diff --git a/README.md b/README.md
index cdcf34f27..974052478 100644
--- a/README.md
+++ b/README.md
@@ -154,6 +154,7 @@ File `install-dependencies` and the relevant subdirectories in `deps-packaging`
| [apr-util](https://apr.apache.org/) | 1.6.3 | 1.6.3 | 1.6.3 |
| [Git](https://www.kernel.org/pub/software/scm/git/) | 2.47.0 | 2.47.0 | 2.47.0 |
| [libexpat](https://libexpat.github.io/) | - | 2.6.3 | 2.6.3 |
+| [nghttp2](https://nghttp2.opg/) | - | - | 1.62.1 |
| [PHP](http://php.net/) | 8.3.12 | 8.3.12 | 8.3.12 |
| [PostgreSQL](http://www.postgresql.org/) | 15.8 | 16.4 | 17.0 |
| [rsync](https://download.samba.org/pub/rsync/) | 3.3.0 | 3.3.0 | 3.3.0 |
diff --git a/build-scripts/compile-options b/build-scripts/compile-options
index 11b091805..2efea9b64 100644
--- a/build-scripts/compile-options
+++ b/build-scripts/compile-options
@@ -208,7 +208,7 @@ case "$ROLE" in
# HUB-ONLY dependencies
hub)
var_append DEPS "libcurl-hub"
- var_append DEPS "libexpat apr apr-util apache git rsync"
+ var_append DEPS "nghttp2 libexpat apr apr-util apache git rsync"
var_append DEPS "postgresql php"
;;
# AGENT-ONLY dependencies
diff --git a/build-scripts/install-dependencies b/build-scripts/install-dependencies
index 9daa041d4..39a7c68f3 100755
--- a/build-scripts/install-dependencies
+++ b/build-scripts/install-dependencies
@@ -48,7 +48,7 @@ check_and_install_perl()
"too old"
PERL_OK="no"
fi
- if ! perl -e 'use List::Util qw(pairs);'; then
+ if ! $PERL -e 'use List::Util qw(pairs);'; then
echo "$PERL has List::Util that does not export pairs. Needs to be at least version 1.29 for OpenSSL version 3.3.2."
PERL_OK="no"
fi
diff --git a/deps-packaging/apache/cfbuild-apache.spec b/deps-packaging/apache/cfbuild-apache.spec
index be143048e..fde623b55 100644
--- a/deps-packaging/apache/cfbuild-apache.spec
+++ b/deps-packaging/apache/cfbuild-apache.spec
@@ -30,13 +30,13 @@ CPPFLAGS=-I%{buildprefix}/include
--prefix=%{prefix}/httpd \
--enable-so \
--enable-mods-shared="all ssl ldap authnz_ldap" \
+ --enable-http2 \
--with-z=%{prefix} \
--with-ssl=%{prefix} \
--with-ldap=%{prefix} \
--with-apr=%{prefix} \
--with-apr-util=%{prefix} \
--with-pcre=%{prefix}/bin/pcre2-config \
- --with-mpm=prefork \
CPPFLAGS="$CPPFLAGS"
%build
diff --git a/deps-packaging/apache/debian/rules b/deps-packaging/apache/debian/rules
index 504541046..d76a3e604 100755
--- a/deps-packaging/apache/debian/rules
+++ b/deps-packaging/apache/debian/rules
@@ -24,7 +24,6 @@ build-stamp:
--with-apr=$(PREFIX) \
--with-apr-util=$(PREFIX) \
--with-pcre=$(PREFIX)/bin/pcre2-config \
---with-mpm=prefork \
CPPFLAGS="$(CPPFLAGS)"
make
diff --git a/deps-packaging/apache/httpd.conf b/deps-packaging/apache/httpd.conf
index 73bbcddd6..dab0b71ab 100644
--- a/deps-packaging/apache/httpd.conf
+++ b/deps-packaging/apache/httpd.conf
@@ -235,11 +235,19 @@ LogLevel warn
-
-LoadModule php_module modules/libphp.so
-AddHandler php-script .php
-AddType application/x-httpd-php-source php
-
+# Use mod_http2
+LoadModule http2_module modules/mod_http2.so
+# Prefer http2 protocol
+Protocols h2 h2c http/1.1
+
+# Setup php to be handled by php-fpm. Required for use of mod_http2 due to threading issues in php.
+LoadModule proxy_module modules/mod_proxy.so
+LoadModule proxy_fcgi_module modules/mod_proxy_fcgi.so
+# need to pass Authorization headers to fpm for API requests
+SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1
+
+SetHandler "proxy:fcgi://127.0.0.1:9000"
+
diff --git a/deps-packaging/nghttp2/cfbuild-nghttp2.spec b/deps-packaging/nghttp2/cfbuild-nghttp2.spec
new file mode 100644
index 000000000..07aeb11e6
--- /dev/null
+++ b/deps-packaging/nghttp2/cfbuild-nghttp2.spec
@@ -0,0 +1,67 @@
+%define nghttp2_version 1.62.1
+
+Summary: CFEngine Build Automation -- nghttp2
+Name: cfbuild-nghttp2
+Version: %{version}
+Release: 1
+Source0: nghttp2-%{nghttp2_version}.tar.xz
+License: MIT
+Group: Other
+Url: nghttp2.org
+BuildRoot: %{_topdir}/BUILD/%{name}-%{version}-%{release}-buildroot
+
+AutoReqProv: no
+
+%define prefix %{buildprefix}
+%prep
+mkdir -p %{_builddir}
+%setup -q -n nghttp2-%{nghttp2_version}
+
+./configure --prefix=%{prefix}
+
+%build
+
+make
+
+%install
+
+rm -rf ${RPM_BUILD_ROOT}
+
+make install DESTDIR=${RPM_BUILD_ROOT}
+
+# Remove unused files
+rm -rf ${RPM_BUILD_ROOT}%{prefix}/lib/libnghttp2.*a
+rm -rf ${RPM_BUILD_ROOT}%{prefix}/share/doc/nghttp2/README.rst
+rm -rf ${RPM_BUILD_ROOT}%{prefix}/share/man/man1/h2load.1
+rm -rf ${RPM_BUILD_ROOT}%{prefix}/share/man/man1/nghttp*
+rm -rf ${RPM_BUILD_ROOT}%{prefix}/share/nghttp2/fetch-ocsp-response
+
+%clean
+
+rm -rf $RPM_BUILD_ROOT
+
+%package devel
+Summary: CFEngine Build Automation -- nghttp2 -- development files
+Group: Other
+AutoReqProv: no
+
+%description
+CFEngine Build Automation -- nghttp2
+
+%description devel
+CFEngine Build Automation -- nghttp2 -- development files
+
+%files
+%defattr(-,root,root)
+
+%dir %prefix/lib
+%prefix/lib/*.so*
+
+%files devel
+%defattr(-,root,root)
+
+%prefix/include
+%dir %prefix/lib
+%prefix/lib/pkgconfig
+
+%changelog
diff --git a/deps-packaging/nghttp2/debian/cfbuild-nghttp2-devel.install b/deps-packaging/nghttp2/debian/cfbuild-nghttp2-devel.install
new file mode 100644
index 000000000..96c4b3019
--- /dev/null
+++ b/deps-packaging/nghttp2/debian/cfbuild-nghttp2-devel.install
@@ -0,0 +1,2 @@
+/var/cfengine/include
+/var/cfengine/lib/pkgconfig
diff --git a/deps-packaging/nghttp2/debian/cfbuild-nghttp2.install b/deps-packaging/nghttp2/debian/cfbuild-nghttp2.install
new file mode 100644
index 000000000..d47339c9d
--- /dev/null
+++ b/deps-packaging/nghttp2/debian/cfbuild-nghttp2.install
@@ -0,0 +1 @@
+/var/cfengine/lib/*.so*
diff --git a/deps-packaging/nghttp2/debian/compat b/deps-packaging/nghttp2/debian/compat
new file mode 100644
index 000000000..f599e28b8
--- /dev/null
+++ b/deps-packaging/nghttp2/debian/compat
@@ -0,0 +1 @@
+10
diff --git a/deps-packaging/nghttp2/debian/control b/deps-packaging/nghttp2/debian/control
new file mode 100644
index 000000000..778b59ddc
--- /dev/null
+++ b/deps-packaging/nghttp2/debian/control
@@ -0,0 +1,18 @@
+Source: cfbuild-nghttp2
+Section: libs
+Priority: optional
+Maintainer: CFEngine Packages
+Build-Depends: debhelper
+Standard-Version: 3.8.4
+
+Package: cfbuild-nghttp2
+Section: libs
+Architecture: any
+Description: CFEngine Build Automation -- nghttp2
+ CFEngine Build Automation -- nghttp2
+
+Package: cfbuild-nghttp2-devel
+Section: libdevel
+Architecture: any
+Desciption: CFEngine Build Automation -- cfbuild-nghttp2-devel
+ CFEngine Build Automation -- cfbuild-nghttp2-devel
diff --git a/deps-packaging/nghttp2/debian/copyright b/deps-packaging/nghttp2/debian/copyright
new file mode 100644
index 000000000..e69de29bb
diff --git a/deps-packaging/nghttp2/debian/rules b/deps-packaging/nghttp2/debian/rules
new file mode 100644
index 000000000..cf106c36b
--- /dev/null
+++ b/deps-packaging/nghttp2/debian/rules
@@ -0,0 +1,50 @@
+#!/usr/bin/make -f
+PREFIX=$(BUILDPREFIX)
+
+clean:
+ dh_testdir
+ dh_testroot
+
+ dh_clean
+
+build: build-stamp
+build-stamp:
+ dh_testdir
+
+ ./configure --prefix=$(PREFIX)
+
+ make
+
+ touch build-stamp
+
+install: build
+ dh_testdir
+ dh_testroot
+ dh_clean -k
+ dh_installdirs
+
+ $(MAKE) install DESTDIR=$(CURDIR)/debian/tmp
+
+ rm -rf $(CURDIR)/debian/tmp$(PREFIX)/lib/libnghttp2.*a
+ rm -rf $(CURDIR)/debian/tmp$(PREFIX)/share/doc/nghttp2/README.rst
+ rm -rf $(CURDIR)/debian/tmp$(PREFIX)/share/man/man1/h2load.1
+ rm -rf $(CURDIR)/debian/tmp$(PREFIX)/share/man/man1/nghttp*
+ rm -rf $(CURDIR)/debian/tmp$(PREFIX)/share/nghttp2
+
+binary-indep: build install
+
+binary-arch: build install
+ dh_testdir
+ dh_testroot
+ dh_install --sourcedir=debian/tmp
+ dh_link
+ dh_strip
+ dh_compress
+ dh_fixperms
+ dh_installdeb
+ dh_gencontrol
+ dh_md5sums
+ dh_builddeb
+
+binary: binary-indep binary-arch
+.PHONY: build clean binary-indep binary-arch binary install configure
diff --git a/deps-packaging/nghttp2/distfiles b/deps-packaging/nghttp2/distfiles
new file mode 100644
index 000000000..ab9b85cef
--- /dev/null
+++ b/deps-packaging/nghttp2/distfiles
@@ -0,0 +1 @@
+2345d4dc136fda28ce243e0bb21f2e7e8ef6293d62c799abbf6f633a6887af72 nghttp2-1.62.1.tar.xz
diff --git a/deps-packaging/nghttp2/source b/deps-packaging/nghttp2/source
new file mode 100644
index 000000000..bbdbefacd
--- /dev/null
+++ b/deps-packaging/nghttp2/source
@@ -0,0 +1 @@
+https://github.com/nghttp2/nghttp2/releases/download/v1.62.1/
diff --git a/deps-packaging/php/cfbuild-php.spec b/deps-packaging/php/cfbuild-php.spec
index 4761e0fe6..7fe3d9abb 100644
--- a/deps-packaging/php/cfbuild-php.spec
+++ b/deps-packaging/php/cfbuild-php.spec
@@ -6,6 +6,7 @@ Version: %{version}
Release: 1
Source0: php-%{php_version}.tar.gz
Source1: php.ini
+Source2: php-fpm.conf
License: MIT
Group: Other
Url: http://example.com/
@@ -45,10 +46,7 @@ LDFLAGS=""
--enable-mbstring \
--enable-sockets \
--disable-mbregex \
- --without-fpm-user \
- --without-fpm-group \
- --without-fpm-systemd \
- --without-fpm-acl \
+ --enable-fpm \
--without-layout \
--without-sqlite3 \
--without-bz2 \
@@ -113,7 +111,9 @@ make
%install
rm -rf ${RPM_BUILD_ROOT}
mkdir -p ${RPM_BUILD_ROOT}%{prefix}/httpd/conf
+mkdir -p ${RPM_BUILD_ROOT}%{prefix}/httpd/php/etc
cp %{prefix}/httpd/conf/httpd.conf ${RPM_BUILD_ROOT}%{prefix}/httpd/conf
+cp ${RPM_BUILD_ROOT}/../../SOURCES/php-fpm.conf ${RPM_BUILD_ROOT}%{prefix}/httpd/php/etc
INSTALL_ROOT=${RPM_BUILD_ROOT} make install
@@ -168,7 +168,8 @@ CFEngine Build Automation -- php -- development files
%prefix/httpd/php/lib
%prefix/httpd/php/bin
%prefix/httpd/php/php
-%prefix/httpd/php/lib/php.ini
+%prefix/httpd/php/etc
+%prefix/httpd/php/sbin
%dir %prefix/httpd/modules
%prefix/httpd/modules/libphp.so
diff --git a/deps-packaging/php/debian/cfbuild-php.install b/deps-packaging/php/debian/cfbuild-php.install
index b40f834e0..3cc70ea08 100644
--- a/deps-packaging/php/debian/cfbuild-php.install
+++ b/deps-packaging/php/debian/cfbuild-php.install
@@ -3,3 +3,5 @@
/var/cfengine/httpd/php/php
/var/cfengine/httpd/modules/libphp.so
/var/cfengine/httpd/php/lib/php.ini
+/var/cfengine/httpd/php/etc/php-fpm.conf
+/var/cfengine/httpd/php/sbin/php-fpm
diff --git a/deps-packaging/php/debian/rules b/deps-packaging/php/debian/rules
index 94eaf588d..22a305053 100755
--- a/deps-packaging/php/debian/rules
+++ b/deps-packaging/php/debian/rules
@@ -25,10 +25,7 @@ build-stamp:
--enable-mbstring \
--enable-sockets \
--disable-mbregex \
---without-fpm-user \
---without-fpm-group \
---without-fpm-systemd \
---without-fpm-acl \
+--enable-fpm \
--without-layout \
--without-sqlite3 \
--without-bz2 \
@@ -96,7 +93,9 @@ install: build
dh_installdirs
mkdir -p $(CURDIR)/debian/tmp$(PREFIX)/httpd/conf
+ mkdir -p $(CURDIR)/debian/tmp$(PREFIX)/httpd/php/etc
cp $(PREFIX)/httpd/conf/httpd.conf $(CURDIR)/debian/tmp$(PREFIX)/httpd/conf/httpd.conf
+ cp $(CURDIR)/php-fpm.conf $(CURDIR)/debian/tmp$(PREFIX)/httpd/php/etc/
INSTALL_ROOT=$(CURDIR)/debian/tmp CPPFLAGS="-I$(PREFIX)/include" LD_LIBRARY_PATH="$(PREFIX)/lib" LD_RUN_PATH="$(PREFIX)/lib" $(MAKE) install
diff --git a/deps-packaging/php/php-fpm.conf b/deps-packaging/php/php-fpm.conf
new file mode 100644
index 000000000..d63b60f59
--- /dev/null
+++ b/deps-packaging/php/php-fpm.conf
@@ -0,0 +1,629 @@
+;;;;;;;;;;;;;;;;;;;;;
+; FPM Configuration ;
+;;;;;;;;;;;;;;;;;;;;;
+
+; All relative paths in this configuration file are relative to PHP's install
+; prefix (/var/cfengine/httpd/php). This prefix can be dynamically changed by using the
+; '-p' argument from the command line.
+
+;;;;;;;;;;;;;;;;;;
+; Global Options ;
+;;;;;;;;;;;;;;;;;;
+
+[global]
+; Pid file
+; Note: the default prefix is /var/cfengine/httpd/php/var
+; Default Value: none
+;pid = run/php-fpm.pid
+pid = /var/cfengine/httpd/php-fpm.pid
+
+; Error log file
+; If it's set to "syslog", log is sent to syslogd instead of being written
+; into a local file.
+; Note: the default prefix is /var/cfengine/httpd/php/var
+; Default Value: log/php-fpm.log
+;error_log = log/php-fpm.log
+error_log = syslog
+
+; syslog_facility is used to specify what type of program is logging the
+; message. This lets syslogd specify that messages from different facilities
+; will be handled differently.
+; See syslog(3) for possible values (ex daemon equiv LOG_DAEMON)
+; Default Value: daemon
+;syslog.facility = daemon
+
+; syslog_ident is prepended to every message. If you have multiple FPM
+; instances running on the same server, you can change the default value
+; which must suit common needs.
+; Default Value: php-fpm
+;syslog.ident = php-fpm
+
+; Log level
+; Possible Values: alert, error, warning, notice, debug
+; Default Value: notice
+;log_level = notice
+
+; Log limit on number of characters in the single line (log entry). If the
+; line is over the limit, it is wrapped on multiple lines. The limit is for
+; all logged characters including message prefix and suffix if present. However
+; the new line character does not count into it as it is present only when
+; logging to a file descriptor. It means the new line character is not present
+; when logging to syslog.
+; Default Value: 1024
+;log_limit = 4096
+
+; Log buffering specifies if the log line is buffered which means that the
+; line is written in a single write operation. If the value is false, then the
+; data is written directly into the file descriptor. It is an experimental
+; option that can potentially improve logging performance and memory usage
+; for some heavy logging scenarios. This option is ignored if logging to syslog
+; as it has to be always buffered.
+; Default value: yes
+;log_buffering = no
+
+; If this number of child processes exit with SIGSEGV or SIGBUS within the time
+; interval set by emergency_restart_interval then FPM will restart. A value
+; of '0' means 'Off'.
+; Default Value: 0
+;emergency_restart_threshold = 0
+
+; Interval of time used by emergency_restart_interval to determine when
+; a graceful restart will be initiated. This can be useful to work around
+; accidental corruptions in an accelerator's shared memory.
+; Available Units: s(econds), m(inutes), h(ours), or d(ays)
+; Default Unit: seconds
+; Default Value: 0
+;emergency_restart_interval = 0
+
+; Time limit for child processes to wait for a reaction on signals from master.
+; Available units: s(econds), m(inutes), h(ours), or d(ays)
+; Default Unit: seconds
+; Default Value: 0
+;process_control_timeout = 0
+
+; The maximum number of processes FPM will fork. This has been designed to control
+; the global number of processes when using dynamic PM within a lot of pools.
+; Use it with caution.
+; Note: A value of 0 indicates no limit
+; Default Value: 0
+; process.max = 128
+
+; Specify the nice(2) priority to apply to the master process (only if set)
+; The value can vary from -19 (highest priority) to 20 (lowest priority)
+; Note: - It will only work if the FPM master process is launched as root
+; - The pool process will inherit the master process priority
+; unless specified otherwise
+; Default Value: no set
+; process.priority = -19
+
+; Send FPM to background. Set to 'no' to keep FPM in foreground for debugging.
+; Default Value: yes
+;daemonize = yes
+
+; Set open file descriptor rlimit for the master process.
+; Default Value: system defined value
+;rlimit_files = 1024
+
+; Set max core size rlimit for the master process.
+; Possible Values: 'unlimited' or an integer greater or equal to 0
+; Default Value: system defined value
+;rlimit_core = 0
+
+; Specify the event mechanism FPM will use. The following is available:
+; - select (any POSIX os)
+; - poll (any POSIX os)
+; - epoll (linux >= 2.5.44)
+; - kqueue (FreeBSD >= 4.1, OpenBSD >= 2.9, NetBSD >= 2.0)
+; - /dev/poll (Solaris >= 7)
+; - port (Solaris >= 10)
+; Default Value: not set (auto detection)
+;events.mechanism = epoll
+
+; When FPM is built with systemd integration, specify the interval,
+; in seconds, between health report notification to systemd.
+; Set to 0 to disable.
+; Available Units: s(econds), m(inutes), h(ours)
+; Default Unit: seconds
+; Default value: 10
+;systemd_interval = 10
+
+;;;;;;;;;;;;;;;;;;;;
+; Pool Definitions ;
+;;;;;;;;;;;;;;;;;;;;
+
+; Multiple pools of child processes may be started with different listening
+; ports and different management options. The name of the pool will be
+; used in logs and stats. There is no limitation on the number of pools which
+; FPM can handle. Your system will tell you anyway :)
+
+; Start a new pool named 'www'.
+; the variable $pool can be used in any directive and will be replaced by the
+; pool name ('www' here)
+[www]
+
+; Per pool prefix
+; It only applies on the following directives:
+; - 'access.log'
+; - 'slowlog'
+; - 'listen' (unixsocket)
+; - 'chroot'
+; - 'chdir'
+; - 'php_values'
+; - 'php_admin_values'
+; When not set, the global prefix (or /var/cfengine/httpd/php) applies instead.
+; Note: This directive can also be relative to the global prefix.
+; Default Value: none
+;prefix = /path/to/pools/$pool
+
+; Unix user/group of the child processes. This can be used only if the master
+; process running user is root. It is set after the child process is created.
+; The user and group can be specified either by their name or by their numeric
+; IDs.
+; Note: If the user is root, the executable needs to be started with
+; --allow-to-run-as-root option to work.
+; Default Values: The user is set to master process running user by default.
+; If the group is not set, the user's group is used.
+user = cfapache
+group = cfapache
+
+; The address on which to accept FastCGI requests.
+; Valid syntaxes are:
+; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
+; a specific port;
+; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
+; a specific port;
+; 'port' - to listen on a TCP socket to all addresses
+; (IPv6 and IPv4-mapped) on a specific port;
+; '/path/to/unix/socket' - to listen on a unix socket.
+; Note: This value is mandatory.
+listen = 127.0.0.1:9000
+
+; Set listen(2) backlog.
+; Default Value: 511 (-1 on Linux, FreeBSD and OpenBSD)
+;listen.backlog = 511
+
+; Set permissions for unix socket, if one is used. In Linux, read/write
+; permissions must be set in order to allow connections from a web server. Many
+; BSD-derived systems allow connections regardless of permissions. The owner
+; and group can be specified either by name or by their numeric IDs.
+; Default Values: Owner is set to the master process running user. If the group
+; is not set, the owner's group is used. Mode is set to 0660.
+;listen.owner = nobody
+;listen.group = nobody
+;listen.mode = 0660
+
+; When POSIX Access Control Lists are supported you can set them using
+; these options, value is a comma separated list of user/group names.
+; When set, listen.owner and listen.group are ignored
+;listen.acl_users =
+;listen.acl_groups =
+
+; List of addresses (IPv4/IPv6) of FastCGI clients which are allowed to connect.
+; Equivalent to the FCGI_WEB_SERVER_ADDRS environment variable in the original
+; PHP FCGI (5.2.2+). Makes sense only with a tcp listening socket. Each address
+; must be separated by a comma. If this value is left blank, connections will be
+; accepted from any ip address.
+; Default Value: any
+;listen.allowed_clients = 127.0.0.1
+
+; Set the associated the route table (FIB). FreeBSD only
+; Default Value: -1
+;listen.setfib = 1
+
+; Specify the nice(2) priority to apply to the pool processes (only if set)
+; The value can vary from -19 (highest priority) to 20 (lower priority)
+; Note: - It will only work if the FPM master process is launched as root
+; - The pool processes will inherit the master process priority
+; unless it specified otherwise
+; Default Value: no set
+; process.priority = -19
+
+; Set the process dumpable flag (PR_SET_DUMPABLE prctl for Linux or
+; PROC_TRACE_CTL procctl for FreeBSD) even if the process user
+; or group is different than the master process user. It allows to create process
+; core dump and ptrace the process for the pool user.
+; Default Value: no
+; process.dumpable = yes
+
+; Choose how the process manager will control the number of child processes.
+; Possible Values:
+; static - a fixed number (pm.max_children) of child processes;
+; dynamic - the number of child processes are set dynamically based on the
+; following directives. With this process management, there will be
+; always at least 1 children.
+; pm.max_children - the maximum number of children that can
+; be alive at the same time.
+; pm.start_servers - the number of children created on startup.
+; pm.min_spare_servers - the minimum number of children in 'idle'
+; state (waiting to process). If the number
+; of 'idle' processes is less than this
+; number then some children will be created.
+; pm.max_spare_servers - the maximum number of children in 'idle'
+; state (waiting to process). If the number
+; of 'idle' processes is greater than this
+; number then some children will be killed.
+; pm.max_spawn_rate - the maximum number of rate to spawn child
+; processes at once.
+; ondemand - no children are created at startup. Children will be forked when
+; new requests will connect. The following parameter are used:
+; pm.max_children - the maximum number of children that
+; can be alive at the same time.
+; pm.process_idle_timeout - The number of seconds after which
+; an idle process will be killed.
+; Note: This value is mandatory.
+pm = dynamic
+
+; The number of child processes to be created when pm is set to 'static' and the
+; maximum number of child processes when pm is set to 'dynamic' or 'ondemand'.
+; This value sets the limit on the number of simultaneous requests that will be
+; served. Equivalent to the ApacheMaxClients directive with mpm_prefork.
+; Equivalent to the PHP_FCGI_CHILDREN environment variable in the original PHP
+; CGI. The below defaults are based on a server without much resources. Don't
+; forget to tweak pm.* to fit your needs.
+; Note: Used when pm is set to 'static', 'dynamic' or 'ondemand'
+; Note: This value is mandatory.
+; Note: For CFEngine the settings below should be synchronized between here and masterfiles/cfe_internal/enterprise/mission_portal.cf
+pm.max_children = 16
+
+; The number of child processes created on startup.
+; Note: Used only when pm is set to 'dynamic'
+; Default Value: (min_spare_servers + max_spare_servers) / 2
+pm.start_servers = 4
+
+; The desired minimum number of idle server processes.
+; Note: Used only when pm is set to 'dynamic'
+; Note: Mandatory when pm is set to 'dynamic'
+pm.min_spare_servers = 2
+
+; The desired maximum number of idle server processes.
+; Note: Used only when pm is set to 'dynamic'
+; Note: Mandatory when pm is set to 'dynamic'
+pm.max_spare_servers = 6
+
+; The number of rate to spawn child processes at once.
+; Note: Used only when pm is set to 'dynamic'
+; Note: Mandatory when pm is set to 'dynamic'
+; Default Value: 32
+;pm.max_spawn_rate = 32
+
+; The number of seconds after which an idle process will be killed.
+; Note: Used only when pm is set to 'ondemand'
+; Default Value: 10s
+;pm.process_idle_timeout = 10s;
+
+; The number of requests each child process should execute before respawning.
+; This can be useful to work around memory leaks in 3rd party libraries. For
+; endless request processing specify '0'. Equivalent to PHP_FCGI_MAX_REQUESTS.
+; Default Value: 0
+;pm.max_requests = 500
+
+; The URI to view the FPM status page. If this value is not set, no URI will be
+; recognized as a status page. It shows the following information:
+; pool - the name of the pool;
+; process manager - static, dynamic or ondemand;
+; start time - the date and time FPM has started;
+; start since - number of seconds since FPM has started;
+; accepted conn - the number of request accepted by the pool;
+; listen queue - the number of request in the queue of pending
+; connections (see backlog in listen(2));
+; max listen queue - the maximum number of requests in the queue
+; of pending connections since FPM has started;
+; listen queue len - the size of the socket queue of pending connections;
+; idle processes - the number of idle processes;
+; active processes - the number of active processes;
+; total processes - the number of idle + active processes;
+; max active processes - the maximum number of active processes since FPM
+; has started;
+; max children reached - number of times, the process limit has been reached,
+; when pm tries to start more children (works only for
+; pm 'dynamic' and 'ondemand');
+; Value are updated in real time.
+; Example output:
+; pool: www
+; process manager: static
+; start time: 01/Jul/2011:17:53:49 +0200
+; start since: 62636
+; accepted conn: 190460
+; listen queue: 0
+; max listen queue: 1
+; listen queue len: 42
+; idle processes: 4
+; active processes: 11
+; total processes: 15
+; max active processes: 12
+; max children reached: 0
+;
+; By default the status page output is formatted as text/plain. Passing either
+; 'html', 'xml' or 'json' in the query string will return the corresponding
+; output syntax. Example:
+; http://www.foo.bar/status
+; http://www.foo.bar/status?json
+; http://www.foo.bar/status?html
+; http://www.foo.bar/status?xml
+;
+; By default the status page only outputs short status. Passing 'full' in the
+; query string will also return status for each pool process.
+; Example:
+; http://www.foo.bar/status?full
+; http://www.foo.bar/status?json&full
+; http://www.foo.bar/status?html&full
+; http://www.foo.bar/status?xml&full
+; The Full status returns for each process:
+; pid - the PID of the process;
+; state - the state of the process (Idle, Running, ...);
+; start time - the date and time the process has started;
+; start since - the number of seconds since the process has started;
+; requests - the number of requests the process has served;
+; request duration - the duration in µs of the requests;
+; request method - the request method (GET, POST, ...);
+; request URI - the request URI with the query string;
+; content length - the content length of the request (only with POST);
+; user - the user (PHP_AUTH_USER) (or '-' if not set);
+; script - the main script called (or '-' if not set);
+; last request cpu - the %cpu the last request consumed
+; it's always 0 if the process is not in Idle state
+; because CPU calculation is done when the request
+; processing has terminated;
+; last request memory - the max amount of memory the last request consumed
+; it's always 0 if the process is not in Idle state
+; because memory calculation is done when the request
+; processing has terminated;
+; If the process is in Idle state, then informations are related to the
+; last request the process has served. Otherwise informations are related to
+; the current request being served.
+; Example output:
+; ************************
+; pid: 31330
+; state: Running
+; start time: 01/Jul/2011:17:53:49 +0200
+; start since: 63087
+; requests: 12808
+; request duration: 1250261
+; request method: GET
+; request URI: /test_mem.php?N=10000
+; content length: 0
+; user: -
+; script: /home/fat/web/docs/php/test_mem.php
+; last request cpu: 0.00
+; last request memory: 0
+;
+; Note: There is a real-time FPM status monitoring sample web page available
+; It's available in: /var/cfengine/httpd/php/share/php/fpm/status.html
+;
+; Note: The value must start with a leading slash (/). The value can be
+; anything, but it may not be a good idea to use the .php extension or it
+; may conflict with a real PHP file.
+; Default Value: not set
+;pm.status_path = /status
+
+; The address on which to accept FastCGI status request. This creates a new
+; invisible pool that can handle requests independently. This is useful
+; if the main pool is busy with long running requests because it is still possible
+; to get the status before finishing the long running requests.
+;
+; Valid syntaxes are:
+; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
+; a specific port;
+; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
+; a specific port;
+; 'port' - to listen on a TCP socket to all addresses
+; (IPv6 and IPv4-mapped) on a specific port;
+; '/path/to/unix/socket' - to listen on a unix socket.
+; Default Value: value of the listen option
+;pm.status_listen = 127.0.0.1:9001
+
+; The ping URI to call the monitoring page of FPM. If this value is not set, no
+; URI will be recognized as a ping page. This could be used to test from outside
+; that FPM is alive and responding, or to
+; - create a graph of FPM availability (rrd or such);
+; - remove a server from a group if it is not responding (load balancing);
+; - trigger alerts for the operating team (24/7).
+; Note: The value must start with a leading slash (/). The value can be
+; anything, but it may not be a good idea to use the .php extension or it
+; may conflict with a real PHP file.
+; Default Value: not set
+;ping.path = /ping
+
+; This directive may be used to customize the response of a ping request. The
+; response is formatted as text/plain with a 200 response code.
+; Default Value: pong
+;ping.response = pong
+
+; The access log file
+; Default: not set
+;access.log = log/$pool.access.log
+
+; The access log format.
+; The following syntax is allowed
+; %%: the '%' character
+; %C: %CPU used by the request
+; it can accept the following format:
+; - %{user}C for user CPU only
+; - %{system}C for system CPU only
+; - %{total}C for user + system CPU (default)
+; %d: time taken to serve the request
+; it can accept the following format:
+; - %{seconds}d (default)
+; - %{milliseconds}d
+; - %{milli}d
+; - %{microseconds}d
+; - %{micro}d
+; %e: an environment variable (same as $_ENV or $_SERVER)
+; it must be associated with embraces to specify the name of the env
+; variable. Some examples:
+; - server specifics like: %{REQUEST_METHOD}e or %{SERVER_PROTOCOL}e
+; - HTTP headers like: %{HTTP_HOST}e or %{HTTP_USER_AGENT}e
+; %f: script filename
+; %l: content-length of the request (for POST request only)
+; %m: request method
+; %M: peak of memory allocated by PHP
+; it can accept the following format:
+; - %{bytes}M (default)
+; - %{kilobytes}M
+; - %{kilo}M
+; - %{megabytes}M
+; - %{mega}M
+; %n: pool name
+; %o: output header
+; it must be associated with embraces to specify the name of the header:
+; - %{Content-Type}o
+; - %{X-Powered-By}o
+; - %{Transfert-Encoding}o
+; - ....
+; %p: PID of the child that serviced the request
+; %P: PID of the parent of the child that serviced the request
+; %q: the query string
+; %Q: the '?' character if query string exists
+; %r: the request URI (without the query string, see %q and %Q)
+; %R: remote IP address
+; %s: status (response code)
+; %t: server time the request was received
+; it can accept a strftime(3) format:
+; %d/%b/%Y:%H:%M:%S %z (default)
+; The strftime(3) format must be encapsulated in a %{}t tag
+; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
+; %T: time the log has been written (the request has finished)
+; it can accept a strftime(3) format:
+; %d/%b/%Y:%H:%M:%S %z (default)
+; The strftime(3) format must be encapsulated in a %{}t tag
+; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
+; %u: remote user
+;
+; Default: "%R - %u %t \"%m %r\" %s"
+;access.format = "%R - %u %t \"%m %r%Q%q\" %s %f %{milli}d %{kilo}M %C%%"
+
+; A list of request_uri values which should be filtered from the access log.
+;
+; As a security precuation, this setting will be ignored if:
+; - the request method is not GET or HEAD; or
+; - there is a request body; or
+; - there are query parameters; or
+; - the response code is outwith the successful range of 200 to 299
+;
+; Note: The paths are matched against the output of the access.format tag "%r".
+; On common configurations, this may look more like SCRIPT_NAME than the
+; expected pre-rewrite URI.
+;
+; Default Value: not set
+;access.suppress_path[] = /ping
+;access.suppress_path[] = /health_check.php
+
+; The log file for slow requests
+; Default Value: not set
+; Note: slowlog is mandatory if request_slowlog_timeout is set
+;slowlog = log/$pool.log.slow
+
+; The timeout for serving a single request after which a PHP backtrace will be
+; dumped to the 'slowlog' file. A value of '0s' means 'off'.
+; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
+; Default Value: 0
+;request_slowlog_timeout = 0
+
+; Depth of slow log stack trace.
+; Default Value: 20
+;request_slowlog_trace_depth = 20
+
+; The timeout for serving a single request after which the worker process will
+; be killed. This option should be used when the 'max_execution_time' ini option
+; does not stop script execution for some reason. A value of '0' means 'off'.
+; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
+; Default Value: 0
+;request_terminate_timeout = 0
+
+; The timeout set by 'request_terminate_timeout' ini option is not engaged after
+; application calls 'fastcgi_finish_request' or when application has finished and
+; shutdown functions are being called (registered via register_shutdown_function).
+; This option will enable timeout limit to be applied unconditionally
+; even in such cases.
+; Default Value: no
+;request_terminate_timeout_track_finished = no
+
+; Set open file descriptor rlimit.
+; Default Value: system defined value
+;rlimit_files = 1024
+
+; Set max core size rlimit.
+; Possible Values: 'unlimited' or an integer greater or equal to 0
+; Default Value: system defined value
+;rlimit_core = 0
+
+; Chroot to this directory at the start. This value must be defined as an
+; absolute path. When this value is not set, chroot is not used.
+; Note: you can prefix with '$prefix' to chroot to the pool prefix or one
+; of its subdirectories. If the pool prefix is not set, the global prefix
+; will be used instead.
+; Note: chrooting is a great security feature and should be used whenever
+; possible. However, all PHP paths will be relative to the chroot
+; (error_log, sessions.save_path, ...).
+; Default Value: not set
+;chroot =
+
+; Chdir to this directory at the start.
+; Note: relative path can be used.
+; Default Value: current directory or / when chroot
+;chdir = /var/www
+
+; Redirect worker stdout and stderr into main error log. If not set, stdout and
+; stderr will be redirected to /dev/null according to FastCGI specs.
+; Note: on highloaded environment, this can cause some delay in the page
+; process time (several ms).
+; Default Value: no
+;catch_workers_output = yes
+
+; Decorate worker output with prefix and suffix containing information about
+; the child that writes to the log and if stdout or stderr is used as well as
+; log level and time. This options is used only if catch_workers_output is yes.
+; Settings to "no" will output data as written to the stdout or stderr.
+; Default value: yes
+;decorate_workers_output = no
+
+; Clear environment in FPM workers
+; Prevents arbitrary environment variables from reaching FPM worker processes
+; by clearing the environment in workers before env vars specified in this
+; pool configuration are added.
+; Setting to "no" will make all environment variables available to PHP code
+; via getenv(), $_ENV and $_SERVER.
+; Default Value: yes
+;clear_env = no
+
+; Limits the extensions of the main script FPM will allow to parse. This can
+; prevent configuration mistakes on the web server side. You should only limit
+; FPM to .php extensions to prevent malicious users to use other extensions to
+; execute php code.
+; Note: set an empty value to allow all extensions.
+; Default Value: .php
+;security.limit_extensions = .php .php3 .php4 .php5 .php7
+
+; Pass environment variables like LD_LIBRARY_PATH. All $VARIABLEs are taken from
+; the current environment.
+; Default Value: clean env
+;env[HOSTNAME] = $HOSTNAME
+;env[PATH] = /usr/local/bin:/usr/bin:/bin
+;env[TMP] = /tmp
+;env[TMPDIR] = /tmp
+;env[TEMP] = /tmp
+
+; Additional php.ini defines, specific to this pool of workers. These settings
+; overwrite the values previously defined in the php.ini. The directives are the
+; same as the PHP SAPI:
+; php_value/php_flag - you can set classic ini defines which can
+; be overwritten from PHP call 'ini_set'.
+; php_admin_value/php_admin_flag - these directives won't be overwritten by
+; PHP call 'ini_set'
+; For php_*flag, valid values are on, off, 1, 0, true, false, yes or no.
+
+; Defining 'extension' will load the corresponding shared extension from
+; extension_dir. Defining 'disable_functions' or 'disable_classes' will not
+; overwrite previously defined php.ini values, but will append the new value
+; instead.
+
+; Note: path INI options can be relative and will be expanded with the prefix
+; (pool, global or /var/cfengine/httpd/php)
+
+; Default Value: nothing is defined by default except the values in php.ini and
+; specified at startup with the -d argument
+;php_admin_value[sendmail_path] = /usr/sbin/sendmail -t -i -f www@my.domain.com
+;php_flag[display_errors] = off
+;php_admin_value[error_log] = /var/log/fpm-php.www.log
+;php_admin_flag[log_errors] = on
+;php_admin_value[memory_limit] = 32M
diff --git a/deps-packaging/release-monitoring.json b/deps-packaging/release-monitoring.json
index 29a79f3a7..e9191f6ee 100644
--- a/deps-packaging/release-monitoring.json
+++ b/deps-packaging/release-monitoring.json
@@ -14,6 +14,7 @@
"libxml2":"1783",
"libyaml":"13522",
"lmdb":"6974",
+ "nghttp2":"8651",
"openldap":"2551",
"openssl":"2566",
"pcre2":"5832",
diff --git a/packaging/cfengine-nova-hub/cfengine-nova-hub.spec.in b/packaging/cfengine-nova-hub/cfengine-nova-hub.spec.in
index 137cbae82..999ef614c 100644
--- a/packaging/cfengine-nova-hub/cfengine-nova-hub.spec.in
+++ b/packaging/cfengine-nova-hub/cfengine-nova-hub.spec.in
@@ -338,6 +338,7 @@ exit 0
# Systemd units
%defattr(644,root,root,755)
/usr/lib/systemd/system/cfengine3.service
+/usr/lib/systemd/system/cf-php-fpm.service
/usr/lib/systemd/system/cf-apache.service
/usr/lib/systemd/system/cf-execd.service
/usr/lib/systemd/system/cf-hub.service
@@ -411,10 +412,12 @@ exit 0
%prefix/httpd/modules
%prefix/httpd/php/lib
%prefix/httpd/php/php
+%prefix/httpd/php/etc
%config(noreplace) %prefix/httpd/php/lib/php.ini
%defattr(755,root,root,755)
%prefix/httpd/php/bin
+%prefix/httpd/php/sbin
# Software upgrade delivery area
%dir %prefix/master_software_updates
diff --git a/packaging/cfengine-nova-hub/debian/cfengine-nova-hub.install b/packaging/cfengine-nova-hub/debian/cfengine-nova-hub.install
index 88944de45..680b140a5 100644
--- a/packaging/cfengine-nova-hub/debian/cfengine-nova-hub.install
+++ b/packaging/cfengine-nova-hub/debian/cfengine-nova-hub.install
@@ -2,6 +2,7 @@
/etc/default
/etc/profile.d
/usr/lib/systemd/system/cfengine3.service
+/usr/lib/systemd/system/cf-php-fpm.service
/usr/lib/systemd/system/cf-apache.service
/usr/lib/systemd/system/cf-execd.service
/usr/lib/systemd/system/cf-hub.service
diff --git a/packaging/cfengine-nova/cfengine-nova.spec.in b/packaging/cfengine-nova/cfengine-nova.spec.in
index c4761a833..f0240892f 100644
--- a/packaging/cfengine-nova/cfengine-nova.spec.in
+++ b/packaging/cfengine-nova/cfengine-nova.spec.in
@@ -163,6 +163,7 @@ exit 0
# Systemd units
%defattr(644,root,root,755)
/usr/lib/systemd/system/cfengine3.service
+/usr/lib/systemd/system/cf-php-fpm.service
/usr/lib/systemd/system/cf-apache.service
/usr/lib/systemd/system/cf-execd.service
/usr/lib/systemd/system/cf-hub.service
diff --git a/packaging/common/cfengine-hub/postinstall.sh b/packaging/common/cfengine-hub/postinstall.sh
index f90fe108b..d49d403a5 100644
--- a/packaging/common/cfengine-hub/postinstall.sh
+++ b/packaging/common/cfengine-hub/postinstall.sh
@@ -87,7 +87,7 @@ fi
#Copy necessary Files and permissions
#
cp "$PREFIX/lib/php"/*.ini "$PREFIX/httpd/php/lib"
-EXTENSIONS_DIR="$(ls -d -1 "$PREFIX/httpd/php/lib/php/extensions/no-debug-non-zts-"*|tail -1)"
+EXTENSIONS_DIR="$(ls -d -1 "$PREFIX/httpd/php/lib/php/extensions/no-debug-zts-"*|tail -1)"
cp "$PREFIX/lib/php"/*.so "$EXTENSIONS_DIR"
#
@@ -994,8 +994,11 @@ chmod -R ug=rX,o= $PREFIX/httpd/htdocs/vendor # 440 for files, 550 for dirs
chmod -R ug=rX,o= $PREFIX/httpd/htdocs/public/scripts/node_modules
##
-# Start Apache server
+# Start Apache server (and php-fpm if present)
#
+if [ -f $PREFIX/httpd/php/sbin/php-fpm ]; then
+ $PREFIX/httpd/php/sbin/php-fpm
+fi
$PREFIX/httpd/bin/apachectl start
#Mission portal
@@ -1037,6 +1040,10 @@ su $MP_APACHE_USER -c "$PREFIX/httpd/php/bin/php $PREFIX/httpd/htdocs/public/ind
# Shut down Apache and Postgres again, because we may need them to start through
# systemd later.
+FPM_PID_FILE=$PREFIX/httpd/php-fpm.pid
+if [ -f "$PHP_FPM_PID_FILE" ]; then
+ kill -9 $(cat "$PHP_FPM_PID_FILE")
+fi
$PREFIX/httpd/bin/apachectl stop
# The above sometimes fails to stop the httpd processes properly. Let's make