<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #707: Upgrade to BOA-2.2.2</title>
    <link>http://localhost:8080/trac/ticket/707</link>
    <description>&lt;p&gt;
I have created a new ticket for this as I have found having one ticket (see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/629" title="maintenance: Upgrade to BOA-2.1.3 Stable Edition (closed: wontfix)"&gt;ticket:629&lt;/a&gt;) for all BOA upgrades makes it really hard to review past upgrades.
&lt;/p&gt;
&lt;p&gt;
Upgrades from BOA-2.0.7 to BOA-2.1.1 did have their own tickets, see &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#Upgradetickets"&gt;wiki:PuffinServer#Upgradetickets&lt;/a&gt; and unless there is a convincing reason not to have one ticket per upgrade I'd rather do it like this.
&lt;/p&gt;
&lt;p&gt;
Jim has pointed out on the Ttech list that:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
the v2.2.0 changelog is up as of a few days ago:
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/HEAD:/CHANGELOG.txt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupalcode.org/project/barracuda.git/blob/HEAD:/CHANGELOG.txt&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The Changelog starts:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;Stable BOA-2.2.0 Release - Full Edition
&lt;/li&gt;&lt;li&gt;Date: TBD
&lt;/li&gt;&lt;li&gt;Includes Aegir 2.x-boa-custom version.
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Release Notes:
&lt;/li&gt;&lt;/ul&gt;&lt;blockquote&gt;
&lt;p&gt;
There are many important changes and improvements in this release you should be aware of *before* running your BOA system upgrade.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
Even if you are on a hosted BOA system with upgrades managed for you, it is very important to read at least this extensive release notes.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
And if you are more curious, read also the big changelog further below, which covers only a small number of over 530 commits since BOA-2.1.3
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I have yet to read the rest of the Changelog.
&lt;/p&gt;
&lt;p&gt;
There is also a task to copy the proposed changes to the BOA configuration in &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/629" title="maintenance: Upgrade to BOA-2.1.3 Stable Edition (closed: wontfix)"&gt;ticket:629&lt;/a&gt; over to this ticket.
&lt;/p&gt;
&lt;p&gt;
Should people other than chris and ed be CC's for this ticket?
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/707</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Wed, 26 Mar 2014 20:50:16 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:1</guid>
      <description>
        &lt;p&gt;
Jim most definitely. This is important. I'm adding him now. And probably Paul; tbc; I have an email out with him asking if he'll take more of a lead on code publishing as it's not working for Sam - so let's see if Paul will also go cc on this.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Wed, 26 Mar 2014 20:50:26 GMT</pubDate>
      <title>cc changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;jim&lt;/em&gt; added
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 06:56:21 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:3</guid>
      <description>
        &lt;p&gt;
Email from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There is new BOA-2.2.0 Stable Edition available.
&lt;/p&gt;
&lt;p&gt;
Please review the changelog and upgrade as soon as possible
to receive all security updates and new features.
&lt;/p&gt;
&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/newboa"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/newboa&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I'll do the upgrade tonight.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 11:50:26 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:4</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Reading through the Changelog, these issues are ones which effect us:
&lt;/p&gt;
&lt;hr /&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="Customphp.iniprotectionhaschangedandwillnothonoroldsettings"&gt;Custom php.ini protection has changed and will not honor old settings&lt;/h2&gt;
&lt;p&gt;
If you have custom settings in any of your php.ini files protected with
old variable in the /root/.barracuda.cnf, make a backup of your ini files
before running this upgrade. While these files will not get overwritten,
they will no longer be used, because we have introduced new, standardized
directory structure to properly support multi-PHP-versions systems.
&lt;/p&gt;
&lt;p&gt;
Respective php.ini files are now located in /opt/phpXX/etc/phpXX.ini
for FPM and /opt/phpXX/lib/php.ini for CLI, where XX is 55, 54, 53 or 52,
depending on the versions listed via _PHP_MULTI_INSTALL variable in the
/root/.barracuda.cnf file. Also the variables used to protect ini files
from being overwritten have changed to _CUSTOM_CONFIG_PHPXX.
&lt;/p&gt;
&lt;p&gt;
If you need any non-standard settings in any of active ini files, don't
overwrite them with the old files, but rather carefully review and apply
only the differences you need.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr /&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="AllPHPFPMworkersin5.55.4and5.3nowusetheondemandmode"&gt;All PHP FPM workers in 5.5, 5.4 and 5.3 now use the 'ondemand' mode&lt;/h2&gt;
&lt;p&gt;
This change will help to better manage memory use, especially on systems with
multiple PHP versions running in parallel. This will also free resources
and allocate them dynamically only when requests are coming and only to
the active FPM pools. Note that the 'ondemand' mode doesn't affect Zend
OPcache, because it is managed by the parent process(es) which stay(s) active.
&lt;/p&gt;
&lt;p&gt;
The net result is that on a vanilla BOA install, without non-hostmaster sites
running, the complete stack consumes just ~200 MB of RAM (in total, so with
MariaDB, Redis and Nginx etc. included) with all three PHP-FPM versions
running in parallel: 5.5, 5.4 and 5.3:
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr /&gt;
&lt;p&gt;
But I don't think these will require any action on our part, they just address things we were manually fixing. Our documentation will need updating after the upgrade, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 13:17:51 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.25&lt;/em&gt; to &lt;em&gt;1.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Reviewing the discussion on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/629" title="maintenance: Upgrade to BOA-2.1.3 Stable Edition (closed: wontfix)"&gt;ticket:629&lt;/a&gt; these are the issues we need to be aware of when doing the BOA upgrade tonight:
&lt;/p&gt;
&lt;h2 id="php-fpmstatus"&gt;php-fpm status&lt;/h2&gt;
&lt;p&gt;
See &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/629#comment:32" title="maintenance: Upgrade to BOA-2.1.3 Stable Edition (closed: wontfix)"&gt;ticket:629#comment:32&lt;/a&gt;, this addresses:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://127.0.0.1/status"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://127.0.0.1/status&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://127.0.0.1/ping"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://127.0.0.1/ping&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Will change to:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://127.0.0.1/fpm-status"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://127.0.0.1/fpm-status&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://127.0.0.1/fpm-ping"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://127.0.0.1/fpm-ping&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
And &lt;tt&gt;/etc/munin/plugin-conf.d/munin-node&lt;/tt&gt; will need updating to:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[phpfpm*]
env.url http://127.0.0.1/php-status
&lt;/pre&gt;&lt;h2 id="barracudaconfig"&gt;barracuda config&lt;/h2&gt;
&lt;p&gt;
Reviewing the discussion on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt;, this is the current &lt;tt&gt;/root/.barracuda.cnf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;###
### Configuration created on 121215-1545
### with Barracuda version BOA-2.0.4
###
### NOTE: the group of settings displayed bellow will *not* be overriden
### on upgrade by the Barracuda script nor by this configuration file.
### They can be defined only on initial Barracuda install.
###
_HTTP_WILDCARD=YES
_MY_OWNIP="81.95.52.103"
#_MY_OWNIP=""
_MY_HOSTN="puffin.webarch.net"
#_MY_HOSTN=""
_MY_FRONT="master.puffin.webarch.net"
_THIS_DB_HOST=localhost
#_THIS_DB_HOST=FQDN
_SMTP_RELAY_TEST=YES
_SMTP_RELAY_HOST=""
_LOCAL_NETWORK_IP=""
_LOCAL_NETWORK_HN=""
###
### NOTE: the group of settings displayed bellow
### will *override* all listed settings in the Barracuda script,
### both on initial install and upgrade.
###
_MY_EMAIL="chris@webarchitects.co.uk"
_XTRAS_LIST="PDS CSF CHV"
_AUTOPILOT=NO
_DEBUG_MODE=NO
_DB_SERVER=MariaDB
_SSH_PORT=22
_LOCAL_DEBIAN_MIRROR="ftp.debian.org"
_LOCAL_UBUNTU_MIRROR="archive.ubuntu.com"
_FORCE_GIT_MIRROR=""
_DNS_SETUP_TEST=YES
_NGINX_EXTRA_CONF=""
_NGINX_WORKERS=AUTO
_PHP_FPM_WORKERS=AUTO
_BUILD_FROM_SRC=YES
_PHP_MODERN_ONLY=YES
_PHP_FPM_VERSION=5.3
_PHP_CLI_VERSION=5.3
#_LOAD_LIMIT_ONE=1444
#_LOAD_LIMIT_TWO=888
_LOAD_LIMIT_ONE=8664
_LOAD_LIMIT_TWO=5328
_CUSTOM_CONFIG_CSF=YES
#_CUSTOM_CONFIG_SQL=NO
_CUSTOM_CONFIG_SQL=YES
_CUSTOM_CONFIG_REDIS=NO
_CUSTOM_CONFIG_PHP_5_2=NO
#_CUSTOM_CONFIG_PHP_5_3=NO
_CUSTOM_CONFIG_PHP_5_3=YES
_SPEED_VALID_MAX=3600
_NGINX_DOS_LIMIT=300
_SYSTEM_UPGRADE_ONLY=YES
_USE_MEMCACHED=NO
_NEWRELIC_KEY=
_USE_STOCK=NO
###
### Configuration created on 121215-1545
### with Barracuda version BOA-2.0.4
###
_EXTRA_PACKAGES=
_PHP_EXTRA_CONF=""
_STRONG_PASSWORDS=NO
_DB_BINARY_LOG=NO
_DB_ENGINE=InnoDB
_NGINX_LDAP=NO
_PHP_GEOS=NO
_PHP_MONGODB=NO
_AEGIR_UPGRADE_ONLY=NO
### Squeeze to Wheezy upgrade config
### See https://trac.transitionnetwork.org/trac/ticket/535
_SQUEEZE_TO_WHEEZY=YES
_NGINX_FORWARD_SECRECY=YES
_NGINX_SPDY=YES
#_BUILD_FROM_SRC=NO
_NGINX_NAXSI=NO
_PHP_ZEND_OPCACHE=YES
_PERMISSIONS_FIX=YES
_MODULES_FIX=YES
_MODULES_SKIP=""
_SSL_FROM_SOURCES=NO
_SSH_FROM_SOURCES=NO
_RESERVED_RAM=0
&lt;/pre&gt;&lt;p&gt;
See &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670#comment:15" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670#comment:15&lt;/a&gt; for the notes about the changes to this file, this is what it has now been updated to:
&lt;/p&gt;
&lt;pre class="wiki"&gt;###
### Configuration created on 121215-1545
### with Barracuda version BOA-2.0.4
###
### NOTE: the group of settings displayed bellow will *not* be overriden
### on upgrade by the Barracuda script nor by this configuration file.
### They can be defined only on initial Barracuda install.
###
_HTTP_WILDCARD=YES
_MY_OWNIP="81.95.52.103"
#_MY_OWNIP=""
_MY_HOSTN="puffin.webarch.net"
#_MY_HOSTN=""
_MY_FRONT="master.puffin.webarch.net"
_THIS_DB_HOST=localhost
#_THIS_DB_HOST=FQDN
_SMTP_RELAY_TEST=YES
_SMTP_RELAY_HOST=""
_LOCAL_NETWORK_IP=""
_LOCAL_NETWORK_HN=""
###
### NOTE: the group of settings displayed bellow
### will *override* all listed settings in the Barracuda script,
### both on initial install and upgrade.
###
_MY_EMAIL="chris@webarchitects.co.uk"
_XTRAS_LIST="PDS CSF CHV"
_AUTOPILOT=NO
_DEBUG_MODE=NO
_DB_SERVER=MariaDB
_SSH_PORT=22
_LOCAL_DEBIAN_MIRROR="ftp.debian.org"
_LOCAL_UBUNTU_MIRROR="archive.ubuntu.com"
_FORCE_GIT_MIRROR=""
_DNS_SETUP_TEST=YES
_NGINX_EXTRA_CONF=""
_NGINX_WORKERS=AUTO
_PHP_FPM_WORKERS=AUTO
#_BUILD_FROM_SRC=YES
_BUILD_FROM_SRC=NO
_PHP_MODERN_ONLY=YES
_PHP_FPM_VERSION=5.3
_PHP_CLI_VERSION=5.3
#_LOAD_LIMIT_ONE=1444
#_LOAD_LIMIT_TWO=888
_LOAD_LIMIT_ONE=8664
_LOAD_LIMIT_TWO=5328
_CUSTOM_CONFIG_CSF=YES
_CUSTOM_CONFIG_SQL=NO
#_CUSTOM_CONFIG_SQL=YES
_CUSTOM_CONFIG_REDIS=NO
_CUSTOM_CONFIG_PHP_5_2=NO
_CUSTOM_CONFIG_PHP_5_3=NO
#_CUSTOM_CONFIG_PHP_5_3=YES
_SPEED_VALID_MAX=3600
_NGINX_DOS_LIMIT=300
#_SYSTEM_UPGRADE_ONLY=YES
_SYSTEM_UPGRADE_ONLY=NO
_USE_MEMCACHED=NO
_NEWRELIC_KEY=
_USE_STOCK=NO
###
### Configuration created on 121215-1545
### with Barracuda version BOA-2.0.4
###
_EXTRA_PACKAGES=
_PHP_EXTRA_CONF=""
_STRONG_PASSWORDS=NO
_DB_BINARY_LOG=NO
_DB_ENGINE=InnoDB
_NGINX_LDAP=NO
_PHP_GEOS=NO
_PHP_MONGODB=NO
_AEGIR_UPGRADE_ONLY=NO
### Squeeze to Wheezy upgrade config
### See https://trac.transitionnetwork.org/trac/ticket/535
#_SQUEEZE_TO_WHEEZY=YES
_SQUEEZE_TO_WHEEZY=NO
_NGINX_FORWARD_SECRECY=YES
_NGINX_SPDY=YES
#_BUILD_FROM_SRC=NO
_NGINX_NAXSI=NO
_PHP_ZEND_OPCACHE=YES
_PERMISSIONS_FIX=YES
_MODULES_FIX=YES
_MODULES_SKIP=""
_SSL_FROM_SOURCES=NO
_SSH_FROM_SOURCES=NO
_RESERVED_RAM=0
&lt;/pre&gt;&lt;p&gt;
After the upgrade has been done this should be run: &lt;tt&gt;/usr/local/bin/BOND.sh&lt;/tt&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Mon, 31 Mar 2014 14:54:37 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:6</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.05&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.25&lt;/em&gt; to &lt;em&gt;1.3&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I notice &lt;a class="ext-link" href="https://twitter.com/omega8cc/status/450600502942658560"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;this tweet&lt;/a&gt; by &lt;a class="ext-link" href="https://twitter.com/omega8cc"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;@omega8cc&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
We are working on some Known Issues affecting systems upgraded to BOA-2.2.0 release: &lt;a class="ext-link" href="http://bit.ly/1rXl2ND"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/1rXl2ND&lt;/a&gt;  #Drupal #Aegir
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Which points to this section of the change log:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
# Known Issues on systems upgraded to BOA-2.2.0 release (work in progress)
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
==&amp;gt; Updated on Mon Mar 31 19:37:24 SGT 2014.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;&lt;li&gt;Compass Tools don't use correct paths to Ruby 2.1.1
&lt;/li&gt;&lt;li&gt;Chive Authentication via SSH session doesn't work on some older instances.
&lt;/li&gt;&lt;li&gt;PHP: Disabled 'create_function' may break some contrib modules or code.
&lt;/li&gt;&lt;li&gt;The drush @foo.com generate-makefile command may not work on some systems.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
So I know you're keen to get PHP and NginX updated ASAP, but I think it'd pay to wait until later this week to do the update -- more issues/tweaks will almost certainly crop up.
&lt;/p&gt;
&lt;p&gt;
FWIW I tend do do my system BOA update between 1 and 2 weeks after the release as in the past I've only had to do it again a few days later... And I like to spend &amp;lt;1h per month dicking around with my server ideally!
&lt;/p&gt;
&lt;p&gt;
Your call, obvs, but it might generate extra faff by going 'early'.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 15:38:09 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:7</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:7</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.3&lt;/em&gt; to &lt;em&gt;1.4&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:6" title="Comment 6 for Ticket #707"&gt;jim&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;PHP: Disabled 'create_function' may break some contrib modules or code.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Is the above an issue for us?
&lt;/p&gt;
&lt;p&gt;
It would be nice to get the update done in this fiancial year...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Mon, 31 Mar 2014 15:46:06 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:8</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:8</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.4&lt;/em&gt; to &lt;em&gt;1.55&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
It could be... Without testing I don't know. Unfortunately we're in the PHP5.2-based world of Drupal 6, so the risk is much higher...
&lt;/p&gt;
&lt;p&gt;
This &lt;a class="ext-link" href="https://www.google.co.uk/search?q=site:drupalcontrib.org+create_function"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;search for create_function within drupalcontrib.org&lt;/a&gt; brings back 91 results including references to Views Bulk Operations and Pathologic on the first 2 pages, both of which we use.
&lt;/p&gt;
&lt;p&gt;
So I'd rate this risk as 'high' on this one, unfortunately...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 16:53:23 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:9</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:9</guid>
      <description>
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:8" title="Comment 8 for Ticket #707"&gt;jim&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
It could be... Without testing I don't know. Unfortunately we're in the PHP5.2-based world of Drupal 6, so the risk is much higher...
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
That includes 5.3?
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
So I'd rate this risk as 'high' on this one, unfortunately...
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;
OK, lets leave it till next month sometime.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 17:03:57 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:10</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:10</guid>
      <description>
        &lt;p&gt;
FWIW they have just tweeted:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
We have fixed 3 Known Issues in BOA-2.2.0 &lt;a class="ext-link" href="http://t.co/LjUlFkl8q7"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://t.co/LjUlFkl8q7&lt;/a&gt; #Aegir #Drupal
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 17:06:45 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:11</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:11</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.55&lt;/em&gt; to &lt;em&gt;1.7&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The oustanding issues are not ones which affect us AFAIK:
&lt;/p&gt;
&lt;pre class="wiki"&gt;==&amp;gt; Updated on Mon Mar 31 12:39:35 EDT 2014
  @=&amp;gt; Issues hot-fixed in stable (run 'barracuda up-stable system' to apply):
  * Compass Tools don't use correct paths to Ruby 2.1.1
  * Chive Authentication via SSH session doesn't work on some older instances.
  * PHP: Disabled 'create_function' may break some contrib modules or code.
  @=&amp;gt; Issues waiting for a fix:
  * The 'git pull' command is broken in limited shell.
  * The drush @foo.com generate-makefile command may not work on some systems.
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 01 Apr 2014 09:43:48 GMT</pubDate>
      <title>summary changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:12</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:12</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;summary&lt;/strong&gt;
                changed from &lt;em&gt;Upgrade to BOA-2.2.0&lt;/em&gt; to &lt;em&gt;Upgrade to BOA-2.2.1&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
BOA-2.2.1 is now out:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;blockquote&gt;
&lt;p&gt;
We are happy to release BOA-2.2.1 Full Edition, which includes only bug fixes to address a few issues discovered after recent major BOA-2.2.0 Release.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
### Stable BOA-2.2.1 Release - Full Edition
### Date: Tue Apr  1 10:28:45 SGT 2014
### Includes Aegir 2.x-boa-custom version.
&lt;/p&gt;
&lt;p&gt;
# Release Notes:
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
This is a bug-fix only release to address issues discovered after recent
major BOA-2.2.0 Release.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
# Fixes in this release:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Chive Authentication via SSH session doesn't work on some older instances.
&lt;/li&gt;&lt;li&gt;Compass Tools don't use correct paths to Ruby 2.1.1
&lt;/li&gt;&lt;li&gt;Cron for sites doesn't work on old instances without Nginx wildcard vhost.
&lt;/li&gt;&lt;li&gt;FTPS (FTP over SSL) connections may experience TLS problems.
&lt;/li&gt;&lt;li&gt;PHP: Disabled 'assert' may cause warnings on features revert.
&lt;/li&gt;&lt;li&gt;PHP: Disabled 'create_function' may break some contrib modules or code.
&lt;/li&gt;&lt;li&gt;The 'git pull' command is broken in limited shell.
&lt;/li&gt;&lt;li&gt;The 'rsync' command is broken in limited shell.
&lt;/li&gt;&lt;li&gt;The 'drush dl foo' command can't be run outside of site directory.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
You can read the full changelog as always at: &lt;a class="ext-link" href="http://bit.ly/newboa"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/newboa&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://omega8.cc/boa-221-full-edition-305"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://omega8.cc/boa-221-full-edition-305&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 03 Apr 2014 08:27:29 GMT</pubDate>
      <title>attachment set</title>
      <link>http://localhost:8080/trac/ticket/707</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;attachment&lt;/strong&gt;
                set to &lt;em&gt;puffin_2014-04-03_redis_dbs-day.png&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 03 Apr 2014 08:42:50 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:13</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:13</guid>
      <description>
        &lt;p&gt;
It's been noted on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/604" title="maintenance: Times for admin tasks (closed: invalid)"&gt;ticket:604&lt;/a&gt; that the site is always slow first thing in the morning and that this is probably due to the Redis cache being "reset" at midnight each night:
&lt;/p&gt;
&lt;p&gt;
&lt;a style="padding:0; border:none" href="http://localhost:8080/trac/attachment/ticket/707/puffin_2014-04-03_redis_dbs-day.png"&gt;&lt;img src="http://localhost:8080/trac/raw-attachment/ticket/707/puffin_2014-04-03_redis_dbs-day.png" /&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
According to the BOA maintainers this "feature" should be &lt;a class="ext-link" href="https://drupal.org/comment/8280341#comment-8280341"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;fixed in the new BOA version&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The &lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/HEAD:/CHANGELOG.txt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;BOA-2.2.1 CHANGELOG.txt&lt;/a&gt; contains:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l433"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;433&lt;/a&gt;  * Redis: Integration module (the modern variant) upgrade to 7.x-2.x-o8-2.6-A
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l434"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;434&lt;/a&gt;  * Redis: Use modern version with enabled fast lock and aggressive flush mode.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
And:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l546"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;546&lt;/a&gt;  * Redis: Auto-Restart if socket is missing only when socket mode is enabled.
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l547"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;547&lt;/a&gt;  * Redis: Exclude cache_form bin or it will break modules like ajax_comments.
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l548"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;548&lt;/a&gt;  * Redis: Force clean restart daily, with long enough sleep time.
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l549"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;549&lt;/a&gt;  * Redis: Restore pwd protection.
&lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob/289cadd8932bf568a999a85e17e281c1d0e4079b:/CHANGELOG.txt#l550"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;550&lt;/a&gt;  * Redis: The cache_metatag bin needs aggressive flush mode -- see #2062379
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Mon, 07 Apr 2014 08:16:51 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:14</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:14</guid>
      <description>
        &lt;p&gt;
FWIW I did the update last night &lt;tt&gt;barracuda up-stable&lt;/tt&gt; followed by &lt;tt&gt;octopus up-stable all&lt;/tt&gt; on Babylon and it all went very well. Took about 1/2 an hour.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Mon, 07 Apr 2014 08:26:23 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:15</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:15</guid>
      <description>
        &lt;p&gt;
And the chart Chris posted 2 comments up is actually more showing Drupal clearing its page caches every 12 hours, rather than the 3-4am system tasks. The latter is represented by a small dip in stored data, but the big drops are the 12-hourly Drupal 'system' cron tasks...
&lt;/p&gt;
&lt;p&gt;
These were once an hour, [&lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/590#comment:37"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tech.transitionnetwork.org/trac/ticket/590#comment:37&lt;/a&gt; now 12 hourly as part of work on 590 (part M) in the 'cleanup' Elysia cron job.
&lt;/p&gt;
&lt;p&gt;
This remains a limitation with Drupal 6's caching infrastructure, though one I think the Redis module maintainers appear to have attempted to mitigate: &lt;a class="ext-link" href="https://drupal.org/node/1875584"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/1875584&lt;/a&gt; &amp;lt;-- hopefully this comes along with 2.2.1...
&lt;/p&gt;
&lt;p&gt;
We can open a ticket to follow up this aspect another time if necessary.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Mon, 07 Apr 2014 08:26:29 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:16</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:16</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.7&lt;/em&gt; to &lt;em&gt;1.8&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 07 Apr 2014 10:39:03 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:17</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:17</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.8&lt;/em&gt; to &lt;em&gt;1.95&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:15" title="Comment 15 for Ticket #707"&gt;jim&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
the chart Chris posted 2 comments up is actually more showing Drupal clearing its page caches every 12 hours
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Ah, I had missed that it is every 12 hours, but it is also the case that Redis is killed and restarted at around ten past midnight each night, this can be seen in the &lt;tt&gt;/var/log/redis/redis-server.log&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[59475] 07 Apr 00:10:04.156 # User requested shutdown...
[59475] 07 Apr 00:10:05.699 # Redis is now ready to exit, bye bye...
[20917] 07 Apr 00:10:06.777 # Server started, Redis version 2.6.16
&lt;/pre&gt;&lt;p&gt;
This is caused by the &lt;tt&gt;/var/xdrago/mysql_backup.sh&lt;/tt&gt; script which contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;/etc/init.d/redis-server stop
killall -9 redis-server
rm -f /var/run/redis.pid
rm -f /var/lib/redis/*
/etc/init.d/redis-server start
echo "Redis server restarted"
&lt;/pre&gt;&lt;p&gt;
And this is set to run via this root crontab:
&lt;/p&gt;
&lt;pre class="wiki"&gt;08 0 * * * bash /var/xdrago/mysql_backup.sh &amp;gt;/dev/null 2&amp;gt;&amp;amp;1
&lt;/pre&gt;&lt;p&gt;
This isn't how Redis is designed to work:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Redis is designed to be a very long running process in your server.
&lt;/p&gt;
&lt;p&gt;
​&lt;a class="ext-link" href="http://redis.io/topics/admin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://redis.io/topics/admin&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
But as Jim has pointed out the effect of Drupal clearing it's cache seems to be the main cause of the Redis cache being emptied.
&lt;/p&gt;
&lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:14" title="Comment 14 for Ticket #707"&gt;jim&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
FWIW I did the update last night &lt;tt&gt;barracuda up-stable&lt;/tt&gt; followed by &lt;tt&gt;octopus up-stable all&lt;/tt&gt; on Babylon and it all went very well.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Do you think it would be safe to update Puffin to the latest BOA, or should we wait some more?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 08 Apr 2014 19:55:16 GMT</pubDate>
      <title>hours, totalhours, summary changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:18</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:18</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.95&lt;/em&gt; to &lt;em&gt;2.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;summary&lt;/strong&gt;
                changed from &lt;em&gt;Upgrade to BOA-2.2.1&lt;/em&gt; to &lt;em&gt;Upgrade to BOA-2.2.2&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I'm tempted to do the upgrade tonight... or should we wait some more... Jim?
&lt;/p&gt;
&lt;p&gt;
New version of BOA, from the &lt;a class="ext-link" href="http://drupalcode.org/project/barracuda.git/blob_plain/HEAD:/CHANGELOG.txt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;CHANGELOG.txt&lt;/a&gt;, note the heartbleed issues are being addressed on &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/692#comment:18" title="maintenance: Debian Updates (new)"&gt;ticket:692#comment:18&lt;/a&gt;.
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.2.2 Release - Barracuda Edition
### Date: Tue Apr  8 07:24:18 PDT 2014
### Includes Aegir 2.x-boa-custom version.
# Release Notes:
  This is a bug-fix only release to address issues discovered after recent
  major BOA-2.2.0 Release and subsequent BOA-2.2.1 release.
  The most important problem fixed in this Release is related to known OpenSSL
  security issue, which has been fixed in OpenSSL 1.0.1g
  To learn more please visit: http://heartbleed.com
  @=&amp;gt; Note for those on self-hosted BOA (skip this if you are on a hosted Aegir)
  We recommend that you enable _SSL_FROM_SOURCES=YES option in your system
  /root/.barracuda.cnf file, to always build latest OpenSSL from sources.
  Note that it will also trigger OpenSSH and cURL install from sources, plus
  subsequent PHP rebuild to include latest SSL libraries.
  This Release doesn't include any updates to the Octopus installer, so there is
  no point in running full upgrade. It is enough to run the barracuda only,
  system upgrade in the "silent mode" with:
  $ screen
  $ barracuda up-stable system
  The system will send you an e-mail with results when the upgrade is complete,
  but there will be no upgrade progress displayed in the console. You can watch
  it, if you prefer, with command (DATE/TIME are placeholders for real values):
  $ tail -f /var/backups/reports/up/barracuda/DATE/barracuda-up-DATE-TIME.log
# System upgrades in this release:
  * Nginx 1.5.13
  * OpenSSL 1.0.1g (if installed from sources)
  * PHP 5.4.27
  * PHP 5.5.11
# Fixes in this release:
  * Chive Authentication via SSH session may break Nginx due to race conditions.
  * Drush specific dt() wrapper is required in Provision for custom platforms.
  * Fix Compass Tools support for Omega (gems dependencies via bundle install).
  * Fix default shell for system level cron tasks.
  * Fix for csf firewall compatibility test.
  * Force better health check on protected vhosts on live SSH-auth update.
  * Issue #2229555 - On fresh boa install link missing durring install.
  * Issue #2229715 - Tasks queue doesn't work on the Master Instance.
  * Issue #2231093 - Add new line before 'UseDNS no' in the sshd_config file.
  * Issue #294 - New Relic ext not installed even if _NEWRELIC_KEY is not empty.
  * Nginx: Backup and re-create default wildcard SSL cert/key with rsa:4096
  * Nginx: Generate 4096 bit long DH parameters when _NGINX_FORWARD_SECRECY=YES
  * PHP: Better default workers limits for the ondemand mode.
  * PHP: max_input_time should be set to 180 and not 60, by default.
  * PHP: Zend OPcache directive opcache.enable=1 must be set in all ini files.
  * The 'scp' command is broken in limited shell.
  * Too broad whitelisting breaks commands in limited shell with 'tmp' keyword.
  * Too restrictive open_basedir defaults break access to valid PEAR paths.
  * Too restrictive open_basedir defaults break access to valid Tika paths.
  * Use rsa:4096 by default in self-signed certs for Nginx and FTPS.
&lt;/pre&gt;&lt;p&gt;
I don't think we should do this, I think we are better off using the Debian packages for OpenSSL and OpenSSH:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
We recommend that you enable _SSL_FROM_SOURCES=YES option in your system
/root/.barracuda.cnf file, to always build latest OpenSSL from sources.
Note that it will also trigger OpenSSH and cURL install from sources, plus
subsequent PHP rebuild to include latest SSL libraries.
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 11 Apr 2014 20:47:31 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:19</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:19</guid>
      <description>
        &lt;p&gt;
Going to do the BOA upgrade now.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 11 Apr 2014 22:26:02 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:20</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:20</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.64&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.2&lt;/em&gt; to &lt;em&gt;3.84&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have just changed this setting from NO, due to recent events.
&lt;/p&gt;
&lt;pre class="wiki"&gt;_STRONG_PASSWORDS=YES
&lt;/pre&gt;&lt;p&gt;
Here is the &lt;tt&gt;/root/.barracuda.cnf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;###
### Configuration created on 121215-1545
### with Barracuda version BOA-2.0.4
###
### NOTE: the group of settings displayed bellow will *not* be overriden
### on upgrade by the Barracuda script nor by this configuration file.
### They can be defined only on initial Barracuda install.
###
_HTTP_WILDCARD=YES
_MY_OWNIP="81.95.52.103"
#_MY_OWNIP=""
_MY_HOSTN="puffin.webarch.net"
#_MY_HOSTN=""
_MY_FRONT="master.puffin.webarch.net"
_THIS_DB_HOST=localhost
#_THIS_DB_HOST=FQDN
_SMTP_RELAY_TEST=YES
_SMTP_RELAY_HOST=""
_LOCAL_NETWORK_IP=""
_LOCAL_NETWORK_HN=""
###
### NOTE: the group of settings displayed bellow
### will *override* all listed settings in the Barracuda script,
### both on initial install and upgrade.
###
_MY_EMAIL="chris@webarchitects.co.uk"
_XTRAS_LIST="PDS CSF CHV"
_AUTOPILOT=NO
_DEBUG_MODE=NO
_DB_SERVER=MariaDB
_SSH_PORT=22
_LOCAL_DEBIAN_MIRROR="ftp.debian.org"
_LOCAL_UBUNTU_MIRROR="archive.ubuntu.com"
_FORCE_GIT_MIRROR=""
_DNS_SETUP_TEST=YES
_NGINX_EXTRA_CONF=""
_NGINX_WORKERS=AUTO
_PHP_FPM_WORKERS=AUTO
#_BUILD_FROM_SRC=YES
_BUILD_FROM_SRC=NO
_PHP_MODERN_ONLY=YES
_PHP_FPM_VERSION=5.3
_PHP_CLI_VERSION=5.3
#_LOAD_LIMIT_ONE=1444
#_LOAD_LIMIT_TWO=888
_LOAD_LIMIT_ONE=8664
_LOAD_LIMIT_TWO=5328
_CUSTOM_CONFIG_CSF=YES
_CUSTOM_CONFIG_SQL=NO
#_CUSTOM_CONFIG_SQL=YES
_CUSTOM_CONFIG_REDIS=NO
_CUSTOM_CONFIG_PHP_5_2=NO
_CUSTOM_CONFIG_PHP_5_3=NO
#_CUSTOM_CONFIG_PHP_5_3=YES
_SPEED_VALID_MAX=3600
_NGINX_DOS_LIMIT=300
#_SYSTEM_UPGRADE_ONLY=YES
_SYSTEM_UPGRADE_ONLY=NO
_USE_MEMCACHED=NO
_NEWRELIC_KEY=
_USE_STOCK=NO
###
### Configuration created on 121215-1545
### with Barracuda version BOA-2.0.4
###
_EXTRA_PACKAGES=
_PHP_EXTRA_CONF=""
_STRONG_PASSWORDS=YES
_DB_BINARY_LOG=NO
_DB_ENGINE=InnoDB
_NGINX_LDAP=NO
_PHP_GEOS=NO
_PHP_MONGODB=NO
_AEGIR_UPGRADE_ONLY=NO
### Squeeze to Wheezy upgrade config
### See https://trac.transitionnetwork.org/trac/ticket/535
#_SQUEEZE_TO_WHEEZY=YES
_SQUEEZE_TO_WHEEZY=NO
_NGINX_FORWARD_SECRECY=YES
_NGINX_SPDY=YES
#_BUILD_FROM_SRC=NO
_NGINX_NAXSI=NO
_PHP_ZEND_OPCACHE=YES
_PERMISSIONS_FIX=YES
_MODULES_FIX=YES
_MODULES_SKIP=""
_SSL_FROM_SOURCES=NO
_SSH_FROM_SOURCES=NO
_RESERVED_RAM=0
&lt;/pre&gt;&lt;p&gt;
Following the notes, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#UpgradingBOA"&gt;wiki:PuffinServer#UpgradingBOA&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;sudo -i
screen
cd
wget -q -U iCab http://files.aegir.cc/BOA.sh.txt
bash BOA.sh.txt
  BOA Meta Installer setup completed
  Please check INSTALL.txt and UPGRADE.txt at http://bit.ly/boa-docs for how-to
  Bye
barracuda up-stable
  Another BOA installer is running probably - /var/run/boa_run.pid exists
ls -lah /var/run/boa_run.pid
  -rw-r--r-- 1 root root 0 Mar 31 14:03 /var/run/boa_run.pid
rm /var/run/boa_run.pid
barracuda up-stable
  Barracuda [Fri Apr 11 21:55:47 BST 2014] ==&amp;gt; BOA Skynet welcomes you aboard!
  Barracuda [Fri Apr 11 21:55:51 BST 2014] ==&amp;gt; INFO: UPGRADE
  Barracuda [Fri Apr 11 21:55:51 BST 2014] ==&amp;gt; INFO: Reading your /root/.barracuda.cnf config file
  Barracuda [Fri Apr 11 21:55:52 BST 2014] ==&amp;gt; NOTE! Please review all config options displayed below
  Barracuda [Fri Apr 11 21:55:52 BST 2014] ==&amp;gt; NOTE! It will *override* all settings in the Barracuda script
  Barracuda [Fri Apr 11 21:55:53 BST 2014] ==&amp;gt; Legacy PHP-CLI 5.2 is not used on this system
  Barracuda [Fri Apr 11 21:55:53 BST 2014] ==&amp;gt; Legacy PHP-FPM 5.2 is not used on this system
  ###
  ### Configuration created on 121215-1545
  ### with Barracuda version BOA-2.0.4
  ###
  ### NOTE: the group of settings displayed bellow will *not* be overriden
  ### on upgrade by the Barracuda script nor by this configuration file.
  ### They can be defined only on initial Barracuda install.
  ###
  _HTTP_WILDCARD=YES
  _MY_OWNIP="81.95.52.103"
  #_MY_OWNIP=""
  _MY_HOSTN="puffin.webarch.net"
  #_MY_HOSTN=""
  _MY_FRONT="master.puffin.webarch.net"
  _THIS_DB_HOST=localhost
  #_THIS_DB_HOST=FQDN
  _SMTP_RELAY_TEST=YES
  _SMTP_RELAY_HOST=""
  _LOCAL_NETWORK_IP=""
  _LOCAL_NETWORK_HN=""
  ###
  ### NOTE: the group of settings displayed bellow
  ### will *override* all listed settings in the Barracuda script,
  ### both on initial install and upgrade.
  ###
  _MY_EMAIL="chris@webarchitects.co.uk"
  _XTRAS_LIST="PDS CSF CHV"
  _AUTOPILOT=NO
  _DEBUG_MODE=NO
  _DB_SERVER=MariaDB
  _SSH_PORT=22
  _LOCAL_DEBIAN_MIRROR="ftp.debian.org"
  _LOCAL_UBUNTU_MIRROR="archive.ubuntu.com"
  _FORCE_GIT_MIRROR=""
  _DNS_SETUP_TEST=YES
  _NGINX_EXTRA_CONF=""
  _NGINX_WORKERS=AUTO
  _PHP_FPM_WORKERS=AUTO
  _PHP_FPM_VERSION=5.3
  _PHP_CLI_VERSION=5.3
  _CUSTOM_CONFIG_CSF=YES
  _CUSTOM_CONFIG_SQL=NO
  #_CUSTOM_CONFIG_SQL=YES
  _CUSTOM_CONFIG_REDIS=NO
  _CUSTOM_CONFIG_PHP_5_2=NO
  _CUSTOM_CONFIG_PHP_5_3=NO
  #_CUSTOM_CONFIG_PHP_5_3=YES
  _SPEED_VALID_MAX=3600
  _NGINX_DOS_LIMIT=300
  #_SYSTEM_UPGRADE_ONLY=YES
  _SYSTEM_UPGRADE_ONLY=NO
  _NEWRELIC_KEY=
  _USE_STOCK=NO
  ###
  ### Configuration created on 121215-1545
  ### with Barracuda version BOA-2.0.4
  ###
  _EXTRA_PACKAGES=
  _PHP_EXTRA_CONF=""
  _STRONG_PASSWORDS=YES
  _DB_BINARY_LOG=NO
  _DB_ENGINE=InnoDB
  _NGINX_LDAP=NO
  _PHP_GEOS=NO
  _PHP_MONGODB=NO
  _AEGIR_UPGRADE_ONLY=NO
  ### Squeeze to Wheezy upgrade config
  ### See https://trac.transitionnetwork.org/trac/ticket/535
  #_SQUEEZE_TO_WHEEZY=YES
  _SQUEEZE_TO_WHEEZY=NO
  _NGINX_FORWARD_SECRECY=YES
  _NGINX_SPDY=YES
  _NGINX_NAXSI=NO
  _PERMISSIONS_FIX=YES
  _MODULES_FIX=YES
  _MODULES_SKIP=""
  _SSL_FROM_SOURCES=NO
  _SSH_FROM_SOURCES=NO
  _RESERVED_RAM=0
  _PHP_MULTI_INSTALL="5.3"
  _CUSTOM_CONFIG_LSHELL=NO
  _CUSTOM_CONFIG_PHP55=NO
  _CUSTOM_CONFIG_PHP54=NO
  _CUSTOM_CONFIG_PHP53=NO
  _CUSTOM_CONFIG_PHP52=NO
  _CPU_SPIDER_RATIO=3
  _CPU_MAX_RATIO=6
  _CPU_CRIT_RATIO=9
  _PHP_FPM_DENY=""
  _REDIS_LISTEN_MODE=PORT
  _STRICT_BIN_PERMISSIONS=YES
  Do you want to proceed with the upgrade? [Y/n] Y
  Barracuda [Fri Apr 11 21:56:48 BST 2014] ==&amp;gt; INFO: Checking your system version...
  Barracuda [Fri Apr 11 21:56:49 BST 2014] ==&amp;gt; Aegir on Debian/wheezy - Skynet Agent v.BOA-2.2.2
  Barracuda [Fri Apr 11 21:56:49 BST 2014] ==&amp;gt; INFO: Updating packages sources list...
  Barracuda [Fri Apr 11 21:56:49 BST 2014] ==&amp;gt; INFO: We will use Debian mirror ftp.debian.org
  Barracuda [Fri Apr 11 21:57:03 BST 2014] ==&amp;gt; INFO: Downloading little helpers...
  Barracuda [Fri Apr 11 21:57:04 BST 2014] ==&amp;gt; INFO: Checking BARRACUDA version...
  Barracuda [Fri Apr 11 21:57:04 BST 2014] ==&amp;gt; INFO: BARRACUDA version test: OK
  Barracuda [Fri Apr 11 21:57:05 BST 2014] ==&amp;gt; UPGRADE START -&amp;gt; checkpoint:
    * Your e-mail address appears to be chris@webarchitects.co.uk - is that correct?
    * Your server hostname is puffin.webarch.net.
    * Your Aegir control panel is/will be available at https://master.puffin.webarch.net.
  Do you want to proceed with the upgrade? [Y/n] Y
  Barracuda [Fri Apr 11 21:57:45 BST 2014] ==&amp;gt; INFO: Cleaning up temp files in /var/opt/
  Barracuda [Fri Apr 11 21:57:45 BST 2014] ==&amp;gt; INFO: Installing extra Drush versions
  Barracuda [Fri Apr 11 21:57:45 BST 2014] ==&amp;gt; INFO: Drush mini-4-14-03-2014 installation complete
  Barracuda [Fri Apr 11 21:57:46 BST 2014] ==&amp;gt; INFO: Drush mini-6-01-04-2014 installation complete
  Barracuda [Fri Apr 11 21:57:52 BST 2014] ==&amp;gt; INFO: Running aptitude update...
  Barracuda [Fri Apr 11 21:58:39 BST 2014] ==&amp;gt; INFO: Upgrading required libraries and tools
  Barracuda [Fri Apr 11 21:58:39 BST 2014] ==&amp;gt; NOTE! This step may take a few minutes, please wait...
  Barracuda [Fri Apr 11 21:59:39 BST 2014] ==&amp;gt; INFO: Testing Nginx version...
  Barracuda [Fri Apr 11 21:59:39 BST 2014] ==&amp;gt; INFO: Installed Nginx version nginx/1.5.7, upgrade required
  Barracuda [Fri Apr 11 21:59:40 BST 2014] ==&amp;gt; INFO: Upgrading Nginx...
  Barracuda [Fri Apr 11 22:00:54 BST 2014] ==&amp;gt; INFO: Running aptitude full-upgrade, please wait...
  Barracuda [Fri Apr 11 22:01:54 BST 2014] ==&amp;gt; INFO: Testing Nginx version...
  Barracuda [Fri Apr 11 22:01:54 BST 2014] ==&amp;gt; INFO: Installed Nginx version nginx/1.5.13, OK
  Barracuda [Fri Apr 11 22:01:54 BST 2014] ==&amp;gt; INFO: Installing MySecureShell 1.32...
  Barracuda [Fri Apr 11 22:02:22 BST 2014] ==&amp;gt; INFO: Installing /usr/bin/wkhtmltopdf x86_64 version...
  Barracuda [Fri Apr 11 22:02:28 BST 2014] ==&amp;gt; INFO: Installing /usr/bin/wkhtmltoimage x86_64 version...
  Barracuda [Fri Apr 11 22:02:34 BST 2014] ==&amp;gt; INFO: Fix #1 for libs in Debian wheezy
  Barracuda [Fri Apr 11 22:02:35 BST 2014] ==&amp;gt; INFO: Checking SMTP connections...
  Barracuda [Fri Apr 11 22:02:35 BST 2014] ==&amp;gt; INFO: Installing VnStat monitor...
  Barracuda [Fri Apr 11 22:02:44 BST 2014] ==&amp;gt; INFO: Upgrading a few more tools...
  Barracuda [Fri Apr 11 22:02:46 BST 2014] ==&amp;gt; INFO: Checking if PHP upgrade is available
  Barracuda [Fri Apr 11 22:02:53 BST 2014] ==&amp;gt; INFO: PHP EXTRA is --with-ldap --with-gmp
  Barracuda [Fri Apr 11 22:02:53 BST 2014] ==&amp;gt; INFO: PHP 5.3.28 will be installed now
  Barracuda [Fri Apr 11 22:02:53 BST 2014] ==&amp;gt; INFO: Installing PHP-FPM 5.3.28
  Barracuda [Fri Apr 11 22:02:53 BST 2014] ==&amp;gt; NOTE! This step may take longer than 8 minutes, please wait...
  Barracuda [Fri Apr 11 22:03:03 BST 2014] ==&amp;gt; INFO: Installing PHP-FPM 5.3.28 part 1/3
  Barracuda [Fri Apr 11 22:03:04 BST 2014] ==&amp;gt; INFO: Installing PHP-FPM 5.3.28 part 2/3
  Barracuda [Fri Apr 11 22:04:59 BST 2014] ==&amp;gt; INFO: Installing PHP-FPM 5.3.28 part 3/3
  Barracuda [Fri Apr 11 22:17:39 BST 2014] ==&amp;gt; INFO: Installing Zend OPcache for PHP-FPM 5.3.28...
  Barracuda [Fri Apr 11 22:18:02 BST 2014] ==&amp;gt; INFO: Installing PhpRedis for PHP-FPM 5.3.28...
  Barracuda [Fri Apr 11 22:18:23 BST 2014] ==&amp;gt; INFO: Installing UploadProgress for PHP-FPM 5.3.28...
  Barracuda [Fri Apr 11 22:18:34 BST 2014] ==&amp;gt; INFO: Installing JSMin for PHP-FPM 5.3.28...
  Barracuda [Fri Apr 11 22:18:46 BST 2014] ==&amp;gt; INFO: Installing Imagick for PHP-FPM 5.3.28...
  Barracuda [Fri Apr 11 22:19:09 BST 2014] ==&amp;gt; INFO: Installing MailParse for PHP-FPM 5.3.28...
  Barracuda [Fri Apr 11 22:19:23 BST 2014] ==&amp;gt; INFO: Installing IonCube x86_64 version for PHP-FPM...
  Barracuda [Fri Apr 11 22:19:27 BST 2014] ==&amp;gt; INFO: Upgrading Limited Shell to version 0.9.16.5-om8...
  Barracuda [Fri Apr 11 22:19:30 BST 2014] ==&amp;gt; INFO: Installed Redis version 2.6.16, upgrade required
  Barracuda [Fri Apr 11 22:19:30 BST 2014] ==&amp;gt; INFO: Installing Redis update for Debian/wheezy...
  Barracuda [Fri Apr 11 22:20:41 BST 2014] ==&amp;gt; INFO: Generating random password for Redis server
  Barracuda [Fri Apr 11 22:20:42 BST 2014] ==&amp;gt; INFO: Updating MariaDB and PHP configuration
  Barracuda [Fri Apr 11 22:20:43 BST 2014] ==&amp;gt; INFO: Running MySQLTuner check on all databases...
  Barracuda [Fri Apr 11 22:20:43 BST 2014] ==&amp;gt; NOTE! This step may take a LONG time, please wait...
  Barracuda [Fri Apr 11 22:20:47 BST 2014] ==&amp;gt; INFO: OS and services upgrade completed
  Barracuda [Fri Apr 11 22:20:47 BST 2014] ==&amp;gt; INFO: Restarting MariaDB server, please wait...
  Barracuda [Fri Apr 11 22:21:05 BST 2014] ==&amp;gt; INFO: Upgrading MariaDB tables if necessary, please wait a minute...
  Do you want to upgrade Aegir Master Instance? [Y/n]  Y
  Barracuda [Fri Apr 11 22:24:01 BST 2014] ==&amp;gt; INFO: Running Aegir Master Instance upgrade
  Barracuda [Fri Apr 11 22:24:02 BST 2014] ==&amp;gt; INFO: Syncing provision backend db_passwd...
  Barracuda [Fri Apr 11 22:24:04 BST 2014] ==&amp;gt; INFO: Running hosting-dispatch (1/3)...
  Barracuda [Fri Apr 11 22:24:17 BST 2014] ==&amp;gt; INFO: Running hosting-dispatch (2/3)...
  Barracuda [Fri Apr 11 22:24:24 BST 2014] ==&amp;gt; INFO: Running hosting-dispatch (3/3)...
  Barracuda [Fri Apr 11 22:24:24 BST 2014] ==&amp;gt; INFO: Syncing hostmaster frontend db_passwd...
  Barracuda [Fri Apr 11 22:24:25 BST 2014] ==&amp;gt; INFO: Testing previous install...
  Barracuda [Fri Apr 11 22:24:25 BST 2014] ==&amp;gt; INFO: Test OK, we can proceed with Hostmaster upgrade
  Barracuda [Fri Apr 11 22:24:25 BST 2014] ==&amp;gt; INFO: Moving old directories
  Barracuda [Fri Apr 11 22:24:25 BST 2014] ==&amp;gt; INFO: Downloading drush...
  Barracuda [Fri Apr 11 22:24:26 BST 2014] ==&amp;gt; INFO: Drush seems to be functioning properly
  Barracuda [Fri Apr 11 22:24:26 BST 2014] ==&amp;gt; INFO: Installing provision backend in /var/aegir/.drush
  Barracuda [Fri Apr 11 22:24:26 BST 2014] ==&amp;gt; INFO: Downloading Drush and Provision extensions...
  Barracuda [Fri Apr 11 22:24:26 BST 2014] ==&amp;gt; INFO: Running hostmaster-migrate, please wait...
  Barracuda [Fri Apr 11 22:24:55 BST 2014] ==&amp;gt; INFO: Syncing hostmaster frontend db_passwd...
  Barracuda [Fri Apr 11 22:25:33 BST 2014] ==&amp;gt; INFO: Aegir Master Instance upgrade completed
  Barracuda [Fri Apr 11 22:25:37 BST 2014] ==&amp;gt; INFO: Upgrading Chive MariaDB Manager...
  Barracuda [Fri Apr 11 22:25:42 BST 2014] ==&amp;gt; INFO: Restarting Redis, PHP-FPM and Nginx
  Barracuda [Fri Apr 11 22:25:51 BST 2014] ==&amp;gt; INFO: Restarting MariaDB server
  Barracuda [Fri Apr 11 22:26:01 BST 2014] ==&amp;gt; INFO: New secure random password for MariaDB generated and updated
  Barracuda [Fri Apr 11 22:26:01 BST 2014] ==&amp;gt; INFO: New entry added to /var/log/barracuda_log.txt
  Barracuda [Fri Apr 11 22:26:01 BST 2014] ==&amp;gt; INFO: Cleaning up system swap, it may take a moment, please wait...
  Barracuda [Fri Apr 11 22:26:40 BST 2014] ==&amp;gt; CARD: Now charging your credit card for this auto-upgrade magic...
  Barracuda [Fri Apr 11 22:26:46 BST 2014] ==&amp;gt; JOKE: Just kidding! Enjoy your Aegir Hosting System :)
  Barracuda [Fri Apr 11 22:26:46 BST 2014] ==&amp;gt; Final post-upgrade cleaning, please wait a moment...
  Barracuda [Fri Apr 11 22:33:40 BST 2014] ==&amp;gt; BYE!
  BARRACUDA upgrade completed
  Bye
&lt;/pre&gt;&lt;p&gt;
While the update was running I was sent this email:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: root@puffin.webarch.net
Date: Fri, 11 Apr 2014 21:57:27 +0100 (BST)
To: chris@webarchitects.co.uk
Subject: lfd on puffin.webarch.net: System Integrity checking detected a modified system file
Time:     Fri Apr 11 21:57:27 2014 +0000
The following list of files have FAILED the md5sum comparison test. This means that the file has been changed in some way. This could be a result of an OS update or application upgrade. If the change is unexpected it should be investigated:
/usr/bin/7z: FAILED
/usr/bin/7za: FAILED
/usr/bin/Magick-config: FAILED
/usr/bin/MagickCore-config: FAILED
/usr/bin/MagickWand-config: FAILED
/usr/bin/Wand-config: FAILED
/usr/bin/add-patch: FAILED
/usr/bin/anytopnm: FAILED
/usr/bin/apt-key: FAILED
/usr/bin/aptitude-fast: FAILED
/usr/bin/autoconf2.13: FAILED
/usr/bin/autoconf2.50: FAILED
/usr/bin/autoheader2.13: FAILED
/usr/bin/autopoint: FAILED
/usr/bin/autoreconf2.13: FAILED
/usr/bin/autoupdate2.13: FAILED
/usr/bin/bashbug: FAILED
/usr/bin/batch: FAILED
/usr/bin/bison.yacc: FAILED
/usr/bin/c89: FAILED
/usr/bin/c89-gcc: FAILED
/usr/bin/c99: FAILED
/usr/bin/c99-gcc: FAILED
/usr/bin/catchsegv: FAILED
/usr/bin/checkbashisms: FAILED
/usr/bin/compile_et: FAILED
/usr/bin/conkeror: FAILED
/usr/bin/crypt: FAILED
/usr/bin/curl-config: FAILED
/usr/bin/dcmd: FAILED
/usr/bin/debconf-updatepo: FAILED
/usr/bin/debsign: FAILED
/usr/bin/dehtmldiff: FAILED
/usr/bin/dpkg-maintscript-helper: FAILED
/usr/bin/dscextract: FAILED
/usr/bin/dumphint: FAILED
/usr/bin/dvipdf: FAILED
/usr/bin/edit-patch: FAILED
/usr/bin/eps2eps: FAILED
/usr/bin/fakeroot: FAILED
/usr/bin/fakeroot-sysv: FAILED
/usr/bin/fakeroot-tcp: FAILED
/usr/bin/font2c: FAILED
/usr/bin/freetype-config: FAILED
/usr/bin/gcore: FAILED
/usr/bin/gdbtui: FAILED
/usr/bin/getbuildlog: FAILED
/usr/bin/gettext.sh: FAILED
/usr/bin/gettextize: FAILED
/usr/bin/glib-gettextize: FAILED
/usr/bin/gpg-error-config: FAILED
/usr/bin/gpg-zip: FAILED
/usr/bin/gsbj: FAILED
/usr/bin/gsdj: FAILED
/usr/bin/gsdj500: FAILED
/usr/bin/gslj: FAILED
/usr/bin/gslp: FAILED
/usr/bin/gsnd: FAILED
/usr/bin/ifnames2.13: FAILED
/usr/bin/igawk: FAILED
/usr/bin/install-info: FAILED
/usr/bin/krb5-config: FAILED
/usr/bin/lessfile: FAILED
/usr/bin/lesspipe: FAILED
/usr/bin/lft: FAILED
/usr/bin/lft.db: FAILED
/usr/bin/lftpget: FAILED
/usr/bin/libgcrypt-config: FAILED
/usr/bin/libmcrypt-config: FAILED
/usr/bin/libpng-config: FAILED
/usr/bin/libpng12-config: FAILED
/usr/bin/libtool: FAILED
/usr/bin/libtoolize: FAILED
/usr/bin/libwmf-config: FAILED
/usr/bin/lorder: FAILED
/usr/bin/lsinitramfs: FAILED
/usr/bin/lspgpot: FAILED
/usr/bin/mkfontdir: FAILED
/usr/bin/msql2mysql: FAILED
/usr/bin/mysql_config: FAILED
/usr/bin/mysql_install_db: FAILED
/usr/bin/mysql_secure_installation: FAILED
/usr/bin/mysqlaccess: FAILED
/usr/bin/mysqlbug: FAILED
/usr/bin/ncurses5-config: FAILED
/usr/bin/ncursesw5-config: FAILED
/usr/bin/neqn: FAILED
/usr/bin/net-snmp-config: FAILED
/usr/bin/nroff: FAILED
/usr/bin/on_ac_power: FAILED
/usr/bin/pamstretch-gen: FAILED
/usr/bin/pcre-config: FAILED
/usr/bin/pdf2dsc: FAILED
/usr/bin/pdf2ps: FAILED
/usr/bin/pdfopt: FAILED
/usr/bin/perldoc: FAILED
/usr/bin/pf2afm: FAILED
/usr/bin/pfbtopfa: FAILED
/usr/bin/pnminterp-gen: FAILED
/usr/bin/pnmmargin: FAILED
/usr/bin/po2debconf: FAILED
/usr/bin/pphs: FAILED
/usr/bin/ppmtomap: FAILED
/usr/bin/printafm: FAILED
/usr/bin/ps2ascii: FAILED
/usr/bin/ps2epsi: FAILED
/usr/bin/ps2pdf: FAILED
/usr/bin/ps2pdf12: FAILED
/usr/bin/ps2pdf13: FAILED
/usr/bin/ps2pdf14: FAILED
/usr/bin/ps2pdfwr: FAILED
/usr/bin/ps2ps: FAILED
/usr/bin/ps2ps2: FAILED
/usr/bin/ps2txt: FAILED
/usr/bin/rgrep: FAILED
/usr/bin/routef: FAILED
/usr/bin/routel: FAILED
/usr/bin/savelog: FAILED
/usr/bin/sensible-browser: FAILED
/usr/bin/sensible-editor: FAILED
/usr/bin/sensible-pager: FAILED
/usr/bin/sftp-kill: FAILED
/usr/bin/sftp-user: FAILED
/usr/bin/shtool: FAILED
/usr/bin/shtoolize: FAILED
/usr/bin/smbtar: FAILED
/usr/bin/ssh-argv0: FAILED
/usr/bin/ssh-copy-id: FAILED
/usr/bin/ssl-cert-check: FAILED
/usr/bin/traceproto: FAILED
/usr/bin/traceproto.db: FAILED
/usr/bin/traceroute-nanog: FAILED
/usr/bin/update-mime-database: FAILED
/usr/bin/updatedb: FAILED
/usr/bin/updatedb.findutils: FAILED
/usr/bin/valgrind: FAILED
/usr/bin/vimtutor: FAILED
/usr/bin/wftopfa: FAILED
/usr/bin/which: FAILED
/usr/bin/x-www-browser: FAILED
/usr/bin/xdg-desktop-icon: FAILED
/usr/bin/xdg-desktop-menu: FAILED
/usr/bin/xdg-email: FAILED
/usr/bin/xdg-icon-resource: FAILED
/usr/bin/xdg-mime: FAILED
/usr/bin/xdg-open: FAILED
/usr/bin/xdg-screensaver: FAILED
/usr/bin/xdg-settings: FAILED
/usr/bin/xlsview: FAILED
/usr/bin/xml2-config: FAILED
/usr/bin/xpdf: FAILED
/usr/bin/xslt-config: FAILED
/usr/bin/yacc: FAILED
/usr/bin/zipgrep: FAILED
/usr/bin/zxpdf: FAILED
/usr/sbin/add-shell: FAILED
/usr/sbin/csf: FAILED
/usr/sbin/invoke-rc.d: FAILED
/usr/sbin/locale-gen: FAILED
/usr/sbin/mkinitramfs: FAILED
/usr/sbin/ntpdate-debian: FAILED
/usr/sbin/paperconfig: FAILED
/usr/sbin/remove-shell: FAILED
/usr/sbin/service: FAILED
/usr/sbin/sync-available: FAILED
/usr/sbin/t1libconfig: FAILED
/usr/sbin/tcptraceroute: FAILED
/usr/sbin/tcptraceroute.db: FAILED
/usr/sbin/tzconfig: FAILED
/usr/sbin/update-ca-certificates: FAILED
/usr/sbin/update-fonts-alias: FAILED
/usr/sbin/update-fonts-dir: FAILED
/usr/sbin/update-fonts-scale: FAILED
/usr/sbin/update-gsfontmap: FAILED
/usr/sbin/update-icon-caches: FAILED
/usr/sbin/update-icon-caches.gtk2: FAILED
/usr/sbin/update-initramfs: FAILED
/bin/bzcmp: FAILED
/bin/bzdiff: FAILED
/bin/bzegrep: FAILED
/bin/bzexe: FAILED
/bin/bzfgrep: FAILED
/bin/bzgrep: FAILED
/bin/bzless: FAILED
/bin/bzmore: FAILED
/bin/lessfile: FAILED
/bin/lesspipe: FAILED
/bin/sh: FAILED
/bin/which: FAILED
/sbin/fsck.nfs: FAILED
/sbin/initctl: FAILED
/sbin/installkernel: FAILED
/sbin/on_ac_power: FAILED
/sbin/resolvconf: FAILED
/sbin/shadowconfig: FAILED
/usr/local/bin/barracuda: FAILED
/usr/local/bin/boa: FAILED
/usr/local/bin/octopus: FAILED
/usr/local/bin/syncpass: FAILED
/usr/local/bin/tuning-primer.sh: FAILED
/etc/init.d/README: FAILED
/etc/init.d/atd: FAILED
/etc/init.d/auditd: FAILED
/etc/init.d/bootlogd: FAILED
/etc/init.d/bootlogs: FAILED
/etc/init.d/bootmisc.sh: FAILED
/etc/init.d/checkfs.sh: FAILED
/etc/init.d/checkroot-bootclean.sh: FAILED
/etc/init.d/checkroot.sh: FAILED
/etc/init.d/chrony: FAILED
/etc/init.d/cron: FAILED
/etc/init.d/dbus: FAILED
/etc/init.d/fancontrol: FAILED
/etc/init.d/halt: FAILED
/etc/init.d/hdparm: FAILED
/etc/init.d/hostname.sh: FAILED
/etc/init.d/hwclock.sh: FAILED
/etc/init.d/ipvsadm: FAILED
/etc/init.d/killprocs: FAILED
/etc/init.d/kmod: FAILED
/etc/init.d/lm-sensors: FAILED
/etc/init.d/lvm2: FAILED
/etc/init.d/motd: FAILED
/etc/init.d/mountall-bootclean.sh: FAILED
/etc/init.d/mountall.sh: FAILED
/etc/init.d/mountdevsubfs.sh: FAILED
/etc/init.d/mountkernfs.sh: FAILED
/etc/init.d/mountnfs-bootclean.sh: FAILED
/etc/init.d/mountnfs.sh: FAILED
/etc/init.d/mtab.sh: FAILED
/etc/init.d/networking: FAILED
/etc/init.d/nginx: FAILED
/etc/init.d/ntp: FAILED
/etc/init.d/pdnsd: FAILED
/etc/init.d/php5-fpm: FAILED
/etc/init.d/php53-fpm: FAILED
/etc/init.d/postfix: FAILED
/etc/init.d/procps: FAILED
/etc/init.d/rc: FAILED
/etc/init.d/rc.local: FAILED
/etc/init.d/rcS: FAILED
/etc/init.d/reboot: FAILED
/etc/init.d/redis-server: FAILED
/etc/init.d/resolvconf: FAILED
/etc/init.d/rmnologin: FAILED
/etc/init.d/rsync: FAILED
/etc/init.d/rsyslog: FAILED
/etc/init.d/saned: FAILED
/etc/init.d/screen-cleanup: FAILED
/etc/init.d/sendsigs: FAILED
/etc/init.d/single: FAILED
/etc/init.d/skeleton: FAILED
/etc/init.d/ssh: FAILED
/etc/init.d/stop-bootlogd: FAILED
/etc/init.d/stop-bootlogd-single: FAILED
/etc/init.d/sudo: FAILED
/etc/init.d/sysstat: FAILED
/etc/init.d/udev: FAILED
/etc/init.d/udev-mtab: FAILED
/etc/init.d/umountfs: FAILED
/etc/init.d/umountnfs.sh: FAILED
/etc/init.d/umountroot: FAILED
/etc/init.d/unattended-upgrades: FAILED
/etc/init.d/urandom: FAILED
/etc/init.d/vnstat: FAILED
/etc/init.d/x11-common: FAILED
&lt;/pre&gt;&lt;p&gt;
Why all the above files were changed should be investigated.
&lt;/p&gt;
&lt;p&gt;
The upgrade also removed the Gandi.net SSL certs and replaced it with self signed ones:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
www.transitionnetwork.org uses an invalid security certificate.
The certificate is not trusted because it is self-signed.
The certificate is only valid for *.puffin.webarch.net
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
So following the steps from &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/466#comment:25" title="task: Puffin install and configuration (closed: fixed)"&gt;ticket:466#comment:25&lt;/a&gt; to fix this:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/ssl/private/
mv nginx-wild-ssl.crt nginx-wild-ssl.crt.old
mv nginx-wild-ssl.key nginx-wild-ssl.key.old
mv pure-ftpd.pem pure-ftpd.pem.old
ln -s ../transitionnetwork.org/transitionnetwork.org.key nginx-wild-ssl.key
ln -s ../transitionnetwork.org/transitionnetwork.org.crt nginx-wild-ssl.crt
ln -s ../transitionnetwork.org/transitionnetwork.org.pem pure-ftpd.pem
/etc/init.d/nginx restart
  Stopping Nginx Server...:.
  Starting Nginx Server...:nginx: [emerg] SSL_CTX_use_PrivateKey_file("/etc/ssl/private/nginx-wild-ssl.key") failed (SSL: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch)
rm nginx-wild-ssl.crt
ln -s ../transitionnetwork.org/transitionnetwork.org.chained.pem nginx-wild-ssl.crt
/etc/init.d/nginx start
  Starting Nginx Server...: failed!
/etc/init.d/nginx status
  Nginx Server... found running with processes: 16141 16140 16139 16138 16137 16136 16135 16134 16133 16132 16131 16129 16127 16125 16124 16122 16120 16119 16117 16116 16114 16108 16105 16103 16102 16101 16099 16098 16096 16095 16093 ... (warning).
&lt;/pre&gt;&lt;p&gt;
We still have the wrong cert.
&lt;/p&gt;
&lt;pre class="wiki"&gt;/etc/init.d/nginx stop
ps -lA | grep -i nginx
  1 S     0 17720     1  1  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17722 17720  1  80   0 - 18620 -      ?        00:00:00 nginx
  5 S    33 17723 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17725 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17726 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17728 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17729 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17730 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17732 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17734 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17739 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17742 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17743 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17745 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17747 17720  0  80   0 - 18654 -      ?        00:00:00 nginx
  5 S    33 17748 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17750 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17751 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17753 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17755 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17756 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17758 17720  0  80   0 - 18622 -      ?        00:00:00 nginx
  5 S    33 17759 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17760 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17761 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17762 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17763 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17764 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17765 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17766 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 17767 17720  0  80   0 - 18559 -      ?        00:00:00 nginx
&lt;/pre&gt;&lt;p&gt;
So basically the BOA self rolled nginx doesn't have working init scripts?!
&lt;/p&gt;
&lt;pre class="wiki"&gt;killall -9 nginx
ps -lA | grep -i nginx
  5 S     0 18335     1  1  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18337 18335  0  80   0 - 18622 -      ?        00:00:00 nginx
  5 S    33 18339 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18340 18335  1  80   0 - 18635 -      ?        00:00:00 nginx
  5 S    33 18341 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18343 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18344 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18346 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18348 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18354 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18356 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18358 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18359 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18361 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18363 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18365 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18367 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18368 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18370 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18372 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18373 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18374 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18375 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18376 18335  1  80   0 - 18635 -      ?        00:00:00 nginx
  5 S    33 18377 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18378 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18379 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18380 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18381 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18382 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
  5 S    33 18383 18335  0  80   0 - 18559 -      ?        00:00:00 nginx
&lt;/pre&gt;&lt;p&gt;
I'm going to reboot the server, this is also needed just in case some stuff is still running since the OpenSSL update.
&lt;/p&gt;
&lt;pre class="wiki"&gt;reboot
  The system is going down for reboot NOW!ch.net (pts/0) (Fri Apr 11 22:45:05 2
uptime
 22:45:25 up 79 days, 21:33,  2 users,  load average: 10.95, 2.63, 1.28
uptime
 22:47:08 up 79 days, 21:35,  1 user,  load average: 45.11, 17.28, 6.68
uptime
 22:47:53 up 79 days, 21:36,  1 user,  load average: 42.35, 20.55, 8.29
uptime
 22:48:08 up 79 days, 21:36,  1 user,  load average: 41.35, 21.41, 8.77
uptime
 22:48:37 up 79 days, 21:37,  1 user,  load average: 38.32, 22.59, 9.56
uptime
 22:50:11 up 79 days, 21:38,  1 user,  load average: 33.89, 25.46, 11.86
&lt;/pre&gt;&lt;p&gt;
Wow, that took ages...
&lt;/p&gt;
&lt;p&gt;
Looking at the console from xen it was down to the firewall -- there is such a huge number of iptables rules generated by csf/ldf that it takes 5 mins to unload or load them, it seems.
&lt;/p&gt;
&lt;p&gt;
Another email about the things that have been updated:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: root@puffin.webarch.net
Date: Fri, 11 Apr 2014 22:33:42 +0100 (BST)
To: chris@webarchitects.co.uk
Subject: lfd on puffin.webarch.net: System Integrity checking detected a modified system file
Time:     Fri Apr 11 22:33:42 2014 +0100
The following list of files have FAILED the md5sum comparison test. This means that the file has been changed in some way. This could be a result of
+an OS update or application upgrade. If the change is unexpected it should be investigated:
/usr/bin/drush: FAILED
/usr/bin/drush4: FAILED
/usr/bin/drush5: FAILED open or read
/usr/bin/drush6: FAILED
/usr/bin/MySecureShell: FAILED
/usr/bin/nginx: FAILED
/usr/bin/php-cli: FAILED
/usr/bin/redis-benchmark: FAILED
/usr/bin/redis-check-aof: FAILED
/usr/bin/redis-check-dump: FAILED
/usr/bin/redis-cli: FAILED
/usr/bin/redis-server: FAILED
/usr/bin/sftp-admin: FAILED
/usr/bin/sftp-state: FAILED
/usr/bin/sftp-who: FAILED
/usr/bin/vnstat: FAILED
/usr/sbin/nginx: FAILED
/usr/sbin/nginx.old: FAILED
/usr/sbin/vnstatd: FAILED
/bin/sh: FAILED
/usr/local/bin/php: FAILED open or read
/usr/local/bin/redis-benchmark: FAILED open or read
/usr/local/bin/redis-check-aof: FAILED open or read
/usr/local/bin/redis-check-dump: FAILED open or read
/usr/local/bin/redis-cli: FAILED open or read
/usr/local/bin/redis-server: FAILED open or read
/etc/init.d/clean-boa-env: FAILED
/etc/init.d/nginx: FAILED
/etc/init.d/php53-fpm: FAILED
/etc/init.d/redis-server: FAILED
&lt;/pre&gt;&lt;p&gt;
It's back up:
&lt;/p&gt;
&lt;pre class="wiki"&gt;uptime
  22:57:57 up 7 min,  1 user,  load average: 1.70, 0.59, 0.24
&lt;/pre&gt;&lt;p&gt;
We still have the self signed cert.
&lt;/p&gt;
&lt;p&gt;
Now to try grepping to work out which nginx files contains the cert path.
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/nginx
   grep -r ssl .
  ./nginx.conf.default:    #    listen       443 ssl;
  ./nginx.conf.default:    #    ssl_certificate      cert.pem;
  ./nginx.conf.default:    #    ssl_certificate_key  cert.key;
  ./nginx.conf.default:    #    ssl_session_cache    shared:SSL:1m;
  ./nginx.conf.default:    #    ssl_session_timeout  5m;
  ./nginx.conf.default:    #    ssl_ciphers  HIGH:!aNULL:!MD5;
  ./nginx.conf.default:    #    ssl_prefer_server_ciphers  on;
  ./sites-available/default.dpkg-dist:#   ssl on;
  ./sites-available/default.dpkg-dist:#   ssl_certificate cert.pem;
  ./sites-available/default.dpkg-dist:#   ssl_certificate_key cert.key;
  ./sites-available/default.dpkg-dist:#   ssl_session_timeout 5m;
  ./sites-available/default.dpkg-dist:#   ssl_protocols SSLv3 TLSv1;
  ./sites-available/default.dpkg-dist:#   ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv3:+EXP;
  ./sites-available/default.dpkg-dist:#   ssl_prefer_server_ciphers on;
&lt;/pre&gt;&lt;p&gt;
So it's none of the files in /etc/nginx so it must be included from somewhere else:
&lt;/p&gt;
&lt;pre class="wiki"&gt;grep -r include *
  nginx.conf:  include /etc/nginx/mime.types;
  nginx.conf:  include /etc/nginx/conf.d/*.conf;
  nginx.conf:  include /etc/nginx/sites-enabled/*;
  nginx.conf.default:    include       mime.types;
  nginx.conf.default:        #    include        fastcgi_params;
  sites-available/default.dpkg-dist:              # include /etc/nginx/naxsi.rules
  sites-available/default.dpkg-dist:      #       include fastcgi_params;
&lt;/pre&gt;&lt;p&gt;
So:
&lt;/p&gt;
&lt;pre class="wiki"&gt;grep -r ssl /etc/nginx/conf.d/*
  ssl_session_cache   shared:SSL:10m;
  ssl_session_timeout            10m;
grep -ri ssl /etc/nginx/sites-enabled/*
  grep: /etc/nginx/sites-enabled/*: No such file or directory
&lt;/pre&gt;&lt;p&gt;
So perhaps this isn't the ngnix config at all? WHERE THE FUCK IS IT?
&lt;/p&gt;
&lt;pre class="wiki"&gt;updatedb
locate *.crt
  /data/disk/tn/config/server_master/ssl.d/transitionnetwork.org/openssl.crt
  /data/disk/tn/config/ssl.d/transitionnetwork.org/bak/openssl.crt
  /data/disk/tn/config/ssl.d/transitionnetwork.org/openssl.crt
&lt;/pre&gt;&lt;p&gt;
Perhaps it's these...
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /data/disk/tn/config/ssl.d/transitionnetwork.org/
ls -lah
   openssl.crt -&amp;gt; /etc/ssl/transitionnetwork.org/transitionnetwork.org.chained.pem
   openssl.key -&amp;gt; /etc/ssl/transitionnetwork.org/transitionnetwork.org.key
&lt;/pre&gt;&lt;p&gt;
Nope...
&lt;/p&gt;
&lt;p&gt;
These look like the possible nginx config files:
&lt;/p&gt;
&lt;pre class="wiki"&gt;locate nginx | grep tn | grep -v backup
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/hosting.feature.nginx.inc
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/hosting_nginx.info
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/hosting_nginx.module
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/hosting_nginx.service.inc
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/ssl
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/ssl/hosting.feature.nginx_ssl.inc
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/ssl/hosting_nginx_ssl.info
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/ssl/hosting_nginx_ssl.module
/data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/nginx/ssl/hosting_nginx_ssl.service.inc
/data/disk/tn/aegir/distro/008/profiles/hostmaster/web_server/nginx
/data/disk/tn/aegir/distro/008/profiles/hostmaster/web_server/nginx/ssl
/data/disk/tn/aegir/distro/008/profiles/hostmaster/web_server/nginx/ssl/hosting_nginx_ssl.drush.inc
/data/disk/tn/config/includes/nginx_advanced_include.conf
/data/disk/tn/config/includes/nginx_legacy_include.conf
/data/disk/tn/config/includes/nginx_modern_include.conf
/data/disk/tn/config/includes/nginx_octopus_include.conf
/data/disk/tn/config/includes/nginx_simple_include.conf
/data/disk/tn/config/nginx.conf
/data/disk/tn/config/server_master/nginx
/data/disk/tn/config/server_master/nginx.conf
/data/disk/tn/config/server_master/nginx/platform.d
/data/disk/tn/config/server_master/nginx/post.d
/data/disk/tn/config/server_master/nginx/post.d/nginx_force_include*
/data/disk/tn/config/server_master/nginx/pre.d
/data/disk/tn/config/server_master/nginx/vhost.d
/data/disk/tn/config/server_master/nginx/vhost.d/iirs-test.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/news.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/pb-stage-20130212.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/pb-stage-20140403.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/space.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/stg2.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/stg3.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/stg4.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/stg.transitionnetwork.org
/data/disk/tn/config/server_master/nginx/vhost.d/tn.puffin.webarch.net
/data/disk/tn/config/server_master/nginx/vhost.d/www.transitionnetwork.org
/data/disk/tn/config/tn.nginx.conf
/data/disk/tn/.drush/provision_cdn/Provision/Service/cdn/nginx.php
/data/disk/tn/.drush/provision/http/nginx
/data/disk/tn/.drush/provision/http/nginx/nginx_service.inc
/data/disk/tn/.drush/provision/http/nginx_ssl
/data/disk/tn/.drush/provision/http/nginx_ssl/nginx_ssl_service.inc
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx.conf
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx_legacy_include.conf
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx_modern_include.conf
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx_octopus_include.conf
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx.php
/data/disk/tn/.drush/provision/http/Provision/Service/http/nginx/ssl.php
/data/disk/tn/static/transition-network-d6-p009/sites/news.transitionnetwork.org/nginx_cache_hour.info
/data/disk/tn/static/transition-network-d6-p009/sites/www.transitionnetwork.org/nginx_cache_quarter.info
/data/disk/tn/static/transition-network-d6-s008/sites/pb-stage-20130212.transitionnetwork.org/nginx_cache_quarter.info
/data/disk/tn/static/transition-network-d6-s008/sites/stg2.transitionnetwork.org/nginx_cache_quarter.info
/data/disk/tn/static/transition-network-d6-s008/sites/stg.transitionnetwork.org/nginx_cache_quarter.info
/data/disk/tn/static/transition-network-d6-s011/sites/pb-stage-20140403.transitionnetwork.org/nginx_cache_quarter.info
/var/aegir/config/server_master/nginx/platform.d/tn.conf
&lt;/pre&gt;&lt;p&gt;
So, checking these places:
&lt;/p&gt;
&lt;pre class="wiki"&gt;grep -ri ssl /data/disk/tn/aegir/distro/008/profiles/hostmaster/modules/hosting/web_server/* | grep crt
grep -ri ssl /data/disk/tn/aegir/distro/008/profiles/hostmaster/web_server/* | grep crt
grep -ri ssl /data/disk/tn/config/tn.nginx.conf
grep -ri ssl /data/disk/tn/config/includes/*
grep -ri ssl /data/disk/tn/config/nginx.conf
grep -ri ssl /data/disk/tn/config/server_master/*
grep -ri ssl /data/disk/tn/config/tn.nginx.conf
grep -ri ssl /data/disk/tn/.drush/provision/http/nginx
grep -ri ssl /data/disk/tn/.drush/provision/http/Provision/Service/http/*
grep -ri ssl /data/disk/tn/static/transition-network-d6-p009/sites/* | grep crt
grep -ri ssl /var/aegir/config/server_master/nginx/platform.d/tn.conf
&lt;/pre&gt;&lt;p&gt;
No joy...
&lt;/p&gt;
&lt;pre class="wiki"&gt;date
  Fri Apr 11 23:24:04 BST 2014
&lt;/pre&gt;&lt;p&gt;
I just don't have a clue where the config files that need fixing are, this is very fustrating, the site is *down*.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 11 Apr 2014 22:42:17 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:21</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:21</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.26&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;3.84&lt;/em&gt; to &lt;em&gt;4.1&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Starting from the beginning...
&lt;/p&gt;
&lt;p&gt;
In /etc/init.d/nginx we have:
&lt;/p&gt;
&lt;pre class="wiki"&gt;NGINX_CONF_FILE="/etc/nginx/nginx.conf"
&lt;/pre&gt;&lt;p&gt;
That files includes:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  include /etc/nginx/mime.types;
  include /etc/nginx/conf.d/*.conf;
  include /etc/nginx/sites-enabled/*;
&lt;/pre&gt;&lt;pre class="wiki"&gt;ls /etc/nginx/conf.d/*.conf
  /etc/nginx/conf.d/aegir.conf@
grep ssl /etc/nginx/conf.d/aegir.conf
  ssl_session_cache   shared:SSL:10m;
  ssl_session_timeout            10m;
grep include /etc/nginx/conf.d/aegir.conf
  include /var/aegir/config/server_master/nginx/pre.d/*;
  include /var/aegir/config/server_master/nginx/platform.d/*;
  include /var/aegir/config/server_master/nginx/vhost.d/*;
  include /var/aegir/config/server_master/nginx/post.d/*;
grep -ir ssl /var/aegir/config/server_master/nginx/pre.d/*
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:### /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  listen                       *:443 ssl spdy;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl                          on;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl_certificate              /etc/ssl/private/nginx-wild-ssl.crt;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl_certificate_key          /etc/ssl/private/nginx-wild-ssl.key;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl_session_timeout          5m;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl_ciphers EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:+RC4:RC4;
  /var/aegir/config/server_master/nginx/pre.d/nginx_wild_ssl.conf:  ssl_prefer_server_ciphers    on;
&lt;/pre&gt;&lt;p&gt;
BINGO!
&lt;/p&gt;
&lt;p&gt;
That file was edited:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  #ssl_certificate              /etc/ssl/private/nginx-wild-ssl.crt;
  #ssl_certificate_key          /etc/ssl/private/nginx-wild-ssl.key;
  ssl_certificate              /etc/ssl/transitionnetwork.org/transitionnetwork.org.chained.pem;
  ssl_certificate_key          /etc/ssl/transitionnetwork.org/transitionnetwork.org.key;
&lt;/pre&gt;&lt;p&gt;
But still:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
www.transitionnetwork.org uses an invalid security certificate.
&lt;/p&gt;
&lt;p&gt;
The certificate is not trusted because it is self-signed.
&lt;/p&gt;
&lt;p&gt;
The certificate is only valid for *.puffin.webarch.net
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
So, copying the files over from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt; again:
&lt;/p&gt;
&lt;pre class="wiki"&gt;rsync -av penguin:tn/ /root/tn/
bash: warning: setlocale: LC_ALL: cannot change locale (en_US.UTF-8)
receiving incremental file list
./
transitionnetwork.org.chained.pem
transitionnetwork.org.crt
transitionnetwork.org.csr
transitionnetwork.org.key
sent 90 bytes  received 9797 bytes  19774.00 bytes/sec
total size is 9499  speedup is 0.96
&lt;/pre&gt;&lt;p&gt;
And:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/ssl/transitionnetwork.org
mv transitionnetwork.org.* old/
mv /root/tn/transitionnetwork.org.* .
&lt;/pre&gt;&lt;p&gt;
And it's fixed!
&lt;/p&gt;
&lt;p&gt;
So the issue was that the right certs were replaced by self signed by BOA...?
&lt;/p&gt;
&lt;p&gt;
What a wast of time that was.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 11 Apr 2014 22:55:04 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:22</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:22</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.1&lt;/em&gt; to &lt;em&gt;4.3&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
So now testing other stuff and looking around...
&lt;/p&gt;
&lt;p&gt;
As expect the default MySQL settings have dramatically reduced the RAM available for the database:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/mysql_qcache_mem.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/mysql_qcache_mem.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
These graphs and lots others have been broken:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/nginx_vhost_traffic.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/nginx_vhost_traffic.html&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_average.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_average.html&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_processes.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_processes.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
But I'm tired and it can wait till tomorrow -- it looks like a permissions issue:
&lt;/p&gt;
&lt;pre class="wiki"&gt;munin-run phpfpm_average
  php_average.value /etc/munin/plugins/phpfpm_average: line 40: /bin/ps: Permission denied
  /etc/munin/plugins/phpfpm_average: line 40: /bin/grep: Permission denied
  /etc/munin/plugins/phpfpm_average: line 40: /bin/grep: Permission denied
  /etc/munin/plugins/phpfpm_average: line 40: /bin/grep: Permission denied
  /etc/munin/plugins/phpfpm_average: line 40: /usr/bin/awk: Permission denied
munin-run phpfpm_connections
  Can't exec "/etc/munin/plugins/phpfpm_connections": Permission denied at /usr/share/perl5/Munin/Node/Service.pm line 263.
  # FATAL: Failed to exec.
munin-run multips_memory
  /usr/share/munin/plugins/plugin.sh: line 14: /bin/sed: Permission denied
  /etc/munin/plugins/multips_memory: line 140: /bin/ps: Permission denied
  /etc/munin/plugins/multips_memory: line 144: /usr/bin/gawk: Permission denied
  /usr/share/munin/plugins/plugin.sh: line 14: /bin/sed: Permission denied
  /etc/munin/plugins/multips_memory: line 140: /bin/ps: Permission denied
  /etc/munin/plugins/multips_memory: line 144: /usr/bin/gawk: Permission denied
  /usr/share/munin/plugins/plugin.sh: line 14: /bin/sed: Permission denied
  /etc/munin/plugins/multips_memory: line 140: /bin/ps: Permission denied
  /etc/munin/plugins/multips_memory: line 144: /usr/bin/gawk: Permission denied
  /usr/share/munin/plugins/plugin.sh: line 14: /bin/sed: Permission denied
  /etc/munin/plugins/multips_memory: line 140: /bin/ps: Permission denied
  /etc/munin/plugins/multips_memory: line 144: /usr/bin/gawk: Permission denied
  /usr/share/munin/plugins/plugin.sh: line 14: /bin/sed: Permission denied
  /etc/munin/plugins/multips_memory: line 140: /bin/ps: Permission denied
  /etc/munin/plugins/multips_memory: line 144: /usr/bin/gawk: Permission denied
&lt;/pre&gt;&lt;p&gt;
More broken shit than a BOA upgrade usually causes...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 08:39:50 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:23</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:23</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.3&lt;/em&gt; to &lt;em&gt;4.8&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
It looks like &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; commited suicide, I got this email:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Date: Sat, 12 Apr 2014 09:11:03 +0100
To: chris@webarchitects.co.uk
Subject: ** PROBLEM Service Alert: puffin/SSH is CRITICAL **
***** Nagios *****
Notification Type: PROBLEM
Service: SSH
Host: puffin
Address: puffin.webarch.net
State: CRITICAL
Date/Time: Sat Apr 12 09:11:03 BST 2014
&lt;/pre&gt;&lt;p&gt;
I couldn't connect via ssh and was about to reboot it at a xen level when I did get in and it looks that with the default BOA settings we are back in load spike suicide land:
&lt;/p&gt;
&lt;pre class="wiki"&gt;uptime
 09:24:23 up 10:34,  1 user,  load average: 65.71, 120.18, 85.84
uptime
 09:29:37 up 10:39,  1 user,  load average: 0.52, 42.71, 61.54
&lt;/pre&gt;&lt;p&gt;
I'll look at the logs in a while to see what happened, but the BOA default is to clobber lots of key logs so I might not find a lot of info.
&lt;/p&gt;
&lt;p&gt;
Since the aim is run with the BOA defaults, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt;, I'll start by doing the minimum needed to get the munin graphs working again and stop the log clobbering so we can get a better picture about what is happening when the server commits suicide again.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 09:25:58 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:24</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:24</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.8&lt;/em&gt; to &lt;em&gt;5.05&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:20" title="Comment 20 for Ticket #707"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Wow, that took ages...
&lt;/p&gt;
&lt;p&gt;
Looking at the console from xen it was down to the firewall -- there is such a huge number of iptables rules generated by csf/ldf that it takes 5 mins to unload or load them, it seems.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Last night I set a &lt;tt&gt;iptables --list&lt;/tt&gt; running in screen, the file it generated:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ls /root/iptables.2014-04-12 -lah
  -rw-r--r-- 1 root root 247K Apr 12 00:28 /root/iptables.2014-04-12
cat /root/iptables.2014-04-12 | wc -l
  3693
&lt;/pre&gt;&lt;p&gt;
I was expecting it to be bigger.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 09:29:20 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:25</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:25</guid>
      <description>
        &lt;p&gt;
Posting this to record 15 mins spent rereading comments and fixing typos and spelling mistakes
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 09:29:51 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:26</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:26</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;5.05&lt;/em&gt; to &lt;em&gt;5.3&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Oops, time missed off last comment.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 10:19:01 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:27</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:27</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.3&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;5.3&lt;/em&gt; to &lt;em&gt;5.6&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Since users are no longer allowed access to most command line functioms because BOA chmodded lits of programes I think adjusting munin tasks that were run by the munin user to now run as root is probable the easiest was to address this, however this could also have negative security implications.
&lt;/p&gt;
&lt;p&gt;
Testing with two graphs to negin with,
&lt;/p&gt;
&lt;pre class="wiki"&gt;[multips]
env.names nginx php_fpm mysqld redis-server munin-node
user root
[multips_memory]
env.names nginx php-fpm mysqld redis-server munin-node
user root
&lt;/pre&gt;&lt;p&gt;
This should fix this graph:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/multips_memory.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/multips_memory.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
As it it working again on the command line:
&lt;/p&gt;
&lt;pre class="wiki"&gt;root@puffin:/etc/munin/plugins# munin-run multips_memory
nginx.value 631918592
php_fpm.value 76709888
mysqld.value 1502449664
redis_server.value U
munin_node.value 10309632
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 12:26:29 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:28</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:28</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;5.6&lt;/em&gt; to &lt;em&gt;6.35&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Fixing the Munin plugins by making them run as root rather than user munin or nobody or other non-root users with less permissions... *sigh*
&lt;/p&gt;
&lt;p&gt;
These ones are not just a matter of a perms fix:
&lt;/p&gt;
&lt;pre class="wiki"&gt;munin-run nginx_request
  request.value U
munin-run nginx_status
  total.value U
  reading.value U
  writing.value U
  waiting.value U
munin-run phpfpm_connections
  accepted.value U
munin-run phpfpm_connections
  accepted.value U
munin-run phpfpm_status
  idle.value U
  active.value U
  total.value U
munin-run redis_127.0.0.1_6379
  Could not connect to Redis at 127.0.0.1:6379: Connection refused
  multigraph redis_commands
  commands.value
  hits.value
  misses.value
  multigraph redis_dbs
  expires.value
&lt;/pre&gt;&lt;p&gt;
For everything else the graphs are starting to be drawn again:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 16:44:42 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:29</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:29</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.52&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;6.35&lt;/em&gt; to &lt;em&gt;6.87&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
There was another load spike suicide this afternoon that's two in the 24 hours since the upgrade to BOA 2.2.2, I'll look at the lofs later and record my findings on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Fixing the broken Munin graphs...
&lt;/p&gt;
&lt;p&gt;
The &lt;tt&gt;/var/aegir/config/server_master/nginx.conf&lt;/tt&gt; files now contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;server {
  listen       *:80;
  server_name 127.0.0.1;
  location /nginx_status {
    stub_status on;
    access_log off;
    allow 127.0.0.1;
    deny all;
  }
}
&lt;/pre&gt;&lt;p&gt;
So trying to work out the URL to get the stats...
&lt;/p&gt;
&lt;pre class="wiki"&gt;lynx -dump http://localhost/nginx_status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://puffin.webarch.net/nginx_status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://127.0.0.1/nginx_status
Active connections: 11
server accepts handled requests
 9354 9354 13400
Reading: 0 Writing: 1 Waiting: 10
&lt;/pre&gt;&lt;p&gt;
So &lt;tt&gt;/etc/munin/plugin-conf.d/munin-node&lt;/tt&gt; was updated to:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[nginx_request]
env.url http://127.0.0.1/nginx_status
user root
[nginx_status]
env.url http://127.0.0.1/nginx_status
user root
&lt;/pre&gt;&lt;p&gt;
And testing:
&lt;/p&gt;
&lt;pre class="wiki"&gt;nginx_status
  total.value 23
  reading.value 0
  writing.value 1
  waiting.value 21
munin-run nginx_request
  request.value 13915
&lt;/pre&gt;&lt;p&gt;
The docs at &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#nginxconfigchanges"&gt;wiki:PuffinServer#nginxconfigchanges&lt;/a&gt; will need updating, we once again have Munin Nginx graphs:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html#nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html#nginx&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 12 Apr 2014 18:20:23 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:30</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:30</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;6.87&lt;/em&gt; to &lt;em&gt;7.62&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The old php config file, /opt/local/etc/php53-fpm.conf still contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;pm.status_path = /status
ping.path = /ping
&lt;/pre&gt;&lt;p&gt;
However that status isn't available at these URLs:
&lt;/p&gt;
&lt;pre class="wiki"&gt;lynx -dump http://127.0.0.1/status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://localhost/status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://puffin.webarch.net/status
                                404 Not Found
     __________________________________________________________________
                                    nginx
&lt;/pre&gt;&lt;p&gt;
Also the new URLs which are supposed to work don't:
&lt;/p&gt;
&lt;pre class="wiki"&gt;lynx -dump http://127.0.0.1/fpm-status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://localhost/fpm-status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://puffin.webarch.net/fpm-status
                                404 Not Found
     __________________________________________________________________
                                    nginx
&lt;/pre&gt;&lt;p&gt;
So we need to find the new php config file to see if the status is enabled.
&lt;/p&gt;
&lt;p&gt;
It's might be one of these files:
&lt;/p&gt;
&lt;pre class="wiki"&gt;updatedb
locate php | grep conf$
/etc/php5/fpm/php-fpm.conf
/etc/php5/fpm/pool.d/www.conf
/opt/etc/php-fpm.conf
/opt/local/etc/php53-fpm.conf
/opt/php52/etc/php52-fpm.conf
/opt/php53/etc/pear.conf
/opt/php53/etc/php53-fpm.conf
/opt/php53/etc/pool.d/www53.conf
/opt/php54/etc/php54-fpm.conf
/opt/php54/etc/pool.d/www54.conf
/opt/php55/etc/php55-fpm.conf
/opt/php55/etc/pool.d/www55.conf
&lt;/pre&gt;&lt;p&gt;
The only one with a status line is /opt/local/etc/php53-fpm.conf
&lt;/p&gt;
&lt;p&gt;
So trying to track down the php-fpm config file which is actually being used...
&lt;/p&gt;
&lt;p&gt;
The /opt/php53/etc/php53-fpm.conf file includes /opt/php53/etc/pool.d/*.conf and /opt/php53/etc/pool.d/www53.conf includes /opt/etc/fpm/fpm-pool-common.conf and that files contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;pm.status_path = /fpm-status
ping.path = /fpm-ping
&lt;/pre&gt;&lt;p&gt;
Looking at /etc/init.d/php53-fpm and /etc/init.d/php5-fpm to try to work out where the php-fpm config files are to be found...
&lt;/p&gt;
&lt;p&gt;
/etc/init.d/php53-fpm contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;php_fpm_CONF=/opt/php53/etc/php53-fpm.conf
&lt;/pre&gt;&lt;p&gt;
And /etc/init.d/php5-fpm contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;DAEMON_ARGS="--fpm-config /etc/php5/fpm/php-fpm.conf"
&lt;/pre&gt;&lt;p&gt;
Before the last upgrade the init script was /etc/init.d/php53-fpm, see &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#php-fpm"&gt;wiki:PuffinServer#php-fpm&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The problem is with Nginx, I tried editing /var/aegir/config/server_master/nginx.conf to add the code we had before:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  location ~ ^/(status|ping)$ {
    fastcgi_pass 127.0.0.1:9090;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    fastcgi_intercept_errors on;
    include fastcgi_params;
    access_log off;
    allow 127.0.0.1;
    deny all;
  }
&lt;/pre&gt;&lt;p&gt;
But that didn't fix it. I think I'm too tired to solve this mystery tonight.
&lt;/p&gt;
&lt;p&gt;
Looking in the logs, we have lots of entries like this in /var/log/php/error_log_53
&lt;/p&gt;
&lt;pre class="wiki"&gt;
[12-Apr-2014 18:00:35 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:35 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:35 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:41 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:41 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:41 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:42 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:00:42 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
[12-Apr-2014 18:07:47 UTC] PHP Warning:  Zend OPcache can't be temporary enabled (it may be only disabled till the end of request) in Unknown on line 0
&lt;/pre&gt;&lt;p&gt;
In /var/log/php/fpm-www53-slow.log there are lots of entries like this, the time matches the last load spike suicide:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[12-Apr-2014 15:20:57]  [pool www53] pid 56669
script_filename = /data/disk/tn/static/transition-network-d6-p009/index.php
[0x00007ff0205f72b0] _drupal_bootstrap() /data/disk/tn/static/transition-network-d6-p009/includes/bootstrap.inc:1480
[0x00007ff0205f7150] _drupal_bootstrap() /data/disk/tn/static/transition-network-d6-p009/includes/bootstrap.inc:1447
[0x00007ff0205f7050] drupal_bootstrap() /data/disk/tn/static/transition-network-d6-p009/index.php:15
[12-Apr-2014 15:21:13]  [pool www53] pid 56670
script_filename = /data/disk/tn/static/transition-network-d6-p009/index.php
[0x00007ff0205f7760] is_readable() /data/conf/global.inc:476
[0x00007ff0205f7628] +++ dump failed
[12-Apr-2014 15:21:18]  [pool www53] pid 56681
script_filename = /data/disk/tn/static/transition-network-d6-p009/index.php
[0x00007ff0205f7760] connect() /data/conf/global.inc:371
[0x00007ff0205f7628] +++ dump failed
[12-Apr-2014 15:21:23]  [pool www53] pid 56547
script_filename = /data/disk/tn/static/transition-network-d6-p009/index.php
[0x000000000348da30] is_readable() /data/conf/global.inc:427
[0x000000000348d8f8] +++ dump failed
[12-Apr-2014 15:21:54]  [pool www53] pid 56695
script_filename = /data/disk/tn/static/transition-network-d6-p009/index.php
[0x00007ff0205f7760] connect() /data/conf/global.inc:371
[0x00007ff0205f7628] +++ dump failed
&lt;/pre&gt;&lt;p&gt;
And in /var/log/php/php53-fpm-error.log there are lots of lines like this which coincide with the last load spike suicide:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[12-Apr-2014 15:21:54] ERROR: failed to ptrace(PEEKDATA) pid 56695: Input/output error (5)
[12-Apr-2014 15:21:58] WARNING: [pool www53] child 56655, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (194.782226 sec), terminating
[12-Apr-2014 15:21:58] WARNING: [pool www53] child 56654, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (197.135421 sec), terminating
[12-Apr-2014 15:21:58] WARNING: [pool www53] child 56653, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (199.566956 sec), terminating
[12-Apr-2014 15:22:01] WARNING: [pool www53] child 56655 exited on signal 15 (SIGTERM) after 201.299257 seconds from start
[12-Apr-2014 15:22:04] WARNING: [pool www53] child 56653 exited on signal 15 (SIGTERM) after 209.593928 seconds from start
[12-Apr-2014 15:22:10] WARNING: [pool www53] child 56654 exited on signal 15 (SIGTERM) after 211.753491 seconds from start
[12-Apr-2014 15:22:18] WARNING: [pool www53] child 56661, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (193.133020 sec), terminating
[12-Apr-2014 15:22:18] WARNING: [pool www53] child 56657, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (189.783626 sec), terminating
[12-Apr-2014 15:22:18] WARNING: [pool www53] child 56590, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (187.447955 sec), terminating
[12-Apr-2014 15:22:22] WARNING: [pool www53] child 56657 exited on signal 15 (SIGTERM) after 219.567805 seconds from start
[12-Apr-2014 15:22:25] WARNING: [pool www53] child 56590 exited on signal 15 (SIGTERM) after 365.818528 seconds from start
[12-Apr-2014 15:22:28] WARNING: [pool www53] child 56661 exited on signal 15 (SIGTERM) after 208.535602 seconds from start
[12-Apr-2014 15:22:38] WARNING: [pool www53] child 56617, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (196.484809 sec), terminating
[12-Apr-2014 15:22:45] WARNING: [pool www53] child 56617 exited on signal 15 (SIGTERM) after 352.524615 seconds from start
[12-Apr-2014 15:22:58] WARNING: [pool www53] child 56670, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (196.228568 sec), terminating
[12-Apr-2014 15:22:58] WARNING: [pool www53] child 56669, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (198.184145 sec), terminating
[12-Apr-2014 15:23:05] WARNING: [pool www53] child 56669 exited on signal 15 (SIGTERM) after 224.906323 seconds from start
[12-Apr-2014 15:23:08] WARNING: [pool www53] child 56670 exited on signal 15 (SIGTERM) after 227.669041 seconds from start
[12-Apr-2014 15:23:19] WARNING: [pool www53] child 56681, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (192.413551 sec), terminating
[12-Apr-2014 15:23:19] WARNING: [pool www53] child 56547, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "GET /index.php") execution timed out (194.007008 sec), terminating
[12-Apr-2014 15:23:21] WARNING: [pool www53] child 56681 exited on signal 15 (SIGTERM) after 200.979892 seconds from start
[12-Apr-2014 15:23:24] WARNING: [pool www53] child 56547 exited on signal 15 (SIGTERM) after 472.666956 seconds from start
[12-Apr-2014 15:23:39] WARNING: [pool www53] child 56695, script '/data/disk/tn/static/transition-network-d6-p009/index.php' (request: "HEAD /index.php") execution timed out (186.279207 sec), terminating
[12-Apr-2014 15:23:41] WARNING: [pool www53] child 56695 exited on signal 15 (SIGTERM) after 216.840863 seconds from start
[12-Apr-2014 15:27:30] ERROR: unable to bind listening socket for address '127.0.0.1:9090': Address already in use (98)
[12-Apr-2014 15:27:30] ERROR: FPM initialization failed
&lt;/pre&gt;&lt;p&gt;
So it's good that the logs are not being clobbered any more but there does appear to be some things not quite right...
&lt;/p&gt;
&lt;p&gt;
I'll do some more on this tomorrow evening...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 14 Apr 2014 09:32:25 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:31</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:31</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.35&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;7.62&lt;/em&gt; to &lt;em&gt;7.97&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Redis isn't running:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ps -lA | grep -i redis
&lt;/pre&gt;&lt;p&gt;
And it won't start:
&lt;/p&gt;
&lt;pre class="wiki"&gt;/etc/init.d/redis-server start
  Starting redis-server: touch: cannot touch `/var/run/redis/redis.pid': No such file or directory
&lt;/pre&gt;&lt;p&gt;
This could explain why the server wasn't coping with load spikes.
&lt;/p&gt;
&lt;p&gt;
Make the directory for the pid file and try to start it:
&lt;/p&gt;
&lt;pre class="wiki"&gt;mkdir /var/run/redis/
chown redis:redis /var/run/redis/
/etc/init.d/redis-server start
  Starting redis-server: failed
&lt;/pre&gt;&lt;p&gt;
The start failed because it had been automatically started by BOA I expect, it is running now:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ps -lA | grep -i redis
  1 S   106 52733     1  0  80   0 - 13575 -      ?        00:00:00 redis-server
&lt;/pre&gt;&lt;p&gt;
The logs is being clobbered:
&lt;/p&gt;
&lt;pre class="wiki"&gt;rotate
[52733] 14 Apr 10:16:33.980 # Server started, Redis version 2.8.8
[52733] 14 Apr 10:16:33.981 # WARNING overcommit_memory is set to 0! Background save may fail under low memory condition. To fix this issue add 'vm.overcommit_memory = 1' to /etc/sysctl.conf and then reboot or run the command 'sysctl vm.overcommit_memory=1' for this to take effect.
&lt;/pre&gt;&lt;p&gt;
The Redis config file, &lt;tt&gt;/etc/redis/redis.conf&lt;/tt&gt; now contains a password, so this has been added to &lt;tt&gt;/etc/munin/plugin-conf.d/munin-node&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[redis_*]
env.password XXX
user root
&lt;/pre&gt;&lt;p&gt;
It has been tested on the command line:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/munin/plugins
munin-run redis_127.0.0.1_6379
  multigraph redis_clients
  clients.value 1
  multigraph redis_blocked_clients
  blocked.value 0
  multigraph redis_memory
  memory.value 37383008
  multigraph redis_fragmentation
  frag.value 1.09
  multigraph redis_total_connections
  connections.value 883
  multigraph redis_expired_keys
  expired.value 8
  multigraph redis_evicted_keys
  evicted.value 0
  multigraph redis_pubsub_channels
  channels.value 0
  multigraph redis_commands
  commands.value 34345
  hits.value 17193
  misses.value 5496
  multigraph redis_dbs
  db0keys.value 3893
  db0expires.value 919
&lt;/pre&gt;&lt;p&gt;
Munin has been restarted:
&lt;/p&gt;
&lt;pre class="wiki"&gt;/etc/init.d/munin-node restart
  [ ok ] Stopping Munin-Node: done.
  [ ok ] Starting Munin-Node: done.
&lt;/pre&gt;&lt;p&gt;
So now we should soon start to get Redis munin graphs again:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html#redis"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html#redis&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 14 Apr 2014 10:49:41 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:32</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:32</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;1.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;7.97&lt;/em&gt; to &lt;em&gt;8.97&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:28" title="Comment 28 for Ticket #707"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
These ones are not just a matter of a perms fix:
&lt;/p&gt;
&lt;pre class="wiki"&gt;munin-run nginx_request
  request.value U
munin-run nginx_status
  total.value U
  reading.value U
  writing.value U
  waiting.value U
&lt;/pre&gt;&lt;/blockquote&gt;
&lt;p&gt;
The odd thing here is that this works on the command line:
&lt;/p&gt;
&lt;pre class="wiki"&gt;munin-run nginx_request
  request.value 249155
munin-run nginx_status
  total.value 30
  reading.value 0
  writing.value 4
  waiting.value 26
&lt;/pre&gt;&lt;p&gt;
But we don't have graphs here:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html#nginx"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/index.html#nginx&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
There is nothing in the log files, &lt;tt&gt;/var/log/munin/&lt;/tt&gt;, but since opening this comment they have started to reappear -- the munin-node restart done to fix the redis logs must have also fixed these graphs?
&lt;/p&gt;
&lt;p&gt;
These are still now working:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;pre class="wiki"&gt;munin-run phpfpm_connections
  accepted.value U
munin-run phpfpm_status
  idle.value U
  active.value U
  total.value U
&lt;/pre&gt;&lt;/blockquote&gt;
&lt;p&gt;
So, the plugins are written in perl:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/munin/plugins
perl -wc phpfpm_connections
  phpfpm_connections syntax OK
perl -wc phpfpm_status
  phpfpm_status syntax OK
&lt;/pre&gt;&lt;p&gt;
The problem is that the status URL is a 404:
&lt;/p&gt;
&lt;pre class="wiki"&gt;lynx -dump http://127.0.0.1/fpm-status
                                404 Not Found
     __________________________________________________________________
                                    nginx
lynx -dump http://127.0.0.1/status
                                404 Not Found
     __________________________________________________________________
                                    nginx
&lt;/pre&gt;&lt;p&gt;
Previously this needed adding to &lt;tt&gt;/var/aegir/config/server_master/nginx.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  location ~ ^/(status|ping)$ {
    fastcgi_pass 127.0.0.1:9090;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    fastcgi_intercept_errors on;
    include fastcgi_params;
    access_log off;
    allow 127.0.0.1;
    deny all;
  }
&lt;/pre&gt;&lt;p&gt;
See &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#nginxconfigchanges"&gt;wiki:PuffinServer#nginxconfigchanges&lt;/a&gt; but when you try connect using those details:
&lt;/p&gt;
&lt;pre class="wiki"&gt;lynx -dump http://127.0.0.1:9090/status
  Looking up 127.0.0.1:9090
  Making HTTP connection to 127.0.0.1:9090
  Sending HTTP request.
  HTTP request sent; waiting for response.
  Retrying as HTTP0 request.
  Looking up 127.0.0.1:9090
  Making HTTP connection to 127.0.0.1:9090
  Sending HTTP request.
  HTTP request sent; waiting for response.
  Alert!: Unexpected network read error; connection aborted.
  Can't Access `http://127.0.0.1:9090/status'
  Alert!: Unable to access document.
  lynx: Can't access startfile
&lt;/pre&gt;&lt;p&gt;
This does appear to be the right port, it is set to 9090 in &lt;tt&gt;/opt/php53/etc/pool.d/www53.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;listen = 127.0.0.1:9090
&lt;/pre&gt;&lt;p&gt;
And that file includes &lt;tt&gt;/opt/etc/fpm/fpm-pool-common.conf&lt;/tt&gt; which contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;pm.status_path = /fpm-status
ping.path = /fpm-ping
&lt;/pre&gt;&lt;p&gt;
It is running on this port:
&lt;/p&gt;
&lt;pre class="wiki"&gt;netstat -tulpn | grep 9090
  tcp        0      0 127.0.0.1:9090          0.0.0.0:*               LISTEN      6852/php53-fpm.conf
&lt;/pre&gt;&lt;p&gt;
And the binary:
&lt;/p&gt;
&lt;pre class="wiki"&gt;ls -l /proc/6852/exe
  lrwxrwxrwx 1 root root 0 Apr 14 00:02 /proc/6852/exe -&amp;gt; /opt/php53/sbin/php-fpm*
&lt;/pre&gt;&lt;p&gt;
And that is the binary referenced in &lt;tt&gt;/etc/init.d/php53-fpm&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;php_fpm_BIN=/opt/php53/sbin/php-fpm
php_fpm_CONF=/opt/php53/etc/php53-fpm.conf
&lt;/pre&gt;&lt;p&gt;
And &lt;tt&gt;/opt/php53/etc/php53-fpm.conf&lt;/tt&gt; includes &lt;tt&gt;/opt/php53/etc/pool.d/*.conf&lt;/tt&gt; and that includes &lt;tt&gt;/opt/etc/fpm/fpm-pool-common.conf&lt;/tt&gt;.
&lt;/p&gt;
&lt;p&gt;
Still non the wiser why we can't get the php-fpm graphs working:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_status.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_status.html&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_connections.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_connections.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
More work is needed on this :-(
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 14 Apr 2014 11:20:29 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:33</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:33</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;8.97&lt;/em&gt; to &lt;em&gt;9.22&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:32" title="Comment 32 for Ticket #707"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Still non the wiser why we can't get the php-fpm graphs working:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_status.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_status.html&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_connections.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/phpfpm_connections.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
Adding this to &lt;tt&gt;/var/aegir/config/server_master/nginx.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  location ~ ^/fpm-(status|ping)$ {
    fastcgi_pass 127.0.0.1:9090;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    fastcgi_intercept_errors on;
    include fastcgi_params;
    access_log off;
    allow 127.0.0.1;
    allow 81.95.52.103;
    deny all;
  }
&lt;/pre&gt;&lt;p&gt;
Has resulted in the Munin graphs to start to be generated again.
&lt;/p&gt;
&lt;p&gt;
However by editing &lt;tt&gt;/var/aegir/config/server_master/nginx.conf&lt;/tt&gt; the "use stock BOA settings where possible" directive, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt;, has been breached and this change might need doing after each BOA upgrade.
&lt;/p&gt;
&lt;p&gt;
The documentation, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#nginxconfigchanges"&gt;wiki:PuffinServer#nginxconfigchanges&lt;/a&gt; has been updated.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Mon, 14 Apr 2014 11:53:25 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:34</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:34</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;9.22&lt;/em&gt; to &lt;em&gt;9.72&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:33" title="Comment 33 for Ticket #707"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Adding this to &lt;tt&gt;/var/aegir/config/server_master/nginx.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  location ~ ^/fpm-(status|ping)$ {
    fastcgi_pass 127.0.0.1:9090;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    fastcgi_intercept_errors on;
    include fastcgi_params;
    access_log off;
    allow 127.0.0.1;
    allow 81.95.52.103;
    deny all;
  }
&lt;/pre&gt;&lt;/blockquote&gt;
&lt;p&gt;
There was an issue about this here: &lt;a class="ext-link" href="https://drupal.org/node/2167459"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2167459&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
We can open a new one with the extra changes if needed. It's not clear from the above which lines were added, Chris? If you can provide a summary of what needed to be changed, I'd be happy to add a ticket in the Barracuda D.o queue tonight.
&lt;/p&gt;
&lt;p&gt;
(Also adding my time for various comments &amp;amp; emails.)
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 14 Apr 2014 12:01:27 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:35</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:35</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;9.72&lt;/em&gt; to &lt;em&gt;9.82&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:34" title="Comment 34 for Ticket #707"&gt;jim&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:33" title="Comment 33 for Ticket #707"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Adding this to &lt;tt&gt;/var/aegir/config/server_master/nginx.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  location ~ ^/fpm-(status|ping)$ {
    fastcgi_pass 127.0.0.1:9090;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    fastcgi_intercept_errors on;
    include fastcgi_params;
    access_log off;
    allow 127.0.0.1;
    allow 81.95.52.103;
    deny all;
  }
&lt;/pre&gt;&lt;/blockquote&gt;
&lt;p&gt;
It's not clear from the above which lines were added, Chris?
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
All the lines above were added.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 14 Apr 2014 12:12:50 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:36</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:36</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;9.82&lt;/em&gt; to &lt;em&gt;10.02&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/707#comment:34" title="Comment 34 for Ticket #707"&gt;jim&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There was an issue about this here: &lt;a class="ext-link" href="https://drupal.org/node/2167459"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2167459&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
According the the diffs linked from that changed were made to &lt;tt&gt;nginx_modern_include.conf&lt;/tt&gt; and &lt;tt&gt;nginx_octopus_include.conf&lt;/tt&gt;, these are the copies of these files on the server:
&lt;/p&gt;
&lt;pre class="wiki"&gt;locate nginx_modern_include.conf | grep -v backups | grep -v \.drush
  /data/disk/tn/config/includes/nginx_modern_include.conf
  /var/aegir/config/includes/nginx_modern_include.conf
&lt;/pre&gt;&lt;pre class="wiki"&gt;locate nginx_octopus_include.conf | grep -v backups | grep -v \.drush | grep -v root
  /data/disk/tn/config/includes/nginx_octopus_include.conf
  /var/aegir/config/includes/nginx_octopus_include.conf
&lt;/pre&gt;&lt;p&gt;
These files do have the changes:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;/var/aegir/config/includes/nginx_modern_include.conf
&lt;/li&gt;&lt;li&gt;/var/aegir/config/includes/nginx_octopus_include.conf
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
But these don't:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;/data/disk/tn/config/includes/nginx_modern_include.conf
&lt;/li&gt;&lt;li&gt;/data/disk/tn/config/includes/nginx_octopus_include.conf
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Should they be manually edited or is there a BOA way to update them?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 14 Apr 2014 12:26:20 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:37</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:37</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.2&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;10.02&lt;/em&gt; to &lt;em&gt;10.22&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The two load spike suicides on Saturday didn't trigger any alerts from CSF so this config in &lt;tt&gt;/etc/csf/csf.conf&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# Check the PT_LOAD_AVG minute Load Average (can be set to 1 5 or 15 and
# defaults to 5 if set otherwise) on the server every PT_LOAD seconds. If the
# load average is greater than or equal to PT_LOAD_LEVEL then an email alert is
# sent. lfd then does not report subsequent high load until PT_LOAD_SKIP
# seconds has passed to prevent email floods.
#
# Set PT_LOAD to "0" to disable this feature
PT_LOAD = "30"
PT_LOAD_AVG = "5"
PT_LOAD_LEVEL = "6"
PT_LOAD_SKIP = "3600"
&lt;/pre&gt;&lt;p&gt;
Has been updated to:
&lt;/p&gt;
&lt;pre class="wiki"&gt;PT_LOAD = "10"
PT_LOAD_AVG = "1"
PT_LOAD_LEVEL = "3"
PT_LOAD_SKIP = "60"
&lt;/pre&gt;&lt;p&gt;
Also this was changed, though I don't know if it'll work:
&lt;/p&gt;
&lt;pre class="wiki"&gt;#PT_APACHESTATUS = "http://127.0.0.1/server-status"
PT_APACHESTATUS = "http://127.0.0.1/nginx_status"
&lt;/pre&gt;&lt;p&gt;
Restarting:
&lt;/p&gt;
&lt;pre class="wiki"&gt;csf -r
  lfd will restart csf within the next 5 seconds
  *WARNING* PT_LOAD_SKIP sanity check. PT_LOAD_SKIP = 60. Recommended range: 1800-86400 (Default: 3600)
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Wed, 16 Apr 2014 11:03:57 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:38</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:38</guid>
      <description>
        &lt;p&gt;
have there been any more issues since Satruday?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 16 Apr 2014 11:10:26 GMT</pubDate>
      <title>attachment set</title>
      <link>http://localhost:8080/trac/ticket/707</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;attachment&lt;/strong&gt;
                set to &lt;em&gt;puffin_2014-04-16_load-week.png&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 16 Apr 2014 11:49:32 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/707#comment:39</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:39</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.65&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;10.22&lt;/em&gt; to &lt;em&gt;10.87&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
There haven't been any load spike suicides since the two on Saturday, but the load is more spiky:
&lt;/p&gt;
&lt;p&gt;
&lt;a style="padding:0; border:none" href="http://localhost:8080/trac/attachment/ticket/707/puffin_2014-04-16_load-week.png"&gt;&lt;img src="http://localhost:8080/trac/raw-attachment/ticket/707/puffin_2014-04-16_load-week.png" /&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The problems on Saturday could well have been mostly, or perhaps totally, because to Redis wasn't running as BOA didn't create a directory for it's process ID file. Or perhaps the suicide thresholds are now set at too low a level? I haven't spent the time to read the updated suicide script to work out what is needed to trigger one.
&lt;/p&gt;
&lt;p&gt;
Using the BOA defaults for MySQL has resulted in MySQL having 1/2 the RAM it had before, this has probably contributed to the changed behaviour, I think we should breach the "use stock BOA settings where possible" policy, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt;, and make changes to the MySQL settings, see &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/587#comment:13" title="maintenance: Puffin MySQL Tuning (assigned)"&gt;ticket:587#comment:13&lt;/a&gt;, the time for that comment has been included in the time for this one.
&lt;/p&gt;
&lt;p&gt;
I still haven't had time to have a close look at the logs from Saturday, but I'm also not sure that it's worth spending any time on this now?
&lt;/p&gt;
&lt;p&gt;
The documentation on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; needs quite a lot of updating, once that has been done then this ticket and &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt; can probably be closed.
&lt;/p&gt;
&lt;p&gt;
This ticket and &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/670" title="maintenance: Roll back performance customisations and use stock BOA settings where ... (closed: fixed)"&gt;ticket:670&lt;/a&gt; are going to end up totalling over 16 hours, this means that this BOA upgrade will have taken twice as longs as the last one, which took 8 hours, see &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#Upgradetickets"&gt;wiki:PuffinServer#Upgradetickets&lt;/a&gt; for the totals.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 30 Apr 2014 09:55:05 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/707#comment:40</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:40</guid>
      <description>
        &lt;p&gt;
Very sorry that when doing this update I forgot to run &lt;tt&gt;octopus up-stable all&lt;/tt&gt;, this might be the cause of the cron tasks stopping, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/724#comment:6" title="defect: Subscription emails from Rob's blog not arriving. (closed: fixed)"&gt;ticket:724#comment:6&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
There is also another BOA update that is outstanding, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/721" title="maintenance: Upgrade to BOA-2.2.3 Stable Edition (closed: fixed)"&gt;ticket:721&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
I'll to that update and this time not forget to run &lt;tt&gt;octopus up-stable all&lt;/tt&gt;, after midnight tonight, so it comes out of the May maintenance budget, unless I hear otherwise.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 01 May 2014 13:16:36 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/707#comment:41</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/707#comment:41</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Closing as it's been superceeded by &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/721" title="maintenance: Upgrade to BOA-2.2.3 Stable Edition (closed: fixed)"&gt;ticket:721&lt;/a&gt; for the 2.2.3 update.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>