3 ms·
I think your last paragraph is overstating things a little. If you're providing hosting for other 'random' clients who upload their own plugins, sure, you need
by deckiedan 10y ago
I think your last paragraph is overstating things a little. If you're providing hosting for other 'random' clients who upload their own plugins, sure, you need to be wildly over-zealous.
I, and probably many others, provide hosting for a few wordpress sites that we admin, and a client has only editor access to.
The way I've got it set up is:
- nginx running as nginx:nginx, handling static files, and passing on to PHP-fpm only for non-upload directories.
- each site directory is owned by $clientname:$clientgroup.
- php-fpm runs in each dir as $clientname-php:$clientgroup.
So wp-config.php, etc. configuration stuff is readable only by the group, and only writable by the owner user.
The PHP running user can upload media, post new content, but cannot upload plugins, edit any other PHP files, change any site-level configuration, etc.
To upload plugins, or do updates, inside wordpress it asks the user each time for a FTP username/password, which it uses to create a local ftp connection in to the server, as $clientname, which can then write to the plugins directory.
FTP is only accessable from localhost, so there's nothing in plaintext on the wire.
Wordpress and plugin updates are done by WP-CLI hourly as a cronjob by the $clientname user.
Each site has its own database, user, and all that too.
All of this is set up by ansible, so it takes me about 3 commands to create a new site from scratch, or 5 to provision it onto a new server.
I've got reasonably defaults set up in php-fpm, so basedir, maxupload, restrictions, and all that. And as much as possible restrictions in place by nginx as well.
I'm working on automatic SSL certs from letsencrypt, which is working on some sites now, which beats the self-signed ones I had before (log-in only to wp-admin by SSL).
It seems relatively good for me. The sites are fast, cheap, and for my clients (small businesses, friends, family, church(s), etc), perfectly adequate.
I understand the full stack, and can keep the very cheap VPS running in less than an hour or so a month.
In the future, I hope that there is something more self-contained and easy to deploy, perhaps like caddy[1].
I'm not a huge fan of wordpress... but it's everywhere, and enough people have heard of it / can do stuff with it. The bus factor is a lot lower than many alternatives.
[1] https://caddyserver.com/ https://caddyserver.com/
- Intermernet 10y agoCaddy is brilliant. Give it another year and I think it will have a significant share of the webserver market. I replaced about 200 lines of nginx configuration with about 15 lines of Caddyfile. This is mostly due to sane defaults and inbuilt support for Let's Encrypt.
- pbowyer 10y agoAre your ansible scripts available, as this sounds an awesome setup? Thanks.
- deckiedan 10y agoI'll try to at some point - but a lot of it was hacked together pretty quickly to various deadlines, so I'd like to refactor some bits and audit it to make sure I didn't do anything stupid like put mysql root passwords in a config template somewhere... I'll try and post to HN when I do.