All manual sections

DocumentationApache/.htaccess compatibility

Apache/.htaccess compatibility

The panel serves the sites with nginx: fast, with the certificate, the page cache and the protections. nginx does not read .htaccess files: for WordPress, Joomla, Drupal, PrestaShop and the applications of Install apps the panel already writes the equivalent rules. If a site has rules of its own in .htaccess (redirects, address rewrites, password-protected folders, error pages), turn on the Apache/.htaccess compatibility.

How it works

  • nginx stays in front: HTTPS certificate, static files (images, CSS, JavaScript) and the WordPress page cache.
  • PHP and the addresses that are not a file go to Apache, listening only on the server's internal address (127.0.0.1): it reads the .htaccess files (AllowOverride All) and runs PHP with the same PHP-FPM pool of the site, so as the site user, with its limits and the PHP settings of the site page.
  • The visitor's address and HTTPS reach Apache from nginx: PHP sees the visitor's real IP (it cannot be forged with a header) and HTTPS=on when the site uses HTTPS.
  • The WordPress page cache keeps working, with the same rules (never for logged-in users, carts, checkouts, the admin area).

Turning it on

On the site page, Web server box, turn on Apache/.htaccess compatibility. The first time an administrator installs Apache (about a minute, mpm_event with mod_proxy_fcgi, mod_rewrite, mod_remoteip); afterwards accounts turn it on for their own sites too. Turning it off, the site is served by nginx alone again.

During a migration from cPanel or another server the panel checks the .htaccess files: when it finds rules of their own (beyond WordPress's standard block) it offers to turn the compatibility on for those sites, and does it during the import.

Good to know

  • Files that exist are served by nginx: an .htaccess rule blocking a static file does not apply. To protect files keep them outside the public folder, or use an Apache password-protected folder for PHP pages.
  • With the symbolic links protection of the Isolation & limits module, .htaccess files cannot turn Options +FollowSymLinks back on (such a line gives a 500 error: remove it).
  • The site's Apache logs are next to nginx's: /var/log/nginx/<domain>.apache-access.log and .apache-error.log.