 'echo "deb [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] https://packages.sury.org/php/ $(lsb_release -sc) main" > /etc/apt/sources.list.d/php.list' && \ ssl-cert \
apt-get update && \ apache2 \
apt-get install -y \ && echo "ServerName localhost" >> /etc/apache2/apache2.conf \
php8.4 php8.4-cli php8.4-fpm php8.4-mysql php8.4-xml php8.4-mbstring php8.4-curl php8.4-zip php8.4-redis libapache2-mod-php8.4 && \ \
apt-get autoremove -y && \ # Add Sury PHP repo
apt-get clean && \ && curl -sSLo /tmp/debsuryorg-archive-keyring.deb https://packages.sury.org/debsuryorg-archive-keyring.deb \
rm -rf /var/lib/apt/lists/* /tmp/* && dpkg -i /tmp/debsuryorg-archive-keyring.deb \
&& echo "deb [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] https://packages.sury.org/php/ $(lsb_release -sc) main" > /etc/apt/sources.list.d/php.list \
\
&& apt-get update \
\
# Install PHP 8.5 + extensions
&& apt-get install -y \
php8.5 \
php8.5-cli \
php8.5-fpm \
php8.5-mysql \
php8.5-xml \
php8.5-mbstring \
php8.5-curl \
php8.5-zip \
php8.5-redis \
\
# Cleanup
&& apt-get autoremove -y \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* /tmp/*
# log management # Apache + PHP-FPM configuration + performance tuning
RUN cat <<EOF > /etc/logrotate.d/apache2 RUN \
# Enable modules
a2enmod proxy_fcgi setenvif expires headers rewrite remoteip socache_shmcb ssl deflate \
\
# Switch to MPM event
&& a2dismod mpm_prefork \
&& a2enmod mpm_event \
\
# Enable PHP-FPM
&& a2enconf php8.5-fpm \
\
# Remote IP config
&& echo 'RemoteIPHeader X-Forwarded-For' > /etc/apache2/conf-available/remoteip.conf \
&& echo 'RemoteIPTrustedProxy 127.0.0.1' >> /etc/apache2/conf-available/remoteip.conf \
&& a2enconf remoteip \
&& sed -ri 's/([[:space:]]*LogFormat[[:space:]]+"[^"]*)%h([^"]*")/\1%a\2/g' /etc/apache2/*.conf \
\
# Security headers
&& echo 'Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"' >> /etc/apache2/conf-available/security.conf \
&& echo 'Header always set X-Content-Type-Options "nosniff"' >> /etc/apache2/conf-available/security.conf \
&& echo 'Header always set X-Frame-Options "SAMEORIGIN"' >> /etc/apache2/conf-available/security.conf \
\
# Compression
&& echo 'AddOutputFilterByType DEFLATE text/html text/plain text/xml text/css application/javascript application/json' > /etc/apache2/conf-available/compression.conf \
&& a2enconf compression \
\
# KeepAlive tuning
&& cat <<EOF > /etc/apache2/conf-available/keepalive.conf
KeepAlive On
MaxKeepAliveRequests 100
KeepAliveTimeout 2
EOF \
&& a2enconf keepalive \
\
# MPM Event tuning
&& cat <<EOF > /etc/apache2/conf-available/mpm-event-tuning.conf
<IfModule mpm_event_module>
StartServers 2
MinSpareThreads 25
MaxSpareThreads 75
ThreadLimit 64
ThreadsPerChild 25
MaxRequestWorkers 150
MaxConnectionsPerChild 1000
</IfModule>
EOF \
&& a2enconf mpm-event-tuning \
\
# Logrotate
&& cat <<EOF > /etc/logrotate.d/apache2
/var/log/apache2/*.log { /var/log/apache2/*.log {
weekly weekly
missingok missingok
@@ -29,25 +98,23 @@ RUN cat <<EOF > /etc/logrotate.d/apache2
} }
EOF EOF
RUN echo 'RemoteIPHeader X-Forwarded-For' > /etc/apache2/conf-available/remoteip.conf && \ # PHP-FPM tuning
echo 'RemoteIPTrustedProxy 127.0.0.1' >> /etc/apache2/conf-available/remoteip.conf && \ RUN sed -i 's/^pm = .*/pm = dynamic/' /etc/php/8.5/fpm/pool.d/www.conf && \
a2enconf remoteip && \ sed -i 's/^pm.max_children = .*/pm.max_children = 20/' /etc/php/8.5/fpm/pool.d/www.conf && \
sed -ri 's/([[:space:]]*LogFormat[[:space:]]+"[^"]*)%h([^"]*")/\1%a\2/g' /etc/apache2/*.conf sed -i 's/^pm.start_servers = .*/pm.start_servers = 2/' /etc/php/8.5/fpm/pool.d/www.conf && \
sed -i 's/^pm.min_spare_servers = .*/pm.min_spare_servers = 2/' /etc/php/8.5/fpm/pool.d/www.conf && \
sed -i 's/^pm.max_spare_servers = .*/pm.max_spare_servers = 5/' /etc/php/8.5/fpm/pool.d/www.conf
# PHP custom config
RUN mkdir -p /php && echo "PHP_INI_SCAN_DIR=/php" > /etc/environment RUN mkdir -p /php && echo "PHP_INI_SCAN_DIR=/php" > /etc/environment
COPY php.ini /php/php.ini COPY php.ini /php/php.ini
COPY 000-default.conf /etc/apache2/sites-available/000-default.conf COPY 000-default.conf /etc/apache2/sites-available/000-default.conf
# Security headers for Apache
RUN echo 'Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"' >> /etc/apache2/conf-available/security.conf && \
echo 'Header always set X-Content-Type-Options "nosniff"' >> /etc/apache2/conf-available/security.conf && \
echo 'Header always set X-XSS-Protection "1; mode=block"' >> /etc/apache2/conf-available/security.conf && \
echo 'Header always set X-Frame-Options "SAMEORIGIN"' >> /etc/apache2/conf-available/security.conf
RUN a2enmod expires headers rewrite remoteip socache_shmcb ssl
EXPOSE 80 EXPOSE 80
CMD ["apachectl", "-D", "FOREGROUND"]
HEALTHCHECK --interval=30s --timeout=10s --retries=3 \ # Startup
CMD curl --silent --fail localhost:80 || exit 1 COPY start.sh /start.sh
RUN chmod +x /start.sh
CMD ["/start.sh"]

View File

@@ -2,15 +2,14 @@
# CORXN - The Core Foundation of Novaconium # CORXN - The Core Foundation of Novaconium
Dockerhub: https://hub.docker.com/r/4lights/phpcontainer Links: [Dockerhub](https://hub.docker.com/r/4lights/corxn), [Git Repo](https://git.4lt.ca/4lt/CORXN)
Git Repo: https://git.4lt.ca/4lt/phpcontainer
CORXN (core-ex-en) is a lightweight yet powerful Docker-based environment designed as the core foundation for the [Novaconium PHP Framework](https://git.4lt.ca/4lt/novaconium). CORXN (core-ex-en) is a lightweight yet powerful Docker-based environment designed as the core foundation for the [Novaconium PHP Framework](https://git.4lt.ca/4lt/novaconium).
It provides a streamlined stack featuring Apache, the latest PHP version, Redis, and MariaDB, optimized for high performance. It provides a streamlined stack featuring Apache, the latest PHP version, Redis, and MariaDB, optimized for high performance.
## Features ## Features
- **PHP Version**: 8.4.5 - **PHP Version**: 8.5.3
- **Apache Web Server**: Configured to run PHP applications - **Apache Web Server**: Configured to run PHP applications
- **Support for**: - **Support for**:
- `remoteip` (reverse proxy) - `remoteip` (reverse proxy)
@@ -34,12 +33,21 @@ cd corxn
```bash ```bash
sudo su sudo su
docker buildx build --no-cache -t 4lights/corxn:6.0.0 -t 4lights/corxn:latest --load . docker buildx build --no-cache -t 4lights/corxn:8.5.3 -t 4lights/corxn:latest --load .
docker login docker login -u <username>
docker push 4lights/corxn:6.0.0 docker push 4lights/corxn:8.5.3
docker push 4lights/corxn:latest docker push 4lights/corxn:latest
``` ```
# Testing
# References And Notes Here is how to text the build:
```bash
mkdir -p data/uploads && sudo chown -R 33:33 data/uploads && chmod 775 data/uploads
docker compose up -d
# Visit: http://localhost:8000/test.php
# Test: file upload and that green checkmarks exist
```
Test using test.php # Logs
```docker logs corxn```

View File

@@ -1,31 +1,31 @@
# Sample Docker Compose # Sample Docker Compose
services: services:
php-apache: corxn:
image: 4lights/phpcontainer:6.0.0 image: 4lights/corxn:latest
ports: ports:
- "8000:80" - "8000:80"
volumes: volumes:
- ./:/data # looks for /data/public - ./test:/data # looks for /data/public
- ./php.ini:/php/php.ini # Optional override php.ini - ./php.ini:/php/php.ini:ro # Optional override php.ini
- ./data/logs:/var/log/apache2 # Optional Logs - ./data/uploads:/data/public/uploads
restart: unless-stopped restart: unless-stopped
networks: networks:
- proxy - proxy
- internal - internal
redis: redis:
image: redis:latest image: redis:7
networks: networks:
- internal - internal
restart: unless-stopped restart: unless-stopped
mariadb: mariadb:
image: mariadb:latest image: mariadb:11
environment: environment:
MYSQL_ROOT_PASSWORD: rootpassword - MYSQL_ROOT_PASSWORD=rootpassword
MYSQL_DATABASE: dbname - MYSQL_DATABASE=dbname
MYSQL_USER: user - MYSQL_USER=user
MYSQL_PASSWORD: password - MYSQL_PASSWORD=password
volumes: volumes:
- ./data/db:/var/lib/mysql - ./data/db:/var/lib/mysql
networks: networks:
@@ -36,4 +36,4 @@ networks:
proxy: proxy:
external: true external: true
internal: internal:
driver: bridge driver: bridge

5
docs/phpmyadmin.md Normal file
View File

@@ -0,0 +1,5 @@
# PHPMYADMIN
You may want to use PHPmyAdmin for testing.
Checkout [Docker Cookbooks](https://github.com/nickyeoman/docker-compose-cookbooks/blob/master/phpmyadmin/docker-compose.yml) for an example.

64
php.ini
View File

@@ -1,55 +1,53 @@
[PHP] [PHP]
; Basic PHP settings ; Performance
max_execution_time = 30 max_execution_time = 30
memory_limit = 500M max_input_time = 60
memory_limit = 512M
; Uploads
upload_max_filesize = 100M upload_max_filesize = 100M
post_max_size = 100M post_max_size = 100M
max_input_time = 60
; Timezone
date.timezone = America/Vancouver date.timezone = America/Vancouver
; Error handling ; Errors (production-safe)
display_errors = On display_errors = Off
display_startup_errors = On display_startup_errors = Off
log_errors = On log_errors = On
error_log = /var/log/php_errors.log error_log = /proc/self/fd/2
; Session settings ; Sessions
session.save_path = "/var/lib/php/sessions" session.save_path = "/var/lib/php/sessions"
session.gc_maxlifetime = 1440 session.gc_maxlifetime = 1440
session.cookie_lifetime = 0 session.cookie_lifetime = 0
session.use_strict_mode = 1 session.use_strict_mode = 1
; File handling
file_uploads = On
allow_url_fopen = On
; Realpath cache ; Realpath cache
realpath_cache_size = 4096k realpath_cache_size = 4096k
realpath_cache_ttl = 120 realpath_cache_ttl = 120
; File upload settings ; cURL
file_uploads = On
allow_url_fopen = On
; Redis settings (ensure Redis extension is loaded)
extension=redis.so
; mbstring settings (useful for multi-byte encoding handling)
mbstring.language = Japanese
mbstring.internal_encoding = UTF-8
mbstring.http_input = auto
mbstring.http_output = UTF-8
mbstring.detect_order = auto
mbstring.substitute_character = none
; cURL settings
curl.cainfo = "/etc/ssl/certs/ca-certificates.crt" curl.cainfo = "/etc/ssl/certs/ca-certificates.crt"
; SMTP settings (for sending mail, if needed) ; Mail (optional)
SMTP = localhost SMTP = localhost
sendmail_path = /usr/sbin/sendmail -t -i sendmail_path = /usr/sbin/sendmail -t -i
; Extension loading ; OPcache (IMPORTANT)
extension=curl opcache.enable=1
extension=mbstring opcache.enable_cli=1
extension=redis opcache.memory_consumption=192
extension=xml opcache.interned_strings_buffer=16
extension=mysqli opcache.max_accelerated_files=20000
extension=pdo_mysql opcache.validate_timestamps=0
extension=zip opcache.revalidate_freq=0
opcache.fast_shutdown=1
; Redis
session.save_handler = redis
session.save_path = "tcp://redis:6379"

6
start.sh Normal file
View File

@@ -0,0 +1,6 @@
#!/bin/bash
set -e
service php8.5-fpm start
exec apachectl -D FOREGROUND

View File

@@ -74,7 +74,7 @@
<div class="container"> <div class="container">
<h1>PHP Container Test Script</h1> <h1>PHP Container Test Script</h1>
<p><a href="https://git.4lt.ca/4lt/phpcontainer">Four Lights PHP Container</a></p> <p><a href="https://git.4lt.ca/4lt/CORXN">Four Lights PHP Container: CORXN</a></p>
<h2>Server Information</h2> <h2>Server Information</h2>
@@ -129,11 +129,7 @@
<?php <?php
if ($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_FILES['testfile'])) { if ($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_FILES['testfile'])) {
if ($_FILES['testfile']['error'] === UPLOAD_ERR_OK) { if ($_FILES['testfile']['error'] === UPLOAD_ERR_OK) {
$uploadDir = '/data/public/uploads/'; $uploadDir = __DIR__ . '/uploads/';
if (!is_dir($uploadDir)) {
mkdir($uploadDir, 0777, true);
}
$destination = $uploadDir . basename($_FILES['testfile']['name']); $destination = $uploadDir . basename($_FILES['testfile']['name']);