<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #357: nginx research</title>
    <link>http://localhost:8080/trac/ticket/357</link>
    <description>&lt;p&gt;
Looking into replacing apache with nginx by testing it on the dev server.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/357</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 12 Oct 2011 13:33:49 GMT</pubDate>
      <title>milestone set</title>
      <link>http://localhost:8080/trac/ticket/357#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;milestone&lt;/strong&gt;
                set to &lt;em&gt;Phase 5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Wed, 12 Oct 2011 13:59:34 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/357#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:2</guid>
      <description>
        &lt;p&gt;
As I mentioned I've set myself up a low-end Linode so I can play and consolidate my hosting away from a shared environment.
&lt;/p&gt;
&lt;p&gt;
In my travels I've found 'Barracuda' which is a meaty script that took my empty Debian 6 server and got NGINX, PHP-FPM, memcache, a fire wall and bunch of other handy stuff... Now most of that is pointless for here but thought you might want to take a gander at the script that set it up so you can see what's what with regards to NGINX and PHP-FPM config: &lt;a class="ext-link" href="http://drupal.org/project/barracuda"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/barracuda&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Also, as mentioned, there's &lt;a class="ext-link" href="http://groups.drupal.org/nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://groups.drupal.org/nginx&lt;/a&gt; with lots of people and information.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 20 Oct 2011 10:18:31 GMT</pubDate>
      <title>hours, status, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;accepted&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The pages are now available via nginx:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
I'll next look at setting up munin before I look at making the (far more compicated) other virtualhosts work with nginx.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 20 Oct 2011 16:30:59 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:4</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.5&lt;/em&gt; to &lt;em&gt;0.7&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have added some munin monitoring for nginx and we should start to get some stats here:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 21 Oct 2011 12:06:24 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.6&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.7&lt;/em&gt; to &lt;em&gt;2.3&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
PHP-FPM, following &lt;a class="ext-link" href="http://fak3r.com/geek/howto/howto-install-php5-fpm-on-debian-squeeze/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://fak3r.com/geek/howto/howto-install-php5-fpm-on-debian-squeeze/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Add this to &lt;tt&gt;/etc/apt/sources.list&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;deb http://packages.dotdeb.org squeeze all
deb-src http://packages.dotdeb.org squeeze all
&lt;/pre&gt;&lt;pre class="wiki"&gt;cd
gpg --keyserver keys.gnupg.net --recv-key 89DF5277
gpg -a --export 89DF5277 | sudo apt-key add -
aptitude update
aptitude safe-upgrade
 The following NEW packages will be installed:
   nginx-common{a} nginx-light{a}
 The following packages will be upgraded:
   libapache2-mod-php5 libmysqlclient16 mysql-client-5.1 mysql-common mysql-server mysql-server-5.1
   mysql-server-core-5.1 nginx php-pear php5 php5-cli php5-common php5-curl php5-dev php5-gd
   php5-imagick php5-mcrypt php5-memcache php5-mysql php5-suhosin
&lt;/pre&gt;&lt;p&gt;
With a new LAMP stack all the config files need updating, the old ones were backed up, new ones installed and diffs were done, these were the changes to &lt;tt&gt;/etc/php5/apache2/php.ini&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;expose_php = Off
memory_limit = 256M
post_max_size = 128M
default_charset = "utf-8"
upload_max_filesize = 100M
max_file_uploads = 50
default_socket_timeout = 120
extension=uploadprogress.so
session.cookie_secure = 1
mbstring.http_input = pass
mbstring.http_output = pass
&lt;/pre&gt;&lt;p&gt;
Things that we had in the old php.ini which I'm note sure if we need in the new one:
&lt;/p&gt;
&lt;pre class="wiki"&gt;output_buffering = Off
serialize_precision = 100
variables_order = "EGPCS"
register_long_arrays = On
register_argc_argv = On
cgi.nph = 1
cgi.fix_pathinfo=0
&lt;/pre&gt;&lt;p&gt;
nginx and php still need more work to get them working...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 21 Oct 2011 12:08:16 GMT</pubDate>
      <title>priority changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:6</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;priority&lt;/strong&gt;
                changed from &lt;em&gt;major&lt;/em&gt; to &lt;em&gt;blocker&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Oh, I see that the PHP upgrade has broken &lt;a class="ext-link" href="http://dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org/&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;Parse error: syntax error, unexpected T_SL in /web/dev.transitionnetwork.org.webarch.net/www/sites/all/modules/imageapi/imageapi_imagemagick.module on line 152
&lt;/pre&gt;&lt;p&gt;
I'll look at fixing this before looking at &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/364" title="maintenance: Migrate from SVN to Git (closed: fixed)"&gt;ticket:364&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 21 Oct 2011 12:14:49 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:7</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:7</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.3&lt;/em&gt; to &lt;em&gt;2.4&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Actually it's a diff in the code in &lt;tt&gt;/web/dev.transitionnetwork.org.webarch.net/www/sites/all/modules/imageapi/imageapi_imagemagick.module&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; .mine
  setlocale(LC_CTYPE, "en_GB.UTF-8");
=======
  // LANG added by chris for UTF-8 filenames
  setlocale(LC_CTYPE, "en_GB.UTF-8");
&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; .r224
&lt;/pre&gt;&lt;p&gt;
I have fixed the for the dev server but not committed it.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 16 Jan 2012 11:31:35 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:8</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:8</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.4&lt;/em&gt; to &lt;em&gt;2.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:3" title="Comment 3 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The pages are now available via nginx:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
The new certs and debian upgrades produced some error messages:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Nginx 'soft' update failed, doing restart
Starting nginx: nginx: [emerg] SSL_CTX_use_certificate_chain_file("/etc/ssl/transitionnetwork.org/transitionnetwork.org.crt") failed (SSL: error:0906D066:PEM routines:PEM_read_bio:bad end line error:140DC009:SSL routines:SSL_CTX_use_certificate_chain_file:PEM lib)
nginx: configuration file /etc/nginx/nginx.conf test failed
invoke-rc.d: initscript nginx, action "start" failed.
dpkg: error processing nginx-light (--configure):
 subprocess installed post-installation script returned error exit status 1
dpkg: dependency problems prevent configuration of nginx:
 nginx depends on nginx-full | nginx-light; however:
  Package nginx-full is not installed.
  Package nginx-light is not configured yet.
dpkg: error processing nginx (--configure):
 dependency problems - leaving unconfigured
&lt;/pre&gt;&lt;p&gt;
So I'm surprised that nginx is still running on the dev server, I have put the errors here so they can be investigated next time this ticket is worked on.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 09 Mar 2012 14:37:28 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:9</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:9</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.3&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.5&lt;/em&gt; to &lt;em&gt;2.8&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Following the last certificate update nginx on the dev server has been broken:
&lt;/p&gt;
&lt;pre class="wiki"&gt;/etc/init.d/nginx start
Starting nginx: nginx: [emerg] SSL_CTX_use_certificate_chain_file("/etc/ssl/transitionnetwork.org/transitionnetwork.org.crt") failed (SSL: error:0906D066:PEM routines:PEM_read_bio:bad end line error:140DC009:SSL routines:SSL_CTX_use_certificate_chain_file:PEM lib)
nginx: configuration file /etc/nginx/nginx.conf test failed
&lt;/pre&gt;&lt;p&gt;
This was fixed thus:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/ssl/transitionnetwork.org/
wget http://crt.gandi.net/GandiStandardSSLCA.crt
wget http://crt.usertrust.com/UTNAddTrustServer_CA.crt
wget http://crt.usertrust.com/AddTrustExternalCARoot.crt
openssl x509 -inform DER -in GandiStandardSSLCA.crt -out GandiStandardSSLCA.pem
openssl x509 -inform DER -in AddTrustExternalCARoot.crt -out AddTrustExternalCARoot.pem
openssl x509 -inform DER -in UTNAddTrustServer_CA.crt -out UTNAddTrustServer_CA.pem
cat transitionnetwork.org.crt &amp;gt; gandi.pem
cat GandiStandardSSLCA.pem &amp;gt;&amp;gt; gandi.pem
cat AddTrustExternalCARoot.pem &amp;gt;&amp;gt; gandi.pem
cat UTNAddTrustServer_CA.pem &amp;gt;&amp;gt; gandi.pem
cat transitionnetwork.org.crt gandi.pem &amp;gt; transitionnetwork.org.chained.pem
&lt;/pre&gt;&lt;p&gt;
And &lt;tt&gt;/etc/nginx/sites-available/kiwi&lt;/tt&gt; was edited:
&lt;/p&gt;
&lt;pre class="wiki"&gt;#ssl_certificate  /etc/ssl/transitionnetwork.org/transitionnetwork.org.crt;
ssl_certificate  /etc/ssl/transitionnetwork.org/transitionnetwork.org.chained.pem;
&lt;/pre&gt;&lt;p&gt;
So now Nginx is working again for this site:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
And the next task is to enable all the other sites on the server, one at a time, till they are all running and then we can switch the ports around and turn apache off.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 15 Mar 2012 12:24:36 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:10</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:10</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.8&lt;/em&gt; to &lt;em&gt;2.95&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Working through each domain name at a time enabling all the services, last year kiwi.transitionnetwork.org was set up to work via nginx:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
And Munin is available via nginx:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/munin/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/munin/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
However /info/ and /phpmyadmin and /apc_info.php don't yet work:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/phpmyadmin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/phpmyadmin&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/apc_info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/apc_info.php&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
So I'm going to work on enabling them to start with.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 15 Mar 2012 13:46:55 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:11</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:11</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.95&lt;/em&gt; to &lt;em&gt;4.15&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
One issue I have just realised that we had with the current setup with varnish, these pages (used by Munin to generate graphs), the second of which displays client's IP addresses (when clients use HTTPS) are set to only be available to the localhost via apache:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8080/apc_info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8080/apc_info.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8080/server-status"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8080/server-status&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
However they were available via varnish to anyone:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org/apc_info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org/apc_info.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org/server-status"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org/server-status&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
I have fixed this on the live and dev server by adding these rules to the varnish config at &lt;tt&gt;/etc/varnish/default.vcl&lt;/tt&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;acl local {
  "localhost";         // myself
  "127.0.0.1";         // myself
  "81.95.52.78";       // this machines main ip address
  "81.95.52.79";       // this machines 2nd ip address
  "81.95.52.80";       // this machines 3rd ip address
}
    ## Pass cron jobs and server-status
    if (req.url ~ "cron.php") {
      if (client.ip ~ local) {
        return (pass);
      }
      else {
        error 403 "Access Denied";
      }
    }
    if (req.url ~ "/server-status$") {
      if (client.ip ~ local) {
        return (pass);
      }
      else {
        error 403 "Access Denied";
      }
    }
    if (req.url ~ "apc_info.php") {
      if (client.ip ~ local) {
        return (pass);
      }
      else {
        error 403 "Access Denied";
      }
    }
&lt;/pre&gt;&lt;p&gt;
The varnish documentation has been updated to match the current configuration, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/DevelopmentServer#Varnish"&gt;wiki:DevelopmentServer#Varnish&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/NewLiveServer#varnish"&gt;wiki:NewLiveServer#varnish&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 15 Mar 2012 16:37:55 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:12</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:12</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.15&lt;/em&gt; to &lt;em&gt;5.65&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Enabling PHP and nginx, the notes previously followed in &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/357#comment:5" title="maintenance: nginx research (closed: fixed)"&gt;ticket:357#comment:5&lt;/a&gt;  have moved to &lt;a class="ext-link" href="http://fak3r.com/2011/09/27/howto-install-php5-fpm-on-debian-squeeze/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://fak3r.com/2011/09/27/howto-install-php5-fpm-on-debian-squeeze/&lt;/a&gt; also following the notes here, &lt;a class="ext-link" href="http://www.webhostingtalk.com/showthread.php?t=1025286"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.webhostingtalk.com/showthread.php?t=1025286&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;aptitude install php5-fpm
  The following NEW packages will be installed:
    php5-fpm
  Creating config file /etc/php5/fpm/php.ini with new version
&lt;/pre&gt;&lt;p&gt;
Start it:
&lt;/p&gt;
&lt;pre class="wiki"&gt;/etc/init.d/php5-fpm start
&lt;/pre&gt;&lt;p&gt;
Check it's running:
&lt;/p&gt;
&lt;pre class="wiki"&gt;netstat -plunt|grep php
tcp        0      0 127.0.0.1:9000          0.0.0.0:*               LISTEN      31616/php-fpm.conf)
&lt;/pre&gt;&lt;p&gt;
Add this to &lt;tt&gt;/etc/nginx/sites-available/kiwi&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;location ~ \.php$ {
      fastcgi_pass 127.0.0.1:9090;
      fastcgi_index index.php;
      fastcgi_param SCRIPT_FILENAME /web/kiwi.webarch.net/www$fastcgi_script_name;
      include fastcgi_params;
}
&lt;/pre&gt;&lt;p&gt;
But the php files result in:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
502 Bad Gateway
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
And this in &lt;tt&gt;/var/log/nginx/error.log&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;2012/03/15 15:56:05 [error] 2763#0: *2 connect() failed (111: Connection refused) while connecting to upstream, client: XX.XX.XX.XX, server: kiwi.transitionnetwork.org, request: "GET /info/php-info.php HTTP/1.1", upstream: "fastcgi://127.0.0.1:9090", host: "kiwi.transitionnetwork.org:4430"
&lt;/pre&gt;&lt;p&gt;
I tried editing the list of allowed hosts, &lt;tt&gt;/etc/php5/fpm/pool.d/www.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;listen.allowed_clients = 127.0.0.1,81.95.52.78,kiwi.transitionnetwork.org,kiwi.webarch.net
&lt;/pre&gt;&lt;p&gt;
I have read a lot of google results but have yet to find an answer to this problem, will pick this up again tomorrow...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 16 Mar 2012 11:19:09 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:13</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:13</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;5.65&lt;/em&gt; to &lt;em&gt;5.9&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
My bad, &lt;tt&gt;/etc/php5/fpm/pool.d/www.conf&lt;/tt&gt; had port 9000 in it not port 9090, fixed:
&lt;/p&gt;
&lt;pre class="wiki"&gt;listen = 127.0.0.1:9090
&lt;/pre&gt;&lt;p&gt;
Added a &lt;tt&gt;root&lt;/tt&gt; directive to the .php section as &lt;a class="ext-link" href="http://forum.nginx.org/read.php?3,222813"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;suggested here&lt;/a&gt; to get php scripts working:
&lt;/p&gt;
&lt;pre class="wiki"&gt;location ~ \.php$ {
      fastcgi_pass 127.0.0.1:9090;
      fastcgi_index index.php;
      fastcgi_param SCRIPT_FILENAME /web/kiwi.webarch.net/www$fastcgi_script_name;
      include fastcgi_params;
      root   "/web/kiwi.webarch.net/www";
}
&lt;/pre&gt;&lt;p&gt;
Now these work:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:8080/apc_info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:8080/apc_info.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/apc_info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/apc_info.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/php-info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/php-info.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/apc.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/apc.php&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
And I think that wraps it up for nginx doing everything apache does for the kiwi.transitionnetwork.org domain, 1 down, quite a few to go!
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 16 Mar 2012 12:30:19 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:14</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:14</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.34&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;5.9&lt;/em&gt; to &lt;em&gt;6.24&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Getting Piwik running with nginx, apache config here &lt;tt&gt;/etc/apache2/sites-enabled/03-piwik.transitionnetwork.org&lt;/tt&gt;, nginx config here &lt;tt&gt;/etc/nginx/sites-available/piwiw&lt;/tt&gt;, initially created as a copy of &lt;tt&gt;/etc/nginx/sites-available/default.dpkg-dist&lt;/tt&gt;, referencing &lt;a class="ext-link" href="http://wiki.nginx.org/MediaWiki"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.nginx.org/MediaWiki&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
These lines were edited, initially to get it working without HTTPS:
&lt;/p&gt;
&lt;pre class="wiki"&gt;        listen    8080;
        root /web/piwik.transitionnetwork.org/piwik;
        index index.php;
        server_name piwik.transitionnetwork.org piwik.transitionnetwork.org.webarch.net;
        root /web/piwik.transitionnetwork.org/piwik;
        index index.php;
        # Make site accessible from http://localhost/
        server_name piwik.transitionnetwork.org piwik.transitionnetwork.org.webarch.net;
        client_max_body_size 5m;
        client_body_timeout 60;
        # see http://wiki.nginx.org/MediaWiki
        location / {
                try_files $uri $uri/ @rewrite;
        }
        location @rewrite {
                rewrite ^/(.*)$ /index.php?title=$1&amp;amp;$args;
        }
        location ^~ /maintenance/ {
                return 403;
        }
        location ~ \.php$ {
                include fastcgi_params;
                fastcgi_pass unix:/tmp/phpfpm.sock;
        }
        location ~ \.php$ {
                fastcgi_pass 127.0.0.1:9090;
                fastcgi_index index.php;
                fastcgi_param SCRIPT_FILENAME /web/piwik.transitionnetwork.org/piwik$fastcgi_script_name;
                include fastcgi_params;
                root   "/web/kiwi.webarch.net/www";
        }
        location ~* \.(js|css|png|jpg|jpeg|gif|ico)$ {
                try_files $uri /index.php;
                expires max;
                log_not_found off;
        }
        location = /_.gif {
                expires max;
                empty_gif;
        }
        location ^~ /cache/ {
                deny all;
        }
&lt;/pre&gt;&lt;p&gt;
Make the config available and restart
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/nginx/sites-enabled
ln -s ../sites-available/piwik 02-piwik
/etc/init.d/nginx restart
  Restarting nginx: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
  nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
  nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
  nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
  nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
  nginx: [emerg] still could not bind()
  nginx.
&lt;/pre&gt;&lt;p&gt;
So, something isn't right, I'll come back to the later after looking at &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/401" title="defect: Intransitionmovie.com errors with Google and Paypal (closed: fixed)"&gt;ticket:401&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 16 Mar 2012 14:15:47 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:15</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:15</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.17&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;6.24&lt;/em&gt; to &lt;em&gt;6.41&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Several mistakes in the server config were fixed and now the mediawiki site is available (unencrypted) via nginx at &lt;a class="ext-link" href="http://wiki.dev.transitionnetwork.org:8080/Main_Page"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.dev.transitionnetwork.org:8080/Main_Page&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;server {
        listen    8000;
        #listen   80; ## listen for ipv4; this line is default and implied
        #listen   [::]:80 default_server ipv6only=on; ## listen for ipv6
        root /web/wiki.dev.transitionnetwork.org/www;
        index index.php;
        # Make site accessible from http://localhost/
        server_name wiki.dev.transitionnetwork.org wiki.dev.transitionnetwork.org.webarch.net;
        client_max_body_size 5m;
        client_body_timeout 60;
        # see http://wiki.nginx.org/MediaWiki
        location / {
                try_files $uri $uri/ @rewrite;
        }
        location @rewrite {
                rewrite ^/(.*)$ /index.php?title=$1&amp;amp;$args;
        }
        location ^~ /maintenance/ {
                return 403;
        }
        location ~ \.php$ {
                include fastcgi_params;
                fastcgi_pass unix:/tmp/phpfpm.sock;
        }
        location ~ \.php$ {
                fastcgi_pass 127.0.0.1:9090;
                fastcgi_index index.php;
                fastcgi_param SCRIPT_FILENAME /web/wiki.dev.transitionnetwork.org/www$fastcgi_script_name;
                include fastcgi_params;
                root   "/web/wiki.dev.transitionnetwork.org/www";
        }
        location ~* \.(js|css|png|jpg|jpeg|gif|ico)$ {
                try_files $uri /index.php;
                expires max;
                log_not_found off;
        }
        location = /_.gif {
                expires max;
                empty_gif;
        }
        location ^~ /cache/ {
                deny all;
        }
}
&lt;/pre&gt;&lt;p&gt;
Next task to make it available via https.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 20 Mar 2012 14:39:33 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:16</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:16</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;4.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;6.41&lt;/em&gt; to &lt;em&gt;10.41&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
All the nginx config is being revisited, been reading &lt;a class="ext-link" href="http://michael.lustfield.net/content/dummies-guide-nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://michael.lustfield.net/content/dummies-guide-nginx&lt;/a&gt; &lt;a class="ext-link" href="http://blog.martinfjordvald.com/2010/07/nginx-primer/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://blog.martinfjordvald.com/2010/07/nginx-primer/&lt;/a&gt; &lt;a class="ext-link" href="http://blog.martinfjordvald.com/2011/02/nginx-primer-2-from-apache-to-nginx/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://blog.martinfjordvald.com/2011/02/nginx-primer-2-from-apache-to-nginx/&lt;/a&gt; &lt;a class="ext-link" href="https://nealpoole.com/blog/2011/04/setting-up-php-fastcgi-and-nginx-dont-trust-the-tutorials-check-your-configuration/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://nealpoole.com/blog/2011/04/setting-up-php-fastcgi-and-nginx-dont-trust-the-tutorials-check-your-configuration/&lt;/a&gt; and &lt;a class="ext-link" href="http://wiki.nginx.org/Pitfalls"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.nginx.org/Pitfalls&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Changing php5-fpm to use a socket rather than tcp, create a dir for the sock file:
&lt;/p&gt;
&lt;pre class="wiki"&gt;mkdir /var/run/php5-fpm
chown www-data:www-data /var/run/php5-fpm
&lt;/pre&gt;&lt;p&gt;
Edit &lt;tt&gt;/etc/php5/fpm/pool.d/www.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[www]
user = www-data
group = www-data
listen = /var/run/php5-fpm/phpfpm.sock
listen.owner = www-data
listen.group = www-data
listen.mode = 0666
listen.allowed_clients = 127.0.0.1,81.95.52.78,kiwi.transitionnetwork.org,kiwi.webarch.net
pm = dynamic
pm.max_children = 5
pm.start_servers = 2
pm.min_spare_servers = 1
pm.max_spare_servers = 3
chdir = /
&lt;/pre&gt;&lt;p&gt;
Security fix, see &lt;a class="ext-link" href="https://nealpoole.com/blog/2011/04/setting-up-php-fastcgi-and-nginx-dont-trust-the-tutorials-check-your-configuration/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://nealpoole.com/blog/2011/04/setting-up-php-fastcgi-and-nginx-dont-trust-the-tutorials-check-your-configuration/&lt;/a&gt; edit &lt;tt&gt;/etc/php5/fpm/php.ini&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cgi.fix_pathinfo=0
&lt;/pre&gt;&lt;p&gt;
These are working:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/munin/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/munin/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/apc.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/apc.php&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/php-info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/php-info.php&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
This needs more work:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/phpmyadmin/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/phpmyadmin/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 21 Mar 2012 13:13:17 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:17</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:17</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.81&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;10.41&lt;/em&gt; to &lt;em&gt;12.22&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
kiwi.transitionnetwork.org is now fully working with nginx (config file &lt;tt&gt;/etc/nginx/sites-available/kiwi&lt;/tt&gt;) and I'm fairly confident that it's been set up to be as secure as possible, the configuration still needs documenting on this wiki, but the config file itself has lots of comments, these things are available on this domain:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/&lt;/a&gt; - server front page / documentation
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/apc_info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/apc_info.php&lt;/a&gt; - script for apc munin stats, only available from localhost
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/munin/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/munin/&lt;/a&gt; - munin stats
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/info/php-info.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/info/php-info.php&lt;/a&gt; - php info (password protected)
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://kiwi.transitionnetwork.org:8000/info/apc.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org:8000/info/apc.php&lt;/a&gt; - apc info (password protected)
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://kiwi.transitionnetwork.org:4430/phpmyadmin/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org:4430/phpmyadmin/&lt;/a&gt; - phpmyadmin (password protected)
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Next to sort these out:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://static.dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://static.dev.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://piwik.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://piwik.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://wiki.dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.dev.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://test.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://test.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://news.dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://news.dev.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 21 Mar 2012 14:37:05 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:18</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:18</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.4&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;12.22&lt;/em&gt; to &lt;em&gt;12.62&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:17" title="Comment 17 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Next to sort these out:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://static.dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://static.dev.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
Done, config file &lt;tt&gt;/etc/nginx/sites-available/static&lt;/tt&gt;:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://static.dev.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://static.dev.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://static.dev.transitionnetwork.org:8000/ttcon2010/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://static.dev.transitionnetwork.org:8000/ttcon2010/&lt;/a&gt; - 2010 conference static files
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://static.dev.transitionnetwork.org:4430/ttcon2010/private"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://static.dev.transitionnetwork.org:4430/ttcon2010/private&lt;/a&gt; - private files from the conference
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
More to follow tomorrow...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 22 Mar 2012 13:35:11 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:19</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:19</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;12.62&lt;/em&gt; to &lt;em&gt;12.72&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
These two sites are going to be very time consuming to migrate due to the number of rewrite rules (98 lines of apache config containing the word &lt;tt&gt;Rewrite&lt;/tt&gt;), I wonder if we shouldn't keep apache just for these and use nginx as a reverse proxy for these domains.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2010.archive.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2010.archive.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 22 Mar 2012 17:00:48 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:20</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:20</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;3.3&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;12.72&lt;/em&gt; to &lt;em&gt;16.02&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have done a load of work on a secure Mediawiki nginx config, but it's still not totally working and I'm not happy with it yet, hopefully I'll complete this tomorrow.
&lt;/p&gt;
&lt;p&gt;
References:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://wiki.nginx.org/MediaWiki"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.nginx.org/MediaWiki&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://blog.bigdinosaur.org/mediawiki-on-nginx/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://blog.bigdinosaur.org/mediawiki-on-nginx/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 23 Mar 2012 14:47:55 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:21</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:21</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.56&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;16.02&lt;/em&gt; to &lt;em&gt;17.58&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Did a lot of work on the wiki config, got things that didn't work that were suggested here  &lt;a class="ext-link" href="http://blog.bigdinosaur.org/mediawiki-on-nginx/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://blog.bigdinosaur.org/mediawiki-on-nginx/&lt;/a&gt; working but then a combination of a really poor ADSL connection and god knows what resulted in the config file I was working on getting deleted, so I'll have to start again next week, really sorry about this :-(
&lt;/p&gt;
&lt;p&gt;
I did lean more about nginx in the process though...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 23 Mar 2012 21:38:10 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:22</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:22</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;17.58&lt;/em&gt; to &lt;em&gt;17.68&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:21" title="Comment 21 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
a combination of a really poor ADSL connection and god knows what
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The high load on kiwi making vim (the text editor I use) really unresponsive, which I mistook for connection problems (which we have been having at work) and my fustration at not being able to get stuff done as a result is probably what...
&lt;/p&gt;
&lt;p&gt;
The thing which took ages to figure out was this code from &lt;a class="ext-link" href="http://blog.bigdinosaur.org/mediawiki-on-nginx/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://blog.bigdinosaur.org/mediawiki-on-nginx/&lt;/a&gt; which doesn't work:
&lt;/p&gt;
&lt;pre class="wiki"&gt;#    Force potentially-malicious files in the /images directory to be served
#    with a text/plain mime type, to prevent them from being executed by
#    the PHP handler
  location ~* ^/images/.*.(html|htm|shtml|php)$ {
      types { }
      default_type text/plain;
  }
&lt;/pre&gt;&lt;p&gt;
It's &lt;strong&gt;a very good idea&lt;/strong&gt; to do this for any directory where users can upload files so I was keen to get it sorted so it could be used for other applications.
&lt;/p&gt;
&lt;p&gt;
The code above simply does &lt;em&gt;nothing&lt;/em&gt;, I'm not exactly sure why as the regex would be OK for apache, I haven't got to the bottom of &lt;em&gt;why&lt;/em&gt; the above doesn't work.
&lt;/p&gt;
&lt;p&gt;
The solution I finally got working was, in essence, this:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  location ^~ /images/ {
      types {
        text/plain    htm html shtml php php5;
         image/gif    gif;
         # ...
         # whitelist here of all file types allowed to be uploaded,
         # see LocalSettings.php for a list
      }
      try_files $uri /index.php;
  }
&lt;/pre&gt;&lt;p&gt;
It won't take long on Monday to recreate the file that got deleted.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 26 Mar 2012 12:18:10 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:23</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:23</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;2.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;17.68&lt;/em&gt; to &lt;em&gt;19.68&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:22" title="Comment 22 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
It won't take long on Monday to recreate the file that got deleted.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I spent a couple of hours on this today, before I was interupted by a power outage in the office, I should get mediawiki sorted tomorrow.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 27 Mar 2012 12:55:48 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:24</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:24</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;4.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;19.68&lt;/em&gt; to &lt;em&gt;23.68&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have finally wrapped up Mediawiki on nginx:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://wiki.dev.transitionnetwork.org:8000/Main_Page"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.dev.transitionnetwork.org:8000/Main_Page&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://wiki.dev.transitionnetwork.org:4430/Main_Page"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.dev.transitionnetwork.org:4430/Main_Page&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
All logins are redirected to HTTPS and I have tested everything I can think of and everything is working.
&lt;/p&gt;
&lt;p&gt;
I have discovered an apache to nginx config convertor which should speed up progress:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://www.anilcetin.com/convert-apache-htaccess-to-nginx/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.anilcetin.com/convert-apache-htaccess-to-nginx/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
For reference if you get this error message:
&lt;/p&gt;
&lt;pre class="wiki"&gt;==&amp;gt; /var/log/nginx/wiki.ssl_error.log &amp;lt;==
2012/03/27 10:57:15 [info] 26009#0: *18 client sent plain HTTP request to HTTPS port while reading client request headers, client: XX.XX.XX.XX, server: wiki.dev.transitionnetwork.org, request: "OPTIONS /index.php?action=ajax HTTP/1.1", host: "wiki.dev.transitionnetwork.org:4430"
==&amp;gt; /var/log/nginx/wiki.ssl_access.log &amp;lt;==
81.95.52.29 - - [27/Mar/2012:10:57:15 +0100] "OPTIONS /index.php?action=ajax HTTP/1.1" 400 271 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:11.0) Gecko/20100101 Firefox/11.0 Iceweasel/11.0"
&lt;/pre&gt;&lt;p&gt;
It can be fixed by adding this to the &lt;tt&gt;location&lt;/tt&gt; section of the config for the php scripts:
&lt;/p&gt;
&lt;pre class="wiki"&gt;fastcgi_param HTTPS on;
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 27 Mar 2012 13:46:57 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:25</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:25</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.3&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;23.68&lt;/em&gt; to &lt;em&gt;23.98&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have made a start on the regular expressions for:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2010.archive.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2010.archive.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 28 Mar 2012 13:47:50 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:26</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:26</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;3.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;23.98&lt;/em&gt; to &lt;em&gt;26.98&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
These sites are now available via nginx on port 8000:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2010.archive.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2010.archive.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
But there is a problem with the regular expressions for the forum archive, I had it working earlier but it's now broken and needs fixing:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org:8000/forum/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org:8000/forum/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
See also &lt;a class="wiki" href="http://localhost:8080/trac/wiki/DevelopmentServer#bbPress"&gt;wiki:DevelopmentServer#bbPress&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I have also discovered the files from a old Wordpress site which was at &lt;a class="ext-link" href="http://transitiontowns.org/webprojectblog"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitiontowns.org/webprojectblog&lt;/a&gt; -- I assume this is safe to ignore -- I have set nginx up not to allow access to it.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 29 Mar 2012 10:25:00 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:27</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:27</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;26.98&lt;/em&gt; to &lt;em&gt;27.08&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The fix for the old forum was easy:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org:8000/forum/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org:8000/forum/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Now onto Pwiki, Trac and then Drupal...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 29 Mar 2012 12:32:34 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:28</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:28</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.46&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;27.08&lt;/em&gt; to &lt;em&gt;28.54&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Piwki has been setup, following &lt;a class="ext-link" href="http://wiki.nginx.org/Piwik"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.nginx.org/Piwik&lt;/a&gt; which is based on &lt;a class="ext-link" href="https://github.com/perusio/piwik-nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://github.com/perusio/piwik-nginx&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
A directory for the cache was needed:
&lt;/p&gt;
&lt;pre class="wiki"&gt;mkdir /var/cache/nginx/fcgicache -p
chown www-data:www-data /var/cache/nginx/fcgicache
&lt;/pre&gt;&lt;p&gt;
I added a web bug to &lt;a class="ext-link" href="http://kiwi.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://kiwi.transitionnetwork.org/&lt;/a&gt; to test it:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://piwik.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://piwik.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 29 Mar 2012 15:10:50 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:29</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:29</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.42&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;28.54&lt;/em&gt; to &lt;em&gt;29.96&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Setting up Trac on Nginx isn't going to be simple, some resources on this:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://wiki.nginx.org/NonRootWebPathApacheStyle"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.nginx.org/NonRootWebPathApacheStyle&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://trac.edgewall.org/wiki/TracNginxRecipe"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://trac.edgewall.org/wiki/TracNginxRecipe&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://trac.edgewall.org/wiki/TracFastCgi#SimpleNginxConfiguration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://trac.edgewall.org/wiki/TracFastCgi#SimpleNginxConfiguration&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://coderanger.net/~coderanger/tracdoc/install/fastcgi.html#nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://coderanger.net/~coderanger/tracdoc/install/fastcgi.html#nginx&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://wiki.nginx.org/NginxHttpFcgiModule"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wiki.nginx.org/NginxHttpFcgiModule&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
See also &lt;a class="wiki" href="http://localhost:8080/trac/wiki/DevelopmentServer#Trac"&gt;wiki:DevelopmentServer#Trac&lt;/a&gt; &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/1" title="task: Trac install (closed: fixed)"&gt;ticket:1&lt;/a&gt; and &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/364" title="maintenance: Migrate from SVN to Git (closed: fixed)"&gt;ticket:364&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
There is also the old subversion repo here &lt;a class="ext-link" href="https://tech.transitionnetwork.org/svn/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tech.transitionnetwork.org/svn/&lt;/a&gt; I guess this isn't needed any more?
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Python is a bit of mess on the development server because (a) a source version was installed in order to get the GA Piwik import working and (b) a unstable version was installed in order to install a unstable version of Trac in order to get it working with git...
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/364#comment:36"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tech.transitionnetwork.org/trac/ticket/364#comment:36&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I'm also concerned that although trac isn't working perfectly at the moment at least it's working...
&lt;/p&gt;
&lt;p&gt;
Do we &lt;strong&gt;need&lt;/strong&gt; trac to be integrated with github?
&lt;/p&gt;
&lt;p&gt;
For now I think I'll look at setting up nginx as a reverse proxy for apache for trac and then fixing trac can be done after the switch to Nginx...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 29 Mar 2012 16:29:31 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:30</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:30</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.4&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;29.96&lt;/em&gt; to &lt;em&gt;30.36&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Trac with Nginx acting as a reverse proxy to apache:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://tech.transitionnetwork.org:4430/trac/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tech.transitionnetwork.org:4430/trac/&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 29 Mar 2012 16:58:33 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:31</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:31</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.4&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;30.36&lt;/em&gt; to &lt;em&gt;30.76&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have made a start on the Drupal sites:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Nginx: &lt;a class="ext-link" href="http://dev.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
This still needs lots of work to replicate the varnish caching etc and setting it up so that authenticated sessions use HTTPS, at the moment it doesn't seem any quicker than apache / varnish, but it should be when it's done...
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Apache: &lt;a class="ext-link" href="http://dev.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 05 Apr 2012 11:27:23 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:32</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:32</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;30.76&lt;/em&gt; to &lt;em&gt;31.76&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The Drupal sites are now available via nginx (but HTTPS only authenticated sessions haven’t been configured yet):
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://dev.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://dev.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://dev.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://test.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://test.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://test.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://test.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://news.dev.transitionnetwork.org:8000/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://news.dev.transitionnetwork.org:8000/&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://news.dev.transitionnetwork.org:4430/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://news.dev.transitionnetwork.org:4430/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
I'm now going to switch all the ports around so that Nginx is on port 80 and 443 and apache will just be used for Trac, further configuration and all the php-fpm and nginx cache tuning can be done after this switch -- at the moment the server is really hard to work on due to the lack of memory, this should improve after the switch, see &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/memory.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/memory.html&lt;/a&gt; (almost 1.5G is being used but there is only 1G -- it's swapping a lot).
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 05 Apr 2012 13:00:34 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:33</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:33</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;31.76&lt;/em&gt; to &lt;em&gt;32.26&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
All references to port 8000 changed to 80 and all references to 4430 changed to 443 in &lt;tt&gt;/etc/nginx/sites-available&lt;/tt&gt;.
&lt;/p&gt;
&lt;p&gt;
For apache all 443 VirtualServers wrapped in &lt;tt&gt;&amp;lt;IfModule mod_ssl.c&amp;gt;&lt;/tt&gt; and mod-ssl disabled (at a later date all the symlinks in &lt;tt&gt;/etc/apache2/sites-enabled&lt;/tt&gt; apart from the trac one can be deleted).
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/apache2/mods-enabled
rm ssl.conf ssl.load
&lt;/pre&gt;&lt;p&gt;
Varnish stopped, apache restarted, nginx restarted.
&lt;/p&gt;
&lt;p&gt;
TODO:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;HTTPS only for authenticated sessions for Drupal sites
&lt;/li&gt;&lt;li&gt;Security checking
&lt;/li&gt;&lt;li&gt;Nginx cache configuration
&lt;/li&gt;&lt;li&gt;php-fpm configuration
&lt;/li&gt;&lt;li&gt;Testing
&lt;/li&gt;&lt;li&gt;Documentation
&lt;/li&gt;&lt;li&gt;Live migration
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 05 Apr 2012 15:25:55 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:34</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:34</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;32.26&lt;/em&gt; to &lt;em&gt;32.36&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Do we still need the subversion repo?
&lt;/p&gt;
&lt;p&gt;
It's currently not set up to work with nginx, I could set up nginx to proxy requests to apache to get it working again if needs be:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://mailman.nginx.org/pipermail/nginx/2007-January/000504.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://mailman.nginx.org/pipermail/nginx/2007-January/000504.html&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://stackoverflow.com/questions/2479346/502-bad-gateway-with-nginx-apache-subversion-ssl-svn-copy"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://stackoverflow.com/questions/2479346/502-bad-gateway-with-nginx-apache-subversion-ssl-svn-copy&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 05 Apr 2012 15:30:37 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:35</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:35</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.03&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;32.36&lt;/em&gt; to &lt;em&gt;32.39&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Munin added to TODO list:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Sort out &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Munin stats&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;HTTPS only for authenticated sessions for Drupal sites
&lt;/li&gt;&lt;li&gt;Security checking
&lt;/li&gt;&lt;li&gt;Nginx cache configuration
&lt;/li&gt;&lt;li&gt;php-fpm configuration
&lt;/li&gt;&lt;li&gt;Testing
&lt;/li&gt;&lt;li&gt;Documentation
&lt;/li&gt;&lt;li&gt;Live migration
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 05 Apr 2012 16:41:21 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:36</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:36</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.43&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;32.39&lt;/em&gt; to &lt;em&gt;32.82&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The forum archive had no CSS:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://2011.archive.transitionnetwork.org/forum/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2011.archive.transitionnetwork.org/forum/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
And the tag pages and rss feeds were 404's, these have all been fixed in &lt;tt&gt;/etc/nginx/archive-shared&lt;/tt&gt;.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 05 Apr 2012 17:12:01 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:37</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:37</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;32.82&lt;/em&gt; to &lt;em&gt;32.92&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Cron added to TODO list:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Fix cron jobs: &lt;tt&gt;lynx -connect_timeout=60 -dump http://dev.transitionnetwork.org/cron.php &amp;gt; /dev/null  (failed)&lt;/tt&gt;
&lt;/li&gt;&lt;li&gt;Sort out &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Munin stats&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;HTTPS only for authenticated sessions for Drupal sites
&lt;/li&gt;&lt;li&gt;Security checking
&lt;/li&gt;&lt;li&gt;Nginx cache configuration
&lt;/li&gt;&lt;li&gt;php-fpm configuration
&lt;/li&gt;&lt;li&gt;Testing
&lt;/li&gt;&lt;li&gt;Documentation
&lt;/li&gt;&lt;li&gt;Live migration
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 17 Apr 2012 10:42:42 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:38</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:38</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.23&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;32.92&lt;/em&gt; to &lt;em&gt;33.15&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:37" title="Comment 37 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;Fix cron jobs: &lt;tt&gt;lynx -connect_timeout=60 -dump http://dev.transitionnetwork.org/cron.php &amp;gt; /dev/null  (failed)&lt;/tt&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
This has been fixed, only connections from the server itself are allowed to the cron.php script, in &lt;tt&gt;/etc/nginx/drupal-shared&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;        location ~ /cron.php$ {
                allow 127.0.1.1;
                allow 81.95.52.78;
                deny all;
                include fastcgi_params;
                fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
                fastcgi_intercept_errors on;
                fastcgi_pass unix:/var/run/php5-fpm/phpfpm.sock;
        }
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 17 Apr 2012 11:43:25 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:39</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:39</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;33.15&lt;/em&gt; to &lt;em&gt;33.65&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:37" title="Comment 37 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;Sort out &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Munin stats&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
Apache stats fixed by changing the port in &lt;tt&gt;/etc/munin/plugin-conf.d/munin-node&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[apache*]
user root
env.url   http://kiwi.webarch.net:%d/server-status?auto
env.ports 8080
&lt;/pre&gt;&lt;p&gt;
See: &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html#apache"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html#apache&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The problem with the Munin stats, &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html#munin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html#munin&lt;/a&gt; was because of permissions, I'm not sure what changed to cause this, this was the problem:
&lt;/p&gt;
&lt;pre class="wiki"&gt;munin-run munin_stats
update.extinfo Can't open /var/log/munin/munin-update.log for reading
update.value U
graph.extinfo Can't open /var/log/munin/munin-graph.log for reading
graph.value U
html.extinfo Can't open /var/log/munin/munin-html.log for reading
html.value U
limits.extinfo Can't open /var/log/munin/munin-limits.log for reading
limits.value U
&lt;/pre&gt;&lt;p&gt;
This was fixed by adding the following to &lt;tt&gt;/etc/munin/plugin-conf.d/munin-node&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[munin_stats]
user root
&lt;/pre&gt;&lt;p&gt;
Now the test returns some values:
&lt;/p&gt;
&lt;pre class="wiki"&gt;munin-run munin_stats
update.value U
graph.value 39.53
html.value 6.65
limits.value U
&lt;/pre&gt;&lt;p&gt;
Nginx stats fixed by changing the port in &lt;tt&gt;/etc/munin/plugin-conf.d/munin-node&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[nginx*]
env.url http://kiwi.webarch.net:80/nginx_status
&lt;/pre&gt;&lt;p&gt;
See &lt;a class="ext-link" href="https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html#nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kiwi.transitionnetwork.org/munin/webarch.net/kiwi.webarch.net/index.html#nginx&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 17 Apr 2012 12:30:19 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:40</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:40</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;33.65&lt;/em&gt; to &lt;em&gt;34.15&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/357#comment:35" title="Comment 35 for Ticket #357"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;HTTPS only for authenticated sessions for Drupal sites
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
With apache we had these rules to redirect port 80 connections:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  # redirect for encrypted logins etc
  RedirectPermanent /user https://dev.transitionnetwork.org/user
  RedirectPermanent /admin https://dev.transitionnetwork.org/admin
  RedirectPermanent /contact https://dev.transitionnetwork.org/contact
  RedirectPermanent /install.php https://dev.transitionnetwork.org/install.php
  RedirectPermanent /update.php https://dev.transitionnetwork.org/update.php
  RedirectMatch /(.*)\/contact$ https://dev.transitionnetwork.org/$1/contact
&lt;/pre&gt;&lt;p&gt;
These can be replaced with these nginx rules in &lt;tt&gt;/etc/nginx/sites-available/dev&lt;/tt&gt; and &lt;tt&gt;/etc/nginx/sites-available/test&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;        # Redirects to HTTPS
        location ^~ /user               { return 301 https://$host$request_uri; }
        location ^~ /admin              { return 301 https://$host$request_uri; }
        location ^~ /contact            { return 301 https://$host$request_uri; }
        location ^~ /install.php        { return 301 https://$host$request_uri; }
        location ^~ /update.php         { return 301 https://$host$request_uri; }
        location ^~ /(.*)\/contact$     { return 301 https://$host$request_uri; }
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 17 Apr 2012 13:22:57 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:41</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:41</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;34.15&lt;/em&gt; to &lt;em&gt;34.35&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Remaining TODO items:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Security checking
&lt;/li&gt;&lt;li&gt;Nginx cache configuration
&lt;/li&gt;&lt;li&gt;php-fpm configuration
&lt;/li&gt;&lt;li&gt;Testing
&lt;/li&gt;&lt;li&gt;Documentation
&lt;/li&gt;&lt;li&gt;Live migration
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Also I note that at the moment the dev site appears to be slower with nginx than it was with varnish and apache, for example the front page of the dev site (just the HTML not any associated files) takes a minimum of about 3 seconds and at times a lot longer:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ab -n 1 -v 4 http://dev.transitionnetwork.org/
Time taken for tests:   4.152 seconds
Time taken for tests:   2.617 seconds
Time taken for tests:   8.725 seconds
Time taken for tests:   4.231 seconds
Time taken for tests:   7.692 seconds
Time taken for tests:   14.641 seconds
Time taken for tests:   22.364 seconds
Time taken for tests:   6.614 seconds
Time taken for tests:   4.599 seconds
Time taken for tests:   4.237 seconds
&lt;/pre&gt;&lt;p&gt;
I think a lot of optimisation is going to be needed before nginx is as fast as the current setup with apache / varnish.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 17 Apr 2012 19:23:12 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/357#comment:42</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:42</guid>
      <description>
        &lt;p&gt;
Some Drupal resources to consider from Jim:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/tree/HEAD:/aegir/conf"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupalcode.org/project/barracuda.git/tree/HEAD:/aegir/conf&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 01 May 2012 12:15:32 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:43</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:43</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;34.35&lt;/em&gt; to &lt;em&gt;35.35&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Some related tickets which have been now closed:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;HTTPS Security Issues &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/409" title="defect: HTTPS Security Issues (closed: fixed)"&gt;ticket:409&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Pressflow problem on Dev site &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/406" title="defect: Pressflow problem on Dev site (closed: fixed)"&gt;ticket:406&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Back to nginx and php-fpm configuration...
&lt;/p&gt;
&lt;p&gt;
Error generated due to lack of memory for PHP when accessing &lt;a class="ext-link" href="http://dev.transitionnetwork.org/admin/reports/status"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org/admin/reports/status&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 64 bytes) in /web/dev.transitionnetwork.org.webarch.net/www/includes/cache.inc on line 32
&lt;/pre&gt;&lt;p&gt;
In /etc/php5/fpm/php.ini the memory limit was increased:
&lt;/p&gt;
&lt;pre class="wiki"&gt;#memory_limit = 128M
memory_limit = 256M
&lt;/pre&gt;&lt;p&gt;
Things that needed adding back into &lt;tt&gt;/web/dev.transitionnetwork.org.webarch.net/www/sites/default/settings.php&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;$conf = array(
'site_name' =&amp;gt; 'This is the Transition Network DEV server',
);
$cookie_domain = '.dev.transitionnetwork.org';
# JK - added according to no anon session module readme
# chris - commented as it doesn't appear to be installed any more?
#$confsession_inc = './sites/all/modules/no_anon/session-no-anon.inc';
# memcache
$conf = array(
  'cache_inc' =&amp;gt; './sites/all/modules/memcache/memcache.inc',
  'memcache_servers' =&amp;gt; array('127.0.0.1:11211' =&amp;gt; 'default'),
  'memcache_bins' =&amp;gt; array(
    'cache' =&amp;gt; 'default',
    'cache_content' =&amp;gt; 'database',
    'cache_form' =&amp;gt; 'database',
    'cache_views' =&amp;gt; 'database'
  ),
);
/**
 * Reroute Email 6.x-1.x-dev variable to send emails to a different address for TEST
 *
 * JK - this is TEST so am rerouting emails!
 */
$conf['reroute_email_enable'] = 1;
# chris - following variable added
$conf['reroute_email_address'] = "transition-dev@email-lists.org";
&lt;/pre&gt;&lt;p&gt;
Note that the site_name settings doesn't appear to be working -- the dev site name was still "Transition Network", so it was fixed at a mysql level:
&lt;/p&gt;
&lt;pre class="wiki"&gt;mysql&amp;gt; select * from variable where name="site_name";
+-----------+----------------------------+
| name      | value                      |
+-----------+----------------------------+
| site_name | s:18:"Transition Network"; |
+-----------+----------------------------+
1 row in set (0.00 sec)
mysql&amp;gt; update variable set value='s:27:"Transition Network DEV Site";' where name="site_name";
Query OK, 1 row affected (0.09 sec)
Rows matched: 1  Changed: 1  Warnings: 0
mysql&amp;gt; select * from variable where name="site_name";
+-----------+-------------------------------------+
| name      | value                               |
+-----------+-------------------------------------+
| site_name | s:27:"Transition Network DEV Site"; |
+-----------+-------------------------------------+
1 row in set (0.00 sec)
&lt;/pre&gt;&lt;p&gt;
The S:27 being 1 less than the character count.
&lt;/p&gt;
&lt;p&gt;
This error is appearing at the top of all pages in admin:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Notice: Undefined index: icon in /web/dev.transitionnetwork.org.webarch.net/www/sites/all/modules/ctools/includes/content.inc on line 73
&lt;/pre&gt;&lt;p&gt;
Also HTTPS logins still don't work, they redirect to the Pressflow installer so perhaps &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/406" title="defect: Pressflow problem on Dev site (closed: fixed)"&gt;ticket:406&lt;/a&gt; was closed too fast :-|
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 01 May 2012 12:57:07 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:44</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:44</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.7&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;35.35&lt;/em&gt; to &lt;em&gt;36.05&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
On the Performance admin page, &lt;a class="ext-link" href="http://dev.transitionnetwork.org/admin/settings/performance"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org/admin/settings/performance&lt;/a&gt; the Page cache, Caching mode settings were changed from "External (experts only, possible side effects)" to "Normal (recommended for production sites, no side effects)".
&lt;/p&gt;
&lt;p&gt;
The dev site isn't serving data gzipped (apache was), this can be tested using apache bench:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ab -v 4 -n 1 -H "Accept-Encoding: gzip" "http://dev.transitionnetwork.org/"
&lt;/pre&gt;&lt;p&gt;
The nginx gzip config was tried but wasn't working so compression was enabled at a drupal level on the performance page, "Page compression", "Enabled", however this didn't result in gzip'ed pages being served either.
&lt;/p&gt;
&lt;p&gt;
Updated TODO list:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Sort out nginx HTTPS and Drupal, this isn't working at all for the dev site, try to login and you get the install page.
&lt;/li&gt;&lt;li&gt;Sort out no-cookies and caching for port 80, authenticated only sessions on port 443.
&lt;/li&gt;&lt;li&gt;Sort out compression for HTML and CSS.
&lt;/li&gt;&lt;li&gt;Test the speed of the site and tune as needed.
&lt;/li&gt;&lt;li&gt;Document the nginx setup.
&lt;/li&gt;&lt;li&gt;When we are happy migrate the live server from apache to nginx.
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 04 May 2012 13:43:20 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:45</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:45</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;36.05&lt;/em&gt; to &lt;em&gt;37.55&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Finally getting somewhere with this there was a mistake in the nginx &lt;tt&gt;root&lt;/tt&gt; path for HTTPS (do'h!). There was also a problem setting the HTTPS env var for php-fpm, the following in a location block (shared for the HTTP and HTTPS settings) didn't work but perhaps there is a way to get this to work, will look at it again next week:
&lt;/p&gt;
&lt;pre class="wiki"&gt;if ($ssl = on) {
       fastcgi_param HTTPS on;
}
&lt;/pre&gt;&lt;p&gt;
You can now login to the dev site using https, but the session cookies set wasn't secure, Session 443 has been re-enabled:
&lt;/p&gt;
&lt;pre class="wiki"&gt;drush en session443
The following extensions will be enabled: session443
Do you really want to continue? (y/n): y
WD php: Notice: Undefined index: icon in ctools_content_process() (line 73 of                 [error]
/web/dev.transitionnetwork.org.webarch.net/www/sites/all/modules/ctools/includes/content.inc).
session443 was enabled successfully.                                                          [ok]
Redirects need to be enabled at admin/settings/session443                                     [status]
&lt;/pre&gt;&lt;p&gt;
And the settings at &lt;a class="ext-link" href="https://dev.transitionnetwork.org/admin/settings/session443"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://dev.transitionnetwork.org/admin/settings/session443&lt;/a&gt; were set to:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Enabled - Redirection may happen according to the rules below.
&lt;/li&gt;&lt;li&gt;Redirect authenticated users to HTTPS and redirect anonymous users on login/registration pages to HTTPS. Anonymous users visiting other pages may use HTTP or HTTPS.
&lt;/li&gt;&lt;li&gt;Force all pages with the login block to use HTTPS.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
This config was also added to &lt;tt&gt;/web/dev.transitionnetwork.org.webarch.net/www/sites/default/settings.php&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;      if (!empty($_SERVER['HTTPS']) &amp;amp;&amp;amp; $_SERVER['HTTPS'] != 'off') {
        ini_set('session.cookie_secure', 1);
      }
&lt;/pre&gt;&lt;p&gt;
And now authenticated session cookies to have the secure flag set.
&lt;/p&gt;
&lt;p&gt;
Also an insecure cookie is set:
&lt;/p&gt;
&lt;pre class="wiki"&gt;LOGGED_IN=1
&lt;/pre&gt;&lt;p&gt;
Which results in all HTTP requests being redirected to HTTPS -- this cookie was being destroyed with our live varnish set up to enable more content to be cached, but it's a handy thing to have so I think we should perhaps make sure it's kept for php pages even if we destroy it for css and images, something for next week...
&lt;/p&gt;
&lt;p&gt;
A ticket has been opened regarding the http link to the favicon in the admin menu, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/411" title="defect: HTTPS problem caused by favicon.ico in admin menu (closed: fixed)"&gt;ticket:411&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 05 May 2012 11:33:50 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:46</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:46</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.4&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;37.55&lt;/em&gt; to &lt;em&gt;38.95&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have read thought all the config suggested by Jim, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/357#comment:42" title="maintenance: nginx research (closed: fixed)"&gt;ticket:357#comment:42&lt;/a&gt; and there are lots of things that doesn't apply to us, I think we need to have a discussion about what the caching strategy is going to be with nginx because I'm not sure what to do next -- the current nginx setup on the dev server is slower than the apache/varnish setup on the live server, for example testing 20 concurrent requests for 600 copies of the front page from another server on the local network, first the dev server:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ab -v 4 -n 600 -c 20 -H "Accept-Encoding: gzip, deflate" http://dev.transitionnetwork.org/
Concurrency Level:      20
Time taken for tests:   10.100 seconds
Complete requests:      600
Failed requests:        7
&lt;/pre&gt;&lt;p&gt;
Live server:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ab -v 4 -n 600 -c 20 -H "Accept-Encoding: gzip, deflate" http://www.transitionnetwork.org/
Concurrency Level:      20
Time taken for tests:   0.641 seconds
Complete requests:      600
Failed requests:        0
&lt;/pre&gt;&lt;p&gt;
Less than 1 second with the live server and 10 seconds with the dev server.
&lt;/p&gt;
&lt;p&gt;
Regading the gzipping issue mentioned in &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/357#comment:44" title="maintenance: nginx research (closed: fixed)"&gt;ticket:357#comment:44&lt;/a&gt; it turns out that is is working when checked using the Firefox Live HTTP Headers plugin, I don't understand why gziped content isn't served to apache bench or when this online test &lt;a class="ext-link" href="http://www.gidnetwork.com/tools/gzip-test.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.gidnetwork.com/tools/gzip-test.php&lt;/a&gt; is used.
&lt;/p&gt;
&lt;p&gt;
This doesn't result in gzipped content:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ab -v 4 -n 1 -H "Accept-Encoding: gzip, deflate" http://kiwi.transitionnetwork.org/
&lt;/pre&gt;&lt;p&gt;
However using curl we do get gzipped content:
&lt;/p&gt;
&lt;pre class="wiki"&gt;curl -I --compressed  http://kiwi.transitionnetwork.org/
&lt;/pre&gt;&lt;p&gt;
So gzipping is working for some clients and not others, with apache all these clients get gzipped content.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 09 May 2012 13:31:23 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:47</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:47</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;2.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;38.95&lt;/em&gt; to &lt;em&gt;40.95&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have spent a couple of hours reading various nginx documentation, including &lt;a class="ext-link" href="https://calomel.org/nginx.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://calomel.org/nginx.html&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I think we basically need to cache everything requested on port 80 and everything we can on port 443.
&lt;/p&gt;
&lt;p&gt;
I have updated the Drush setup on the dev server based on the suggestions here, &lt;a class="ext-link" href="https://github.com/perusio/drupal-with-nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://github.com/perusio/drupal-with-nginx&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;mkdir /etc/drush
cp /usr/local/drush/examples/example.aliases.drushrc.php \
/etc/drush/aliases.drushrc.php
&lt;/pre&gt;&lt;p&gt;
Then the following was added to that file:
&lt;/p&gt;
&lt;pre class="wiki"&gt;$aliases['dev'] = array(
    'uri' =&amp;gt; 'dev.transitionetwork.org',
    'root' =&amp;gt; '/web/dev.transitionnetwork.org.webarch.net/www',
  );
$aliases['test'] = array(
    'uri' =&amp;gt; 'test.transitionetwork.org',
    'root' =&amp;gt; '/web/test.transitionnetwork.org.webarch.net/www',
  );
&lt;/pre&gt;&lt;p&gt;
And the cronjob for the dev site was changed to:
&lt;/p&gt;
&lt;pre class="wiki"&gt;DRUSH=/usr/local/bin/drush
*/50 * * * * $DRUSH @dev cron -q
&lt;/pre&gt;&lt;p&gt;
Further drush configuration could be done to allow interaction with the live server if needs be.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 10 May 2012 16:14:27 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/357#comment:48</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:48</guid>
      <description>
        &lt;p&gt;
php-fpm is not working at the moment, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/218#comment:38" title="maintenance: Debian upgrades and updates (closed: fixed)"&gt;ticket:218#comment:38&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 28 May 2012 13:22:06 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:49</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:49</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.09&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;40.95&lt;/em&gt; to &lt;em&gt;42.04&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Before caching is sorted out we need to get session 443 working properly, see &lt;a href="http://localhost:8080/trac/ticket/357#comment:45" title="Comment 45 for Ticket #357"&gt;comment:45&lt;/a&gt; -- at the moment it isn't, the secure flag is being set on the &lt;tt&gt;LOGGED_IN&lt;/tt&gt; cookie and this means that requests to the http version of the site are not being redirected, I'm not sure why as it was working before. I have checked the environment and with https the PHP variable &lt;tt&gt;_SERVER["HTTPS"]&lt;/tt&gt; is set to &lt;tt&gt;on&lt;/tt&gt; and with http it isn't set -- this is how it should be.
&lt;/p&gt;
&lt;p&gt;
There is also this issue with the lifetime of the &lt;tt&gt;LOGGED_IN&lt;/tt&gt; cookie which hasn't been fixed in the current version of session443, &lt;a class="ext-link" href="https://drupal.org/node/1338266"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/1338266&lt;/a&gt; -- we should probably apply it.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 29 May 2012 10:25:52 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/357#comment:50</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:50</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;42.04&lt;/em&gt; to &lt;em&gt;42.24&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have done some more testing with the Firefox &lt;a class="ext-link" href="https://addons.mozilla.org/en-US/firefox/addon/live-http-headers/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Live HTTP Headers&lt;/a&gt; and &lt;a class="ext-link" href="https://addons.mozilla.org/en-US/firefox/addon/cookie-manager/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Advanced Cookie Manager&lt;/a&gt; and Session 443 does appear to be working correctly.
&lt;/p&gt;
&lt;p&gt;
When one is on the login page at &lt;a class="ext-link" href="https://dev.transitionnetwork.org/user/login"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://dev.transitionnetwork.org/user/login&lt;/a&gt; and the form is POST'ed a 302 is returned to redirect people to their user page and this Set-Cookie header is sent with the 302:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Set-Cookie: SESS456789012b2e466470fa7d2012345f24c=27f9cdaa43c6c0987f0f290d3456789b; expires=Thu, 21-Jun-2012 13:46:35 GMT; path=/; domain=.dev.transitionnetwork.org; secure; HttpOnly
&lt;/pre&gt;&lt;p&gt;
And then the user page is requested and with that page the LOGGED_IN cookie is set (correctly not secure):
&lt;/p&gt;
&lt;pre class="wiki"&gt;Set-Cookie: LOGGED_IN=1; path=/; domain=.dev.transitionnetwork.org
&lt;/pre&gt;&lt;p&gt;
Note that this should have the same expired date as the session cookie, see &lt;a href="http://localhost:8080/trac/ticket/357#comment:49" title="Comment 49 for Ticket #357"&gt;comment:49&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
If one then visits the http version of the site the LOGGED_IN cookie is sent and a 302 redirect the user back to HTTPS.
&lt;/p&gt;
&lt;p&gt;
I don't know why this wasn't workijng last night, since then I have restarted Firefox and cleared all the *.transitionnetwork.org cookies out -- this seems to have fixed it.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 25 Jan 2013 16:35:02 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/357#comment:51</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/357#comment:51</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;accepted&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The new &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt; is now up and running and all the sites on it are using Nginx (Trac is using Nginx as a reverse proxy to tracd) for more details of the Nginx configuration see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/470" title="maintenance: Penguin install and configuration (closed: fixed)"&gt;ticket:470&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The main transition network site is also due to be running on Nginx as soon as &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; goes live, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/466" title="task: Puffin install and configuration (closed: fixed)"&gt;ticket:466&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
So this ticket can finally be closed.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>