3623
Comment: Basic Apache
|
6674
More Apache examples
|
Deletions are marked like this. | Additions are marked like this. |
Line 134: | Line 134: |
== Location-specific configuration == {{{domain "yourdomain" with web "www" with location "/private" with errorDocument "404" "not_found_private.html"; end; (* When in the /private tree of URI-space, handle 404s with not_found_private.html *) directory "/usr/local/doc" with errorDocument "404" "not_found_doc.html"; end; (* When looking for a file in real directory /usr/local/doc, handle 404s with not_found_doc.html *) end; end;}}} == Server aliases == {{{domain "yourdomain" with web "www" with serverAlias "www2.yourdomain"; serverAlias "www.otherdomain"; (* www2.yourdomain and www.otherdomain are alternate names for this vhost *) end end;}}} Note that you must have domtool configuration rights to all domains you name with `serverAlias`. == Directory options == {{{domain "yourdomain" with web "www" with options [execCGI, indexes]; (* Use exactly the Apache options execCGI and indexes by default for this vhost *) set_options [includesNOEXEC]; (* Add the option includesNOEXEC, leaving the others alone *) unset_options [indexes]; (* Change our mind about including indexes *) directoryIndex ["index.html", "index.php", "index.txt"]; (* When looking for the default file to serve for a directory, consider these possibilities in order *) action "image/gif" "/cgi-bin/images.cgi"; (* Run /cgi-bin/images.cgi to serve images *) addDefaultCharset "utf-8"; (* Use the UTF-8 character set by default *) location "/prefix" with forceType "text/plain"; (* Serve all files in this location as plain text *) forceTypeOff; (* Change our mind about that! *) (* All the other directives mentioned above can be used in locations, too, but forceType* _must_ be in a location. *) end; end; end;}}} == Access control == {{{domain "yourdomain" with vhost "www" with location "/loc1" with authType basic; (* Use HTTP basic authentication in this location *) authName "my domain"; (* Tell users that they're authenticating for "my domain" *) authUserFile "/etc/webusers"; (* Look up user/password information in /etc/webusers *) orderAllowDeny; (* Access is denied by default *) requireValidUser; (* Anyone providing a valid password is allowed *) denyFrom "badguys.evil.net"; (* However, anyone coming from this domain is banned *) denyFrom "1.2"; (* Also ban anyone with a 1.2.*.* IP address *) end; location "/loc2"; authType basic; authName "my other domain"; authUserFile "/etc/otherone"; denyFromAll; (* Deny everyone by default *) requireUser ["fred", "barney"]; (* Allow fred and barney in *) requireGroup ["prehistoric"]; (* Also require membership in the prehistoric group *) end; end; end}}} |
Here are some example configuration files for DomTool, our distributed configuration management system.
1. Domains
1.1. The Model T
If you just want to declare your domain with a www.yourdomain virtual host serving out of ~/public_html/ and all mail forwarded to your mailbox, use: {{{dom "yourdomain" with end;}}}
1.2. Upgraded Model T
If you like everything dom gives you but want to add additional configuration, include it between with..end. For instance, to add an extra web virtual host other: {{{dom "yourdomain" with
- web "other" with
- (* More configuration could go here *)
end;}}}
1.3. The Do-It-Yourself
The lowest-level way of configuring a domain is the domain directive, which does nothing but set up basic DNS parameters and provide a space for including further directives: {{{domain "yourdomain" with
- (* Your directives here *)
end;}}}
2. DNS
Here's a tour through the available DNS features.
{{{domain "yourdomain" with
- nameserver "ns.hcoop.net"; nameserver "ns2.hcoop.net"; (* Specify two DNS servers that are authoritative for yourdomain *) dnsIP "host" "1.2.3.4"; (* Add a mapping from host.yourdomain to IP address 1.2.3.4 *) dnsMail 23 "mail.yourdomain"; (* Register mail.yourdomain as an SMTP handler for yourdomain, with priority 23 *) dnsAlias "hcoop" "hcoop.net"; (* Add an alias such that hcoop.yourdomain resolves to the same thing as hcoop.net *) dnsIP "dynamic" "5.6.7.8" where
- TTL = 100
end;}}}
3. Mail
{{{domain "yourdomain" with
- handleMail; (* HCoop should provide relaying for yourdomain *)
emailAlias "user1" "user1@gmail.com"; (* Forward mail from user1@yourdomain to user1@gmail.com *) emailAlias "user2" "me"; (* Forward mail from user2@yourdomain to HCoop user me *)
aliasMulti "pals" ["pal1@yahoo.com", "pal2@prodigy.com", "pal3"]; (* Forward mail from pals@yorudomain to pal1@yahoo.com, pal2@prodigy.com, and HCoop user pal3 *) aliasDrop "spamtrap"; (* Silently drop all mail to spamtrap@yourdomain *) defaultAlias "me"; (* Send all yourdomain mail that doesn't match some local user or other special rule to user me *) catchAllAlias "me"; (* Send all yourdomain mail, period, to user me *)
end;}}}
4. Apache
4.1. The Model T
{{{domain "yourdomain" with
- web "www" with
- (* This is a web host found at www.yourdomain. *)
end;}}}
Note that the web directive also adds the right DNS mapping for your virtual host.
4.2. The Do-It-Yourself
{{{domain "yourdomain" with
- vhost "www" with end;
end;}}}
This one doesn't add any DNS mappings.
4.3. Using a nonstandard web server
{{{domain "yourdomain" with
- web "www" where
WebNodes = ["fyodor"]
end;}}}
4.4. Bucking all the trends
{{{domain "yourdomain" with
- web "www" where
DocumentRoot = "/some/random/directory"; User = "me_web"; Group = "me_web"; SSL = true
end;}}}
4.5. Basic URL handling
{{{domain "yourdomain" with
- web "www" with
- alias "/doc" "/usr/local/doc"; (* Serve all URIs beginning in /doc out of directory /usr/local/doc *) scriptAlias "/my-script" "/var/cgi/a-program"; (* Handle requests for /my-script by calling the CGI program /var/cgi/a-program *) errorDocument "404" "not_found.html"; (* Handle HTTP error code 404 by sending file not_found.html *)
end;}}}
4.6. Location-specific configuration
{{{domain "yourdomain" with
- web "www" with
- location "/private" with
- errorDocument "404" "not_found_private.html";
- errorDocument "404" "not_found_doc.html";
- location "/private" with
end;}}}
4.7. Server aliases
{{{domain "yourdomain" with
- web "www" with
- serverAlias "www2.yourdomain"; serverAlias "www.otherdomain"; (* www2.yourdomain and www.otherdomain are alternate names for this vhost *)
end;}}}
Note that you must have domtool configuration rights to all domains you name with serverAlias.
4.8. Directory options
{{{domain "yourdomain" with
- web "www" with
- options [execCGI, indexes]; (* Use exactly the Apache options execCGI and indexes by default for this vhost *) set_options [includesNOEXEC]; (* Add the option includesNOEXEC, leaving the others alone *) unset_options [indexes]; (* Change our mind about including indexes *) directoryIndex ["index.html", "index.php", "index.txt"]; (* When looking for the default file to serve for a directory, consider these possibilities in order *) action "image/gif" "/cgi-bin/images.cgi"; (* Run /cgi-bin/images.cgi to serve images *) addDefaultCharset "utf-8"; (* Use the UTF-8 character set by default *) location "/prefix" with
- forceType "text/plain"; (* Serve all files in this location as plain text *) forceTypeOff; (* Change our mind about that! *) (* All the other directives mentioned above can be used in locations, too, but forceType* _must_ be in a location. *)
- options [execCGI, indexes]; (* Use exactly the Apache options execCGI and indexes by default for this vhost *) set_options [includesNOEXEC]; (* Add the option includesNOEXEC, leaving the others alone *) unset_options [indexes]; (* Change our mind about including indexes *) directoryIndex ["index.html", "index.php", "index.txt"]; (* When looking for the default file to serve for a directory, consider these possibilities in order *) action "image/gif" "/cgi-bin/images.cgi"; (* Run /cgi-bin/images.cgi to serve images *) addDefaultCharset "utf-8"; (* Use the UTF-8 character set by default *) location "/prefix" with
end;}}}
4.9. Access control
{{{domain "yourdomain" with
- vhost "www" with
- location "/loc1" with
- authType basic; (* Use HTTP basic authentication in this location *) authName "my domain"; (* Tell users that they're authenticating for "my domain" *) authUserFile "/etc/webusers"; (* Look up user/password information in /etc/webusers *) orderAllowDeny; (* Access is denied by default *) requireValidUser; (* Anyone providing a valid password is allowed *) denyFrom "badguys.evil.net"; (* However, anyone coming from this domain is banned *) denyFrom "1.2"; (* Also ban anyone with a 1.2.*.* IP address *)
- authType basic; authName "my other domain"; authUserFile "/etc/otherone"; denyFromAll; (* Deny everyone by default *) requireUser ["fred", "barney"]; (* Allow fred and barney in *) requireGroup ["prehistoric"]; (* Also require membership in the prehistoric group *)
- location "/loc1" with
end}}}