Latest topic 5 d ago

Web Hosting Discussion Forums, Tutorials, Reviews & Services forum

forumweb.hosting ↗

XenForo forum in English.

Discussions per day
0
Discussions collected
55
Messages per day
2
Sections
0
Sources tracked
1
Engine
XenForo

Latest discussions

Collected every 4 hours from the forum's public feed. Only the title, the link and the beginning of the message are reproduced; every link points back to the source.

fail2ban banned the customer, and the customer is the one who phoned

Classic version of this: someone's mail client has an old password saved, retries every couple of minutes, trips the jail, and the ban is at firewall level so they lose the website too. From their side the site went down for no reason. Worse when the office sits behind one NAT address. One misconfigured phone in the corner and everybody in the building is locked out, and nothing in the site logs explains it because the traffic never reached the site. Adding them to ignoreip fixes the call... fail2ban banned the customer, and the customer is the one who phoned

The customer says the site is slow and every graph you have says it is not

Load average fine, memory fine, disk fine, uptime graph a flat green line, and a customer on the phone telling you the site is unusable. Had this often enough that I stopped treating the graphs as an answer. Averages are the first thing that hides it. A mean response time looks healthy while the slowest five percent of requests are terrible, and if the customer's admin pages happen to live in that five percent then their experience of the site is the slow one. Logging per request duration... The customer says the site is slow and every graph you have says it is not

Redirect loop after putting a site behind a proxy, and the certificate was never the problem

Moved a site behind a proxy and it started bouncing between itself until the browser gave up. Certificate was valid, the proxy was fine, and the site worked perfectly when I hit the origin directly. TLS terminates at the proxy, so the proxy talks to the origin over plain HTTP. The application looks at its own connection, sees HTTP, and issues a redirect to HTTPS. That redirect goes back through the proxy, which again calls the origin over HTTP. Nothing is broken, it is just two layers each... Redirect loop after putting a site behind a proxy, and the certificate was never the problem

Mail from the site lands in spam and the DNS records all check out

Spent a week convinced my SPF record was wrong. It was not. DKIM signed, DMARC published, every online checker green, and the mail still went to spam for two of the bigger providers. The problem was the envelope sender. SPF is evaluated against the address in MAIL FROM, not the From header your recipient sees. A script calling PHP's mail() hands the message to the local sendmail, which sets the envelope sender to the system user at the server hostname. So SPF gets checked against a hostname... Mail from the site lands in spam and the DNS records all check out

Swap on a box with plenty of RAM, still worth having?

Keep going back and forth on this. The argument for turning it off entirely is that swap only converts a fast death into a slow one, and a server that is thrashing is worse than a server that has restarted. Where I ended up is keeping swap but setting vm.swappiness low, somewhere around 10. The reasoning is that a long running box accumulates pages that are genuinely cold, daemons that started and never did anything since, and moving those out leaves more room for page cache. That is a real... Swap on a box with plenty of RAM, still worth having?

df says the disk is full, du cannot find the space, and neither is lying

Hit 100 percent on a VPS and spent an hour with du adding up to maybe thirty gigabytes less than df was reporting. The gap was real, not a rounding problem. It was a log file that had been deleted while the service still had it open. The directory entry is gone so du cannot see it, but the inode stays allocated until the process closes the handle, so df still counts it. lsof +L1 lists exactly these. Restarting the service released it immediately, no reboot needed. Since then... df says the disk is full, du cannot find the space, and neither is lying

Uploaded over FTP, served by PHP-FPM, and the two disagree about who owns the file

A directory on one of my boxes ended up with two sets of files, half owned by the FTP user and half by the pool user PHP-FPM runs as. Both look fine in a listing. The site works until something tries to write next to a file it does not own. The symptom that gave it away was WordPress asking for FTP credentials to run an update. It does that when the files are not owned by the user executing PHP, which is correct behaviour and a useful signal, though it took me a while to read it that way... Uploaded over FTP, served by PHP-FPM, and the two disagree about who owns the file

The cron job runs fine by hand and does nothing at 3am

A backup script I wrote ran perfectly every time I tested it from the shell, then silently produced nothing for four nights in a row once it was in crontab. No error anywhere I thought to look. Cron does not give your job the environment your login shell has. The PATH it hands over is usually just /usr/bin:/bin, it does not read .bashrc or .profile, and HOME may not be what you assume. So a script calling mysqldump or php or aws by bare name works when you run it and fails the moment cron... The cron job runs fine by hand and does nothing at 3am

Which tool should I use to compare my hosting provider's speed with other hosting providers?

There are lots of different online performance tests: Google PageSpeed Insights iWebTool Speed Test AlertFox Page Load Time WebPageTest Also there are several desktop/client software such as: ping tool YSlow Firebug's Net console Fiddler Http Watch I just want to decide if my hosting provider has a good enough performance or if I need to switch my hosting to another provider. So, which tool should I use to compare speed of my hosting provider with other hosting providers?

Which alerts did you switch off, and did any of them come back to bite you?

The monitoring got noisier than the servers. Disk warnings firing every night while a backup writes and clearing an hour later, load spikes during log rotation, certificate notices for domains that renew themselves anyway. After a few months of that I had stopped reading any of it, which is the same as not having it. First thing I cut was anything that resolves without me. If an alert has never once required me to do something, it is not an alert, it is a graph, and it belongs on a... Which alerts did you switch off, and did any of them come back to bite you?

Splitting RAM between MySQL and PHP-FPM on a single VPS, how do you decide?

On a box running both the database and the PHP workers, the two are competing for the same RAM, and I keep discovering I gave one of them too much only when the OOM killer picks a side. It usually picks MySQL, which is the worst available outcome, because the site then serves errors instead of merely being slow. My rough method is to size the InnoDB buffer pool to fit the working set if it fits at all, then work out how many PHP-FPM workers the remainder allows using the memory those... Splitting RAM between MySQL and PHP-FPM on a single VPS, how do you decide?

55 discussions collected since 2 September 2026. Track this forum by keyword →