我已经用 php-fpm 解决了这个问题。
您需要的是以下内容。在 apache 中你需要为 php 文件定义代理:
<FilesMatch "\.php$">
<If "-f %{REQUEST_FILENAME}">
SetHandler "proxy:unix:/run/phpfpm/foo_com.sock"
</If>
</FilesMatch>
您需要在 php-fpm 配置中定义(例如 foo.com 站点):
[foo_com]
group = wwwrun
listen = /run/phpfpm/foo_com.sock
listen.group = wwwrun
listen.owner = wwwrun
pm = dynamic
pm.max_children = 32
pm.max_requests = 500
pm.max_spare_servers = 4
pm.min_spare_servers = 2
pm.start_servers = 2
user = wp-foo_com
然后在 mysql 中,您需要拥有 wp-foo_com 具有权限的用户,例如foo_com 数据库。
在 wp-config.php 中,您将 define( 'DB_HOST', '120.0.0.1' ); 替换为 define( 'DB_HOST', 'localhost:/run/mysqld/mysqld.sock' ); 假设 /run/mysqld/mysqld.sock 是 mysql 套接字的路径。
为什么会这样?因为当对任何 php 文件的请求进入时,它将被传递给 php-fpm(通过 apache),然后 php-fpm 以上面配置中定义的用户身份执行该代码(在我们的示例中,它是 wp-foo_com 用户)。
如果有人在使用 nixos,你可以使用这个配置:
{ config, pkgs, lib, ... }:
let
domain = "foo.com";
normalizedDomain = "foo_com";
user = "wp-${normalizedDomain}";
group = config.services.httpd.group;
in {
networking.firewall.enable = true;
networking.firewall.allowedTCPPorts = [ 80 443 ];
services.mysql.package = pkgs.mysql;
services.mysql.enable = true;
services.mysql.ensureDatabases = [ normalizedDomain ];
services.mysql.ensureUsers = [{
name = user;
ensurePermissions = { "${normalizedDomain}.*" = "ALL PRIVILEGES"; };
}];
users.users.${user}.group = group;
services.phpfpm.pools."${normalizedDomain}" = {
inherit user group;
phpPackage = pkgs.php;
settings = {
"pm" = "dynamic";
"pm.max_children" = 32;
"pm.max_requests" = 500;
"pm.max_spare_servers" = 4;
"pm.min_spare_servers" = 2;
"pm.start_servers" = 2;
"listen.owner" = config.services.httpd.user;
"listen.group" = config.services.httpd.group;
};
};
services.httpd = {
enable = true;
enablePHP = true;
extraModules = [ "proxy_fcgi" ];
virtualHosts."${normalizedDomain}" = {
adminAddr = "admin@localhost";
serverAliases = [ domain "www.${domain}" ];
documentRoot = "/var/www/${normalizedDomain}/public_html";
extraConfig = ''
<Directory "/var/www/${normalizedDomain}/public_html">
<FilesMatch "\.php$">
<If "-f %{REQUEST_FILENAME}">
SetHandler "proxy:unix:/run/phpfpm/${normalizedDomain}.sock|fcgi://localhost/"
</If>
</FilesMatch>
# standard wordpress .htaccess contents
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
DirectoryIndex index.php
Require all granted
Options +FollowSymLinks
</Directory>
# https://wordpress.org/support/article/hardening-wordpress/#securing-wp-config-php
<Files wp-config.php>
Require all denied
</Files>
'';
};
};
services.httpd.adminAddr = "admin@example.com";
}