@cryptotaxi247 / netdata-1 / commits / f6c6b34fa

Update Running-behind-apache.md (#6406)

* Update Running-behind-apache.md Added example Apache 2.4 dedicated host file. Order deny, allow directives will be depricated in future version. Basic Auth can be added to the Proxy block so Location block can be removed. Added example Apache 2.4.24 unix domain socket location. * Fixing back-qutoes line 265

Steve8291 committed Jul 9, 2019 at 12:34 UTC f6c6b34fa6d024e0bcb96198f35a18e2d871cc92
1 file changed +42 -3
docs/Running-behind-apache.md
+42 -3
@@ -3,7 +3,7 @@
3 Below you can find instructions for configuring an apache server to:
4
5 1. proxy a single Netdata via an HTTP and HTTPS virtual host
6 -2. dynamically proxy any number of Netdata
6 +2. dynamically proxy any number of Netdata servers
7 3. add user authentication
8 4. adjust Netdata settings to get optimal results
9
@@ -145,13 +145,15 @@ sudo a2ensite netdata.conf && service apache2 reload
145
146 ## Netdata proxy in Plesk
147 _Assuming the main goal is to make Netdata running in HTTPS._
148 +
149 1. Make a subdomain for Netdata on which you enable and force HTTPS - You can use a free Let's Encrypt certificate
150 2. Go to "Apache & nginx Settings", and in the following section, add:
151 +
152 ```
153 RewriteEngine on
154 RewriteRule (.*) http://localhost:19999/$1 [P,L]
155 ```
154 -3. Optional: If your server is remote, then just replace "localhost" with your actual hostname or IP, it just works.
156 +3. Optional: If your server is remote, then just replace "localhost" with your actual hostname or IP, it just works.
157
158 Repeat the operation for as many servers as you need.
159
@@ -164,6 +166,7 @@ Install the package `apache2-utils`. On debian / ubuntu run `sudo apt-get instal
166
167 Then, generate password for user `netdata`, using `htpasswd -c /etc/apache2/.htpasswd netdata`
168
169 +**Apache 2.2 Example:**
170 Modify the virtual host with these:
171
172 ```
@@ -186,6 +189,34 @@ Modify the virtual host with these:
189
190 Specify `Location /` if Netdata is running on dedicated virtual host.
191
192 +
193 +
194 +**Apache 2.4 (dedicated virtual host) Example:**
195 +
196 +```
197 +<VirtualHost *:80>
198 + RewriteEngine On
199 + ProxyRequests Off
200 + ProxyPreserveHost On
201 +
202 + ServerName netdata.domain.tld
203 +
204 + <Proxy *>
205 + AllowOverride None
206 + AuthType Basic
207 + AuthName "Protected site"
208 + AuthUserFile /etc/apache2/.htpasswd
209 + Require valid-user
210 + </Proxy>
211 +
212 + ProxyPass "/" "http://localhost:19999/" connectiontimeout=5 timeout=30 keepalive=on
213 + ProxyPassReverse "/" "http://localhost:19999/"
214 +
215 + ErrorLog ${APACHE_LOG_DIR}/netdata-error.log
216 + CustomLog ${APACHE_LOG_DIR}/netdata-access.log combined
217 +</VirtualHost>
218 +```
219 +
220 Note: Changes are applied by reloading or restarting Apache.
221
222 # Netdata configuration
@@ -230,6 +261,14 @@ You can also use a unix domain socket. This will also provide a faster route bet
261 [web]
262 bind to = unix:/tmp/netdata.sock
263 ```
264 +
265 +Apache 2.4.24+ can not read from `/tmp` so create your socket in `/var/run/netdata`
266 +
267 +```
268 +[web]
269 + bind to = unix:/var/run/netdata/netdata.sock
270 +```
271 +
272 _note: Netdata v1.8+ support unix domain sockets_
273
274 At the apache side, prepend the 2nd argument to `ProxyPass` with `unix:/tmp/netdata.sock|`, like this:
@@ -265,6 +304,6 @@ apache logs accesses and Netdata logs them too. You can prevent Netdata from gen
304 Make sure the requests reach Netdata, by examing `/var/log/netdata/access.log`.
305
306 1. if the requests do not reach Netdata, your apache does not forward them.
268 -2. if the requests reach Netdata by the URLs are wrong, you have not re-written them properly.
307 +2. if the requests reach Netdata but the URLs are wrong, you have not re-written them properly.
308
309 [![analytics](https://www.google-analytics.com/collect?v=1&aip=1&t=pageview&_s=1&ds=github&dr=https%3A%2F%2Fgithub.com%2Fnetdata%2Fnetdata&dl=https%3A%2F%2Fmy-netdata.io%2Fgithub%2Fdocs%2FRunning-behind-apache&_u=MAC~&cid=5792dfd7-8dc4-476b-af31-da2fdb9f93d2&tid=UA-64295674-3)]()