Repository navigation
Expand file tree
/
Copy pathdefault
More file actions
181 lines (164 loc) · 6.32 KB
/
Copy pathdefault
File metadata and controls
181 lines (164 loc) · 6.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
# PerfSimPhp - Nginx site configuration for Azure App Service PHP blessed image
#
# This file is a SERVER BLOCK only (not a complete nginx.conf).
# Per Microsoft docs, it is copied to /etc/nginx/sites-available/default
# by the startup command, overriding the stock site config.
#
# DUAL FPM POOL ARCHITECTURE:
# - Port 9000 (www pool): Load test and other endpoints
# - Port 9001 (metrics pool): Reserved for /api/metrics/* and /api/health/*
# This prevents load test traffic from starving the dashboard.
#
# Startup command (set in Azure Portal → General Settings):
# /home/site/wwwroot/startup.sh
#
# Reference: https://docs.microsoft.com/azure/app-service/configure-language-php?pivots=platform-linux#change-site-root
# Upstream definitions for the two FPM pools
upstream fpm_main {
server 127.0.0.1:9000;
}
upstream fpm_metrics {
server 127.0.0.1:9001;
}
server {
#proxy_cache cache;
#proxy_cache_valid 200 1s;
listen 80;
listen [::]:80;
listen 8080;
listen [::]:8080;
root /home/site/wwwroot/public;
index index.php index.html index.htm hostingstart.html;
server_name _;
port_in_redirect off;
# Security headers
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
# Disable HSTS to prevent caching of HTTPS redirects during debugging
add_header Strict-Transport-Security "max-age=0" always;
# Front controller: serve static files, fall through to index.php
location / {
index index.php index.html index.htm hostingstart.html;
try_files $uri $uri/ /index.php?$args;
}
# ==========================================================================
# METRICS POOL ROUTES — Dedicated workers that can't be starved by load test
# ==========================================================================
# /api/metrics/probe → MAIN pool (measures main pool latency, not metrics pool)
location = /api/metrics/probe {
try_files $uri /index.php?$args;
fastcgi_split_path_info ^(.+?\.php)(|/.*)$;
fastcgi_pass fpm_main;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $query_string;
fastcgi_param REQUEST_URI $request_uri;
fastcgi_intercept_errors on;
fastcgi_connect_timeout 5;
fastcgi_send_timeout 30;
fastcgi_read_timeout 30;
}
# /api/metrics (not /probe) and /api/metrics/internal-probes → metrics pool
location ~ ^/api/metrics(/|$) {
try_files $uri /index.php?$args;
fastcgi_split_path_info ^(.+?\.php)(|/.*)$;
fastcgi_pass fpm_metrics;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $query_string;
fastcgi_param REQUEST_URI $request_uri;
fastcgi_intercept_errors on;
fastcgi_connect_timeout 5;
fastcgi_send_timeout 30;
fastcgi_read_timeout 30;
}
# /api/health/probe → MAIN pool (measures main pool latency for dashboard)
location = /api/health/probe {
try_files $uri /index.php?$args;
fastcgi_split_path_info ^(.+?\.php)(|/.*)$;
fastcgi_pass fpm_main;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $query_string;
fastcgi_param REQUEST_URI $request_uri;
fastcgi_intercept_errors on;
fastcgi_connect_timeout 5;
fastcgi_send_timeout 30;
fastcgi_read_timeout 30;
}
# /api/health/* → metrics pool (port 9001)
location ~ ^/api/health(/|$) {
try_files $uri /index.php?$args;
fastcgi_split_path_info ^(.+?\.php)(|/.*)$;
fastcgi_pass fpm_metrics;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $query_string;
fastcgi_param REQUEST_URI $request_uri;
fastcgi_intercept_errors on;
fastcgi_connect_timeout 5;
fastcgi_send_timeout 30;
fastcgi_read_timeout 30;
}
# /api/admin/events → metrics pool (event log for dashboard)
location = /api/admin/events {
try_files $uri /index.php?$args;
fastcgi_split_path_info ^(.+?\.php)(|/.*)$;
fastcgi_pass fpm_metrics;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $query_string;
fastcgi_param REQUEST_URI $request_uri;
fastcgi_intercept_errors on;
fastcgi_connect_timeout 5;
fastcgi_send_timeout 30;
fastcgi_read_timeout 30;
}
# Redirect server error pages to the static page /50x.html
location = /50x.html {
root /html/;
}
# Disable .git directory
location ~ /\.git {
deny all;
access_log off;
log_not_found off;
}
# Deny access to hidden files
location ~ /\. {
deny all;
access_log off;
log_not_found off;
}
# PHP-FPM processing — MAIN POOL (load test, simulations, etc.)
location ~ [^/]\.php(/|$) {
fastcgi_split_path_info ^(.+?\.php)(|/.*)$;
fastcgi_pass fpm_main;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $query_string;
fastcgi_intercept_errors on;
fastcgi_connect_timeout 300;
fastcgi_send_timeout 3600;
fastcgi_read_timeout 3600;
fastcgi_buffer_size 128k;
fastcgi_buffers 4 256k;
fastcgi_busy_buffers_size 256k;
}
# Gzip compression
gzip on;
gzip_types text/plain text/css application/json application/javascript text/xml application/xml image/svg+xml;
gzip_min_length 1000;
}