FreeUnit

DokuWiki§

To run the DokuWiki content management system using Unit:

  1. Install Unit with a PHP language module.

  2. Install and configure DokuWiki’s prerequisites.

  3. Install DokuWiki’s core files. Here, we install it at /path/to/app/; use a real path in your configuration.

    $ mkdir -p /path/to/app/ && cd /path/to/app/
    
    $ wget https://download.dokuwiki.org/src/dokuwiki/dokuwiki-stable.tgz
    
    $ tar xvzf dokuwiki-stable.tgz --strip-components=1
    
    $ rm dokuwiki-stable.tgz
    
  4. Run the following command (as root) so Unit can access the application directory:

    # chown -R unit:unit /path/to/app/
    

    Note

    The unit:unit user-group pair is available only with official packages, Docker images, and some third-party repos. Otherwise, account names may differ; run the ps aux | grep unitd command to be sure.

    For further details, including permissions, see the security checklist.

  5. Next, prepare the app configuration for Unit (use real values for share and root):

    Warning

    The share action in the configuration below serves any file that no earlier step sends elsewhere. It serves a PHP file as source; it never runs it. The uri patterns are globs and match case-sensitively, so *.php does not match /config.PHP. On a case-insensitive filesystem (macOS, Windows, or a Docker Desktop bind mount from either) that file exists, and the share returns it with the passwords in it. A file the patterns never name, such as config.php.bak or settings.inc, is served the same way.

    Add a types allow-list to the share action. Keep the fallback where the configuration has one:

    "types": ["image/*", "text/css", "application/javascript", "font/*"]
    

    Unit compares this list with the MIME type it looks up from the file’s extension. The lookup is case-insensitive, so /config.PHP still resolves to application/x-httpd-php and is refused. An extension Unit does not know, such as .phtml or .inc, has an empty type, and the allow-list refuses that too. A refused request takes the share’s fallback when there is one, and gets a 403 response when there is not. Do not write the list as a refuse-list such as [“!application/x-httpd-php”]: a negated pattern does not exclude an empty type. See MIME filtering for the pattern syntax and the MIME type table for the limits of types, including the index file case.

    The list above is a starting point. Add the types your site serves -- text/html, application/json, text/plain, the XML types, application/pdf, video/* -- or those files are not served.

    {
        "listeners": {
            "*:80": {
                "pass": "routes"
            }
    
        },
    
        "routes": [
            {
                "match": {
                    "uri": [
                        "/data/*",
                        "/conf/*",
                        "/bin/*",
                        "/inc/*",
                        "/vendor/*"
                    ]
                },
    
                "action": {
                    "return": 404
                }
            },
            {
                "match": {
                    "uri": [
                        "/",
                        "*.php"
                    ]
                },
    
                "action": {
                    "pass": "applications/dokuwiki"
                }
            },
            {
                "action": {
                    "share": "/path/to/app$uri"
                }
            }
        ],
    
        "applications": {
            "dokuwiki": {
                "type": "php",
                "root": "/path/to/app/",
                "index": "doku.php"
            }
        }
    }
    
  6. Upload the updated configuration. Assuming the JSON above was added to config.json. Run the following command as root:

    # curl -X PUT --data-binary @config.json --unix-socket \
           /path/to/control.unit.sock http://localhost/config/
    

    Note

    The control socket path may vary; run unitd -h or see Startup and Shutdown for details.

    After a successful update, your app should be available on the listener’s IP address and port.

  7. Browse to /install.php to complete your installation:

    DokuWiki on Unit - Installation Screen