DevOps & Cloud · Cheatsheet
Apache HTTP Server Cheatsheet
Virtual hosts, modules, SSL, .htaccess, reverse proxy, and performance tuning
64 commands 9 sections
No entry matches that filter.
-
sudo systemctl start apache2Start Apache service -
sudo systemctl stop apache2Stop Apache service -
sudo systemctl restart apache2Restart Apache (drops connections) -
sudo systemctl reload apache2Graceful reload (no downtime) -
sudo systemctl enable apache2Enable Apache on boot -
sudo systemctl status apache2Check Apache service status -
apachectl configtestTest configuration syntax -
apachectl -VShow version and build parameters -
apachectl -t -D DUMP_MODULESList all loaded modules -
apachectl -SShow parsed virtual host settings
-
<VirtualHost *:80>Define a virtual host on port 80 -
ServerName example.comSet primary domain for vhost -
ServerAlias www.example.comAdd alternate domain name -
DocumentRoot /var/www/htmlSet root directory for content -
ErrorLog ${APACHE_LOG_DIR}/error.logSet error log path -
CustomLog ${APACHE_LOG_DIR}/access.log combinedSet access log with format -
sudo a2ensite example.confEnable a virtual host config -
sudo a2dissite example.confDisable a virtual host config
-
sudo a2enmod rewriteEnable mod_rewrite for URL rewriting -
sudo a2dismod autoindexDisable directory listing module -
sudo a2enmod sslEnable SSL/TLS module -
sudo a2enmod headersEnable HTTP headers module -
sudo a2enmod proxyEnable reverse proxy module -
sudo a2enmod proxy_httpEnable HTTP proxy support -
sudo a2enmod expiresEnable cache expiry headers -
sudo a2enmod deflateEnable gzip compression -
apache2ctl -MList all enabled modules
-
sudo a2enmod sslEnable SSL module -
SSLEngine onEnable SSL for a virtual host -
SSLCertificateFile /path/cert.pemSet SSL certificate path -
SSLCertificateKeyFile /path/key.pemSet SSL private key path -
SSLCertificateChainFile /path/chain.pemSet certificate chain file -
sudo certbot --apache -d example.comInstall Let's Encrypt cert -
Header always set Strict-Transport-Security "max-age=31536000"Enable HSTS header
-
RewriteEngine OnEnable URL rewriting in .htaccess -
RewriteCond %{HTTPS} offCondition: if not HTTPS -
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]Redirect HTTP to HTTPS -
RewriteRule ^old-page$ /new-page [R=301,L]Permanent redirect (301) -
RewriteRule ^api/(.*)$ index.php?route=$1 [QSA,L]Route API requests to index.php -
Options -IndexesDisable directory listing -
AllowOverride AllAllow .htaccess to override config -
ErrorDocument 404 /404.htmlCustom 404 error page
-
ProxyPass / http://localhost:3000/Forward all requests to backend -
ProxyPassReverse / http://localhost:3000/Adjust response headers for proxy -
ProxyPreserveHost OnPass original Host header to backend -
ProxyPass /ws ws://localhost:3000/wsProxy WebSocket connections -
<Proxy balancer://mycluster>Define a load balancer cluster -
BalancerMember http://server1:8080Add backend server to balancer
-
Require all deniedDeny access to directory (2.4+) -
Require ip 192.168.1.0/24Allow access from IP range -
Require all grantedAllow access to all -
ServerTokens ProdHide Apache version in headers -
ServerSignature OffRemove server info from error pages -
Header set X-Content-Type-Options "nosniff"Prevent MIME type sniffing -
Header set X-Frame-Options "SAMEORIGIN"Prevent clickjacking
-
LogLevel warnSet log verbosity (emerg to trace8) -
tail -f /var/log/apache2/error.logStream error log in real-time -
ExpiresActive OnEnable cache expiry headers -
ExpiresByType image/png "access plus 1 month"Cache images for 1 month -
AddOutputFilterByType DEFLATE text/html text/cssEnable gzip for HTML/CSS -
KeepAlive OnEnable persistent connections -
MaxKeepAliveRequests 100Max requests per connection -
KeepAliveTimeout 5Timeout for keep-alive (seconds)
-
https://httpd.apache.org/docs/2.4/Apache HTTP Server 2.4 manual: directive contexts, modules, TLS, and proxy configuration.