PHP-FPM, A Pool On A Socket That Cannot Shell Out
php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-php-fpm?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [PHP-FPM, A Pool On A Socket That Cannot Shell Out](https://www.iac-bazaar.com/catalog/ansible-php-fpm?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# PHP-FPM, A Pool On A Socket That Cannot Shell Out: https://www.iac-bazaar.com/catalog/ansible-php-fpm (download from your IaC Bazaar account)
```Preview:
Documentation
php-fpm
A PHP pool a web server can reach and nothing else can. The role writes one
pool listening on a unix socket, with open_basedir closed around the
application's own tree and the process-spawning functions removed. The live test
runs PHP through the socket with a FastCGI client, so the pool is proven on its
own, with no web server in the path.
No download, and no version to pin. EL 10 packages php-fpm, so the role installs it by name and takes the PHP the distribution ships - which is also what gets the security updates. What the role owns is the pool: who it runs as, what it may reach, and how much of the host it may use.
The pool file is checked before it lands. php-fpm has no way to test a single
pool file - php-fpm -t tests the main configuration and everything it includes
- so the role installs a small checker that wraps the candidate in a throwaway
main configuration and tests that. A pool that would not parse never reaches
/etc/php-fpm.d, and the running pool keeps serving.
The pool's error log is written by a worker, not by the master. Leave
/var/log/php-fpm root-owned - which is how the package ships it - and the pool
starts, serves, and records not one PHP error, because the master opens its own
log as root while php_admin_value[error_log] is opened by a worker running as
the pool's user. The role owns that directory as the pool's user, and the live
test reads a blocked call out of the log rather than assuming it was written.
A pool on a unix socket opens no TCP listener at all, and the live test
asserts exactly that: ss -ltnp must not mention php-fpm anywhere. A pool on
127.0.0.1:9000 is reachable by every local user; a socket at 0660 is reachable
by one group.
Both restrictions are proven, in both directions. A script reading
/etc/shadow is refused while a file inside the tree opens, and a script calling
shell_exec stops at the call - the response is a 500, the text after the call
never runs, and the pool's own error log names the function. Checking only that
PHP executes would pass a pool with neither restriction in place.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-httpd-tls
httpd with mod_ssl from AppStream on EL 10: one TLS site, an explicit protocol floor and cipher list, HSTS, and the plain port doing nothing but redirecting. The live test reads the site with the certificate the role installed, checks the headers, and is refused when it asks for a cipher outside the list. Original role, live-tested on Rocky Linux 10.
ansible-caddy-https
Caddy with HTTPS on: the package serves plain HTTP with a Server header and an admin API any local process can use. This role gives private names a certificate from Caddy's own CA (public ones get Let's Encrypt), redirects HTTP, sends HSTS and the security headers, drops Server, turns the admin API off, and serves files or proxies an upstream. Original role, live-tested on Rocky Linux 10.
ansible-nginx
Verified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.