Apache/.htaccess compatibility
The panel serves the sites with nginx: fast, with the certificate, the page cache and the protections. nginx does not read .htaccess files: for WordPress, Joomla, Drupal, PrestaShop and the applications of Install apps the panel already writes the equivalent rules. If a site has rules of its own in .htaccess (redirects, address rewrites, password-protected folders, error pages), turn on the Apache/.htaccess compatibility.
How it works
- nginx stays in front: HTTPS certificate, static files (images, CSS, JavaScript) and the WordPress page cache.
- PHP and the addresses that are not a file go to Apache, listening only on the server's internal address (127.0.0.1): it reads the
.htaccessfiles (AllowOverride All) and runs PHP with the same PHP-FPM pool of the site, so as the site user, with its limits and the PHP settings of the site page. - The visitor's address and HTTPS reach Apache from nginx: PHP sees the visitor's real IP (it cannot be forged with a header) and
HTTPS=onwhen the site uses HTTPS. - The WordPress page cache keeps working, with the same rules (never for logged-in users, carts, checkouts, the admin area).
Turning it on
On the site page, Web server box, turn on Apache/.htaccess compatibility. The first time an administrator installs Apache (about a minute, mpm_event with mod_proxy_fcgi, mod_rewrite, mod_remoteip); afterwards accounts turn it on for their own sites too. Turning it off, the site is served by nginx alone again.
During a migration from cPanel or another server the panel checks the .htaccess files: when it finds rules of their own (beyond WordPress's standard block) it offers to turn the compatibility on for those sites, and does it during the import.
Good to know
- Files that exist are served by nginx: an
.htaccessrule blocking a static file does not apply. To protect files keep them outside the public folder, or use an Apache password-protected folder for PHP pages. - With the symbolic links protection of the Isolation & limits module,
.htaccessfiles cannot turnOptions +FollowSymLinksback on (such a line gives a 500 error: remove it). - The site's Apache logs are next to nginx's:
/var/log/nginx/<domain>.apache-access.logand.apache-error.log.