PHP-FPM, A Pool On A Socket That Cannot Shell Out

php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.

ansibleWeb & App Servers

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-php-fpm/badge)](https://www.iac-bazaar.com/catalog/ansible-php-fpm?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [PHP-FPM, A Pool On A Socket That Cannot Shell Out](https://www.iac-bazaar.com/catalog/ansible-php-fpm?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# PHP-FPM, A Pool On A Socket That Cannot Shell Out: https://www.iac-bazaar.com/catalog/ansible-php-fpm (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

php-fpm

A PHP pool a web server can reach and nothing else can. The role writes one pool listening on a unix socket, with open_basedir closed around the application's own tree and the process-spawning functions removed. The live test runs PHP through the socket with a FastCGI client, so the pool is proven on its own, with no web server in the path.

No download, and no version to pin. EL 10 packages php-fpm, so the role installs it by name and takes the PHP the distribution ships - which is also what gets the security updates. What the role owns is the pool: who it runs as, what it may reach, and how much of the host it may use.

The pool file is checked before it lands. php-fpm has no way to test a single pool file - php-fpm -t tests the main configuration and everything it includes

  • so the role installs a small checker that wraps the candidate in a throwaway main configuration and tests that. A pool that would not parse never reaches /etc/php-fpm.d, and the running pool keeps serving.

The pool's error log is written by a worker, not by the master. Leave /var/log/php-fpm root-owned - which is how the package ships it - and the pool starts, serves, and records not one PHP error, because the master opens its own log as root while php_admin_value[error_log] is opened by a worker running as the pool's user. The role owns that directory as the pool's user, and the live test reads a blocked call out of the log rather than assuming it was written.

A pool on a unix socket opens no TCP listener at all, and the live test asserts exactly that: ss -ltnp must not mention php-fpm anywhere. A pool on 127.0.0.1:9000 is reachable by every local user; a socket at 0660 is reachable by one group.

Both restrictions are proven, in both directions. A script reading /etc/shadow is refused while a file inside the tree opens, and a script calling shell_exec stops at the call - the response is a 500, the text after the call never runs, and the pool's own error log names the function. Checking only that PHP executes would pass a pool with neither restriction in place.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules