6 ms·
Is anybody still using Apache? I'm really iterested on the whys (in addition to the obvious legacy reasons).
by kodfodrasz 9y ago
Is anybody still using Apache?
I'm really iterested on the whys (in addition to the obvious legacy reasons).
- tyingq 9y agoOne driver is popular software that depends on the .htaccess construct. WordPress, for example. It can run on other servers, but their own docs call out the issue..."Since Nginx does not have .htaccess-type capability and WordPress cannot automatically modify the server configuration for you, it cannot generate the rewrite rules for you"
- pmlnr 9y ago... and this is why WP has it's own rewrite engine, which works perfectly with nginx.
- tyingq 9y agoThe quoted text is from their docs, and does not read that way. Some more: "With Nginx there is no directory-level configuration file like Apache's .htaccess or IIS's web.config files. All configuration has to be done at the server level by an administrator, and WordPress cannot modify the configuration, like it can with Apache or IIS"
- pmlnr 9y agohttps://codex.wordpress.org/Rewrite_API https://codex.wordpress.org/Rewrite_API What you are saying is, on it's own, true. It's also a solved problem for WP.
- runako 9y agoAccording to Netcraft, 21% of the sites on the public Internet run Apache: https://news.netcraft.com/archives/2017/07/20/july-2017-web-server-survey.html https://news.netcraft.com/archives/2017/07/20/july-2017-web-... There are lots of legit reasons to run Apache: - it works like a champ - it's widely known - it's got a big ecosystem (plugins, etc.) - it has a fairly complete WebDAV implementation - it's widely supported TL;DR "legacy" sometimes means "good" and not just "old."
- pmlnr 9y agoYeah, right. It's also still prone to slowloris and you can take down a shared hosting server with a laptop in a coffee store. In this case legacy is either "I don't know anything else", "well it worked so far" or "meh".
- delias_ 9y agoRunning apache in front of tomcat is still a very common pattern. Mostly due to connection handling and configuration around it.
- Blackthorn 9y agoNo other server implements complete support for server side includes.
- pmlnr 9y agonginx with lua or perl module?
- Blackthorn 9y agoPlease explain exactly how that provides complete support for the server side includes standard.
- drzaiusapelord 9y agoAlmost every DO, vultr, Linode, etc guide I've seen for LAMP server config uses Apache. I also suspect apache, being the old guard, is the defacto standard in various appliances, routers, firewalls, IoT, etc devices. Its our generation's BIND. Its probably never going away, even if better competitors come and go. As far as stats go, according to netcraft MS's IIS is leading with Apache second and nginx a distant third. Of course, this data isn't terribly reliable as netcraft can only see front ends, which may hide whats behind the load balancer, but IIS/Apache are still kings.
- hannob 9y agoApache is the standard solution in web hosting. Its "killer feature" are htaccess files. It provides a possibility to give users a limited way to configure their virtual hosts, without giving them too much power. (Unfortunately there are some unfixed systemic security issues with that, namely symlink attacks...)
- wolco 9y agoSpeed is one of the reasons to stay on apache. Using nginx to serve static and using php_mod vs fpm-php will be faster as long as you disable directory level .htaccess
- pmlnr 9y agoIf you're using php-fpm over unix socket, I doubt this is true, please show some stats.
- Veratyr 9y agoDoes this apply to anything other than PHP? Not saying it's not significant, just curious. Does mod_wsgi outperform uwsgi with uwsgi_pass for example?
- Thaxll 9y agoNginx is faster than Apache, you're talking about PHP which is very different. php-fpm is not part of Nginx.
- xorcist 9y agoNginx should be faster in theory, but it's kind of hard to show in practice as the actual http parsing is just so much faster than anything else. You have to really tune them for for benchmark scenarios to see any kind of difference. What your vendor supports and what you are most comfortable with configuring should decide which one you run. PHP, as you say, is something else entirely. It's so much slower than your http server so the latter doesn't matter at all.
- oxguy3 9y agoIt's still a really nice web server. Easy to configure, incredibly reliable, twenty years of security fixes under its belt, endless docs/info available for it online. I've been meaning to learn nginx for a while, but with Apache working just fine, it doesn't feel very urgent. Besides Apache and nginx, there aren't really any servers I'd trust for production use. Conceptually, I really like what Caddy is doing, but it's simply too young, not to mention the concerns that came up when Let's Encrypt had an outage back in May: https://github.com/mholt/caddy/issues/1680 https://github.com/mholt/caddy/issues/1680
- mholt 9y agoThe concerns about Caddy handling an ACME server outage are not really well founded these days, because: 1) Caddy has the most robust OCSP implementation of any web server. It caches staples locally and refreshes them halfway through the validity period so it can endure days-long OCSP responder outages. 2) Even if a certificate needs to be renewed while the ACME server is down, Caddy can endure 2-to-3-week-long outages of the ACME server because it renews 30 days out from expiration and tries twice per day until it succeeds, logging its actions along the way. And because Caddy is written in Go, memory leaks like what Apache suffers are much less likely, if not impossible. (Source: I implemented it.)
- stephenr 9y ago> 1)... Two calls to OpenSSL and a few lines of shell script will fetch staples from LE whenever I want (ie more often than your defaults that have caused problems before) for HAProxy to serve. How's that for robust. >2)... great so you're as reliable as.. any other LE client that tries to renew before expiry, but without the ability to choose when to renew certs?
- mholt 9y ago1) Caddy has never had OCSP outage problems. When LE's OCSP responders went down for a day a few months ago, Caddy was the ONLY server that kept sites online (unless nginx was explicitly configured for it; almost all Apache sites with it went down, including gnu.org). 2) Ours is the only LE client built directly into the web server, so "reliability" isn't really a comparable factor. By doing renewals automatically, Caddy's HTTPS implementation is more reliable and robust than doing it manually.
- jimjag 9y agoLots of reasons. First of all, it is fast and reliable. The choice of MPMs allow for sys-admins to choose exactly how they want httpd to scale. Unparalleled RFC compliance. Load balancing with dynamic, runtime configuration. Failover. .htaccess file. Full support for FPM/FastCGI. Fully Open Source and community driven (not Open Core). mod_rewrite capability. Hundreds of modules for almost every and all situation. Most people simply take the "lazy" route and not even investigate httpd, instead relying on the FUD about much older versions (you still get, for example, the screed that "Apache forks off a new process for each request")... Apache httpd 2.4 is just as fast and reliable as any other web-server out there, nginx included. It's just not seen as the "cool and hip" web-server. I guess some people are more concerned about marketing.
- tannhaeuser 9y agoAre you kidding? Apache is by far the most used web server for dynamic content-driven sites. It's "killer" feature is its robustness, in particular for (shared or otherwise) CGI hosting (and PHP hosting, of course). Outside the web app bubble, CGIs eg. per-request process spawning isn't a performance problem at all when you're using caching, which Apache httpd conveniently provides with mod_cache; mod_cache, unlike eg. Varnish and other dedicated caching solutions, has full RFC7324 caching with re-validation, not just "Expires:". Apache httpd in many ways is a much more complete web server solution compared to, say, nginx (which I like as well). I'm prefering Apache httpd for the depth of available documentation alone, because everything is developed openly, C source is accessible and not hard to develop with, and because of the breadth of available options (certbot/letsencrypt/acme reference implementation on Apache, WebDAV, clustering etc. etc.).
- joosters 9y agoIt's pretty robust these days and is battle-hardened by the many attacks on it. Plus it has support for just about everything under the sun - that is, if someone has written something that extends or relies upon a web server, there will almost certainly be apache support. (And I'm writing this as a dev who worked on a competing web server which IM-biased-O was vastly better :)
- liveoneggs 9y agoa popular CDN vendor has noted that SSL with apache was faster than nginx at very large scale (although was later replaced with something else).
- AndyMcConachie 9y agoI use Apache all the time. It's great software. It's kept up to date and it works for everything I want it to work with. This idea that because it's old and not hip therefore it's use is questionable is kinda dumb. I was disappointed when OBSD wrote their own httpd that was initially filled with stupid bugs. If it ain't broke don't fix it.
- jlgaddis 9y agoI use Apache specifically on shared web servers in order to run each customer's web site under a separate uid/gid (for security purposes). I use it on other $work web servers just for consistency/ease of management (performance isn't an issue). Mostly I use it because, after probably 20 years or so, I'm quite comfortable with and accustomed to it. That said, I have started putting a few of my own web sites on nginx just to try it out a bit and get some familiarity with it.