4 ms·
How many Billions of visitors you need, until a local .htaccess slows down your Website significant ?
by prottmann 13y ago
How many Billions of visitors you need, until a local .htaccess slows down your Website significant ?
- laumars 13y agoIt's not just dependant on traffic, other factors include: o How deep the page request is (as Apache cascades it's checks down the directory structure, so /article/year/month/day/page.html could look for a .htaccess file in 4 different locations before even reaching /.htaccess. o The IOPS of your storage (super fast SSD, slower NFS server, SAN? etc) o And whether your host OS has done any file caching (dependant on if a file exists and if it's been modified outside of the OS, in the case of network mounted file systems) So the only way to know precisely would be to benchmark (a basic load test should suffice). However if you're running a blog on a VPS and you occasionally have articles hit HN and other aggregators, then disabling .htaccess (amongst other free tweaks) could be enough to prevent your site getting DDoS'ed offline if/when you hit the front page.
- dave1010uk 13y agoVery rough benchmarks running "ab" against a random page on localhost: with AllowOverride 215rps without AllowOverride 245rps It makes a difference, but there's not enough data to conclude much.
- m3mnoch 13y agoso, what you're saying here is that if you skip the ease and convenience of .htaccess files, you can get better performance? as in, if you get slasdotted (ha! i'm old!) your site will stay up either way as long as you're getting less than 215 rps. and it goes down either way if you're getting more than 245 rps. that's a pretty tiny window in the grand scheme of things. yeah... i'd rather my personal site be easier to maintain. and, as to the security of it -- if you have access to the httpd.conf file, i GUARANTEE you've got bigger holes in your own hodge-podge, whole-system security than something like an .htaccess file on which you'd have to work really hard and explicitly make insecure. just sayin'.
- laumars 13y ago> as in, if you get slasdotted (ha! i'm old!) your site will stay up either way as long as you're getting less than 215 rps. and it goes down either way if you're getting more than 245 rps. that's a pretty tiny window in the grand scheme of things. 12% performance boost is actually quite a significant jump when you're pushing heavy traffic and looking to shave any fat from the stack you can find. Also your comment about "and it goes down either way if you're getting more than 245 rps" doesn't really make a whole lot of sense as the webfarm isn't going to magically crash the moment you get one request more. I suspect you're not really understanding what those ab results are representing, but that doesn't really matter as I wouldn't trust those figures for any real world usage anyway. As I pointed out in another post in this thread, the actual performance penalty will be subject to a considerable number variables. > and, as to the security of it -- if you have access to the httpd.conf file, i GUARANTEE you've got bigger holes in your own hodge-podge, whole-system security than something like an .htaccess file on which you'd have to work really hard and explicitly make insecure. You have things completely backwards there. httpd.conf is more secure than .htaccess because httpd.conf can only be amended and actioned by root where as .htaccess will have lower security permissions and is loaded on demand (ie an attacker doesn't need to restart the Apache daemon to action any changes).
- m3mnoch 13y ago> I suspect you're not really understanding what those ab results are representing ah. no, no. i'm not adequately explaining where i was going with that. lemme try again. 1) it's not 12% on a web farm. it's 12% on one server. 2) that 12% manifests in a slowly degrading experience. so, it takes 4 seconds to return during peak traffic instead of 3 and a half. meh. whatever. therefore, if you get hit by something that will actually make a difference, it's not going to be within 12%. it's going to be like 12,000%. so, it's not going to make a whit of difference at that point whether you have httpd.conf or .htaccess. >You have things completely backwards there again, i'm not explaining myself well. i fully understand that, in theory, httpd.conf is more secure. i'm not talking about that. if you have access to httpd.conf, you also probably have access to /etc/ssh/sshd_config -- did you configure that securely? does your server allow root logins? what about your mysql config? what about the latest security update to the distro? i'm just saying, if you've got access to httpd.conf, you've got the whole server. that means you've probably got bigger fish to fry as to worrying about security than a pretty harmless, defaulted as secure, .htaccess file.