Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cc72fda741 | ||
|
|
a865a13940 | ||
|
|
8dbfdf599a | ||
|
|
2e85f458d3 |
@@ -9,21 +9,34 @@
|
||||
serverName shared-ols
|
||||
|
||||
## Real client IP behind HAProxy. HAProxy sets X-Forwarded-For (the real
|
||||
## client) and X-Forwarded-Proto. Mode 2 = trust the proxy header. HAProxy is
|
||||
## the only thing that ever connects to this tier (it's not publicly exposed),
|
||||
## so trusting the header from the docker-network peer is safe — same trust
|
||||
## model as the shared httpd's RemoteIPInternalProxy.
|
||||
useIpInProxyHeader 2
|
||||
## client) and X-Forwarded-Proto. Mode 1 = always use X-Forwarded-For as the
|
||||
## client IP. HAProxy is the ONLY thing that ever connects to this tier (it's on
|
||||
## client-net with no host-published ports) and it OVERWRITES X-Forwarded-For
|
||||
## with %[src] (set-header, not add-header), so a client can't spoof it — mode 1
|
||||
## is safe here and matches the working standalone litespeed config.
|
||||
## NOTE: mode 2 ("trusted IP only") does NOT mean "trust the proxy header" — it
|
||||
## extracts the real IP ONLY when the connecting peer is in a TRUSTED access
|
||||
## list, which this tier never configured. With mode 2 + no trusted IP, OLS kept
|
||||
## HAProxy's container IP as REMOTE_ADDR for every request, so WP security
|
||||
## plugins saw all tenants as one IP and blocking it locked everyone out.
|
||||
useIpInProxyHeader 1
|
||||
|
||||
## LSCache enabled at MODULE scope for the whole tier (dedicated cache volume,
|
||||
## ephemeral across rebuilds; OLS auto-keys a per-vhost subdir under storagePath).
|
||||
## enableCache/enablePrivateCache ON here means the cache module is ACTIVE, but a
|
||||
## response is only cached if it's marked cacheable — the LiteSpeed Cache WP
|
||||
## plugin sets X-LiteSpeed-Cache-Control headers, and checkPublic/PrivateCache +
|
||||
## ignoreRespCacheCtrl=0 make OLS honor them. No plugin → nothing cached (safe).
|
||||
## PUBLIC (anonymous) caching ONLY: enableCache 1 + checkPublicCache 1 let OLS
|
||||
## serve cacheable, non-logged-in responses marked by the LiteSpeed Cache WP
|
||||
## plugin's X-LiteSpeed-Cache-Control headers (ignoreRespCacheCtrl=0 honors them).
|
||||
##
|
||||
## PRIVATE caching is intentionally OFF (enablePrivateCache 0 + checkPrivateCache 0).
|
||||
## Logged-in / cookie-bearing pages must NEVER be cached at the tier. We previously
|
||||
## left enablePrivateCache=1 assuming "no plugin -> nothing cached," but that was
|
||||
## WRONG: with private storage + reqCookieCache on, OLS privately cached logged-in
|
||||
## responses regardless of plugin, serving stale wp-admin (e.g. a "failed update"
|
||||
## nag that persisted for the full privateExpireInSeconds TTL). Keeping private
|
||||
## cache off guarantees logged-in pages are always served fresh.
|
||||
module cache {
|
||||
storagePath ${LSCACHE_ROOT}
|
||||
checkPrivateCache 1
|
||||
checkPrivateCache 0
|
||||
checkPublicCache 1
|
||||
maxCacheObjSize 10000000
|
||||
maxStaleAge 200
|
||||
@@ -33,6 +46,6 @@ module cache {
|
||||
ignoreReqCacheCtrl 0
|
||||
ignoreRespCacheCtrl 0
|
||||
enableCache 1
|
||||
enablePrivateCache 1
|
||||
enablePrivateCache 0
|
||||
}
|
||||
## ---- end shared-ols server append ----
|
||||
|
||||
Reference in New Issue
Block a user