Blog

  • RunCloud 2024 Year in Review

    RunCloud 2024 Year in Review

    Welcome to RunCloud’s 2024 year in review.

    First of all, Happy New Year – here’s to 2025! ♥️

    I hope all of you have had an incredible winter break (or Christmas 🎄 break if you celebrate) – and a wonderful New Year’s Eve with family and friends.

    As we wrap up the first month of 2025, we want to take a moment to reflect on the past year, and to look ahead to what we’re focusing on for the coming year.

    Here’s a quick summary in case you’re here for the first time:

    RunCloud is a server management platform that makes it easy to run production-grade infrastructure. Trusted from startups to enterprises – from your favorite indie hackers and WordPress agencies through to world-class hosting companies.

    This year, we delivered:

    💳 Over 13,254 new server deployments

    🕵️ 54 product updates shipped

    📈 10,740 Web app (Git & Atomic) deployments

    So, without further ado, let’s look back on what a year 2024 was…

    Overhauling Our Documentation

    We gave our product documentation a facelift, to say the least. And we didn’t stop there! While we were at it, we also re-reviewed every article in our documentation, leading to partial/complete rewrites of almost every single article.

    This sets a new standard for our product documentation going forward, and demonstrates our ongoing commitment to making RunCloud as easy as possible to use – outside of continuing to build a product that just “feels right” and “makes sense”.

    Overhauling Our Blog

    In conjunction with the huge overhaul of our product documentation, we brought our blog into line with the new design, keeping things such as the navigation consistent, and building on top of the same design system.

    The final part of the RunCloud marketing site that remains to be consolidated into a newer, overhauled design style that’s indicative of where we’re at is our homepage and other pages at the root (i.e., pricing, about, etc.).

    This is something we’re excited to take on this year, so stay tuned!

    Shipping V3 of the RunCloud API

    This year, RunCloud as a product took a massive leap forward for developers. With the introduction of V3 of the RunCloud API, it’s never been a better time to build with RunCloud.

    Companies such as ZipWP, InstaWP, and many others have already been taking advantage of our API to make it much easier to build their platforms powered by RunCloud under the hood.

    Learn more in our API documentation here.

    Note: For those interested, we’re using Apidog to power our API documentation. This is separate from our primary product documentation – which is a headless WordPress site.

    Improving Pricing to Align With Our Direction

    With the release of your all-new RunCloud Workspace and version 3 of our API, we updated our pricing plans in line with the direction of RunCloud as a product and company.

    This change was initially viewed as controversial, but as the initial reactions faded, we were pleased to re-align with our core audience, who saw why this was a necessary change and, like us, couldn’t be more excited to continue using RunCloud as part of their stack.

    RunCloud Turns 7

    Towards the end of the year (September), RunCloud turned 7!

    Even after 7 years, it feels like we’re just getting started. Most startups don’t make it past 1 year, let alone 3, 5, and now 7. We’re deeply grateful to survive – and thrive, serving thousands of customers in over 100 countries.

    Here are some of the values that have carried us through the past 7 years:

    1. Customer-first always. Despite tough competition, we prioritized solving our customers’ immediate needs.
    2. Brand matters. From day one, we invested in building trust and a strong brand – a rare focus in today’s impatient startup world.
    3. Customer satisfaction. We can’t please everyone, but with a 99% CSAT score, we keep learning from the 1% who challenge us.
    4. Flywheel over funnels. We focus equally on existing customers and acquiring new ones, ensuring long-term growth.
    5. Simplicity wins. We respect competitors but focus on crafting a simple, straightforward product that meets real needs.
    6. Value-driven growth. Instead of chasing hype, we channel our energy into improving the product and scaling thoughtfully.

    Our biggest lesson is to compete with yourself.

    Focus on your customers, build a better product, and stay ethical. The world moves fast, but we can choose to stay grounded and build something meaningful, one step at a time.

    We know we have a long way to go, and we are just as ambitious about RunCloud as a product as many of the people in our community who continue to get involved and help shape the direction of the product with their feedback and constructive discussions.

    Here’s to a great year ahead. 🫡

    Meanwhile, you’ll find a highlight reel below of some of our bigger updates from throughout the year. For a full list of everything that’s new, please refer to our changelog.

    And Some More Big Product Updates From This Year

    Introducing The RunCloud Workspace

    Meet your all-new RunCloud Workspace. Bring your team into RunCloud with fine-grained control over what resources invited team members can see and what specific actions they can perform in your workspace.

    Note: To create a workspace, you’ll need to be on a RunCloud Business or Enterprise plan.

    Here are some guides to help you get up and running with your new workspace:

    Introducing Support for ARM Servers on RunCloud

    RunCloud now supports ARM servers – an alternative server architecture offering a more efficient solution with lower power consumption and reduced heat output – ideal for cost-effective, scalable data centers.

    Supported Configurations

    • Native NGINX server
    • Native OLS server
    • Containerized NGINX server

    Note: Containerized OLS servers are not supported with ARM

    The server providers that support direct deployments from your RunCloud dashboard that offer ARM server offerings are Hetzner, AWS EC2, Google Cloud Platform, and Azure.

    Introducing Server Storage & Web Application Monitoring

    We’re excited to announce that Storage Monitoring has landed!

    Today’s release includes a series of updates we know many of you have been waiting for. With RunCloud Monitoring, it’s never been easier to monitor the storage breakdown of your servers – based on web apps, databases, log files, and more.

    Learn more about Storage Monitoring on RunCloud here.

    And that’s not all! RunCloud Monitoring now also offers web application monitoring, including Slow Script Monitoring, IP Address Hit Monitoring, and Top Path Monitoring:

    Automatic Configuration of Access Control Lists for Redis

    We’re excited to introduce a new security feature that automatically safeguards your Redis instances using Access Control Lists (ACLs). With this update, RunCloud ensures that your Redis deployments are securely configured by default, providing an additional layer of protection for your data.

    This is particularly important if you host multiple web applications on a single server.

    Newly-deployed servers and web applications are secured by default.

    Note: The minimum agent version is 2.8.9+8.

    Learn more and refer to this guide on how to secure existing web applications.

    A big thank you goes out to the security researcher – Vladimir Smitka – who performed a series of tests and originally reported this proposed improvement to how Redis works by default on RunCloud.

    The setup process may vary slightly due to the individual/custom configurations of existing web apps. Please feel free to get in touch if you run into any issues.

    Working with Paddle as a Merchant of Record

    You can now pay for your RunCloud subscription using credit/debit cards, PayPal, and Google Pay.

    This has been made possible by partnering with Paddle (the complete payments, tax, and subscription solution for SaaS) to process payments and act as our Merchant of Record, allowing us to deliver the best subscription and payment experience for our users worldwide.

  • How to Fix WordPress Revisions Not Showing [SOLVED]

    How to Fix WordPress Revisions Not Showing [SOLVED]

    Are your WordPress post revisions not showing? Has your WordPress revisions option suddenly become invisible, or disabled? We’ve got you covered!

    In this article, we’ll explain exactly what the problems are likely to be, and how to get your WordPress revisions showing and working correctly.

    WordPress is a dynamic CMS that allows website owners and content creators to easily edit and update existing content. However, the editing process isn’t always straightforward, and mistakes or unintended changes can happen.

    To overcome this, WordPress provides a WordPress post revisions feature that can automatically create snapshots of your content every time you save a draft or update a published post. This built-in system allows website administrators and content creators to:

    • Track changes made to content over time
    • Restore previous versions of a post
    • Recover accidentally deleted content
    • Collaborate more effectively by maintaining a comprehensive editing history

    Each revision captures the entire state of a post at a specific moment, including text, formatting, and metadata. WordPress automatically creates a new revision every time you save a draft or update a published post.

    This feature provides peace of mind for content creators, bloggers, and website administrators by ensuring that no valuable work is permanently lost due to accidental deletions or unwanted edits.

    Whether you’re managing a personal blog, a corporate website, or a complex multi-author platform, revisions offer a transparent, reliable mechanism to manage content development.

    In this guide, we’ll discuss the challenges surrounding WordPress revisions and focus on why this feature might suddenly become invisible.

    Our goal is to equip you with practical, step-by-step solutions to diagnose and resolve issues preventing your content’s version history from displaying correctly. We’ll explore the most common reasons behind missing revisions and provide clear steps to restore this functionality.

    Why WordPress Revisions Are Not Showing

    WordPress revisions are a powerful feature designed to track content changes, but various technical and configuration issues can interrupt their functionality. Let’s see a few reasons why WordPress revisions don’t work:

    1. Revision Limit Settings: WordPress has a default limit on the number of revisions stored. If this limit is set too low or disabled, fewer revisions might appear (or none at all).
    2. Plugin Interference: Some plugins that modify post-editing or database interactions can disrupt the revision tracking mechanism.
    3. Theme Compatibility Issues: Custom themes might inadvertently modify WordPress core functions related to post revisions.
    4. Database Configuration: Incorrect database settings or optimization plugins can suppress revision storage.
    5. User Role Permissions: Certain user roles might have restricted access to viewing post revisions.
    Viewing revisions in WordPress dashboard

    Suggested read: The Complete WordPress Speed Optimization Guide

    Ways to Re-Enable WordPress Revisions

    You can take steps to troubleshoot WordPress revision settings in your WordPress website.

    Enabling Post Revisions from wp-config

    The WordPress revisions setting in your WordPress website may be disabled. You can easily enable post revisions by editing your server’s ‘WP_POST_REVISIONS’ environment variable. To do this, you can add the following code to your wp-config.php file:

    define('WP_POST_REVISIONS', 10); // Limits revisions to 10
    // Or for unlimited revisions
    define('WP_POST_REVISIONS', true);
    enabling WordPress revisions in wp-config.php file

    This method allows fine-tuned control over revision tracking directly in your WordPress configuration file. Place the code before the line that says, “That’s all, stop editing!” and save it. Once you save the file, new revisions will be saved in your WordPress website whenever you create an edit.

    Suggested read: The Complete WordPress Speed Optimization Guide

    Enabling Revisions for Custom Post Types

    Custom post types in WordPress require specific configurations to enable revision tracking. This process ensures your custom content types maintain the same version control capabilities as standard WordPress posts.

    Method 1: Registering Custom Post Type with Revisions

    When creating a custom post type, add ‘revisions’ to the ‘supports’ parameter during registration:

    register_post_type('your_cpt_name', array(
        'supports' => array('title', 'editor', 'revisions'),
        'public' => true,
        'label' => 'Custom Post Type Name'
    ));

    Suggested read: How to Migrate WordPress From Shared Hosting To Cloud Server

    Method 2: Advanced Custom Fields (ACF) Integration

    Custom post types in WordPress often require specific configurations to enable revision tracking. When working with plugins like Custom Post Type UI or Advanced Custom Fields (ACF), you must explicitly add revision support during post-type registration. Use the following code snippet to enable post revisions:

    add_filter('acf/settings/save_json', 'my_acf_json_save_point');
    function my_acf_json_save_point($path) {
        return get_stylesheet_directory() . '/acf-json';
    }

    By configuring these settings, you can enable revisions in custom post types, allowing you to maintain the same revision tracking capabilities as standard WordPress posts.

    Suggested read: Protect Your WordPress Login pages with Cloudflare Zero Trust

    Limiting Post Revisions for Better Performance

    WordPress revisions consume database storage over time, potentially impacting site performance. If you run a big site with lots of revisions, your database can become bloated and sluggish. Website owners can maintain optimal database efficiency by implementing strategic revision limits while preserving critical content version history.

    Proactively managing post revisions helps maintain website speed, reduces storage requirements, and ensures a streamlined content management experience. Website administrators should periodically review and optimize revision settings to balance content tracking needs with system performance.

    Suggested read: The Best WordPress Caching Plugins To Speed Up Your Site (2024)

    Why Disabling Revisions is No Longer Recommended

    Modern web infrastructure has dramatically changed the perspective on disabling WordPress post revisions for performance optimization. What was once considered a best practice is now considered an unnecessary compromise.

    Advanced hosting technologies and caching mechanisms have effectively neutralized previous performance concerns. Website administrators now recognize that version tracking provides more value than marginal resource savings.

    Network-level CDNs and application-level caching solutions such as Redis and Memcached dramatically reduce database query loads. Additionally, modern database systems implement sophisticated query caching mechanisms that minimize performance overhead.

    WordPress revisions consume negligible database storage compared to total website resources. Modern hosting environments handle database overhead with remarkable efficiency and scalability. Furthermore, disk storage costs have dramatically decreased, making content preservation more economical than potential data loss. The minimal computational resources required for revision tracking are inconsequential compared to other website operations.

    Suggested read: The 5 Best WordPress Security Plugins (2024)

    Wrapping Up WordPress Revisions Management

    In this post, we’ve discussed steps for managing WordPress revisions, covering everything from troubleshooting missing versions to why revision tracking is considered useful despite minimal performance impact. You can maintain robust content version control while ensuring website efficiency by understanding revision tracking, configuration methods, and best practices.

    If you are a WordPress website owner seeking streamlined deployment and management, you should use RunCloud to manage your websites.

    RunCloud eliminates complex server management challenges, providing:

    • One-click WordPress deployments
    • Advanced caching configurations
    • Security hardening
    • Seamless migration tools

    Optimize your WordPress website’s performance and management – get started with RunCloud.

    For further WordPress optimization insights, explore RunCloud’s comprehensive guides:

    FAQs on WordPress Post Revisions

    How do I delete old revisions in WordPress?

    You can use a database optimization plugin like WP-Optimize or manually delete revisions through phpMyAdmin by running an SQL query to remove older entries from the wp_posts table.

    How many revisions does WordPress keep?

    WordPress keeps unlimited post revisions by default, but you can limit this to a specific number (like 10) by adding a code snippet to your wp-config.php file.

    How do I reduce revisions in WordPress?

    Add a simple code snippet to wp-config.php that limits the number of revisions, such as define('WP_POST_REVISIONS', 5); to keep only the most recent five revisions.

    How do I see all revisions in WordPress?

    Open the post editor and click on the “Revisions” button at the top right corner. This button displays a side-by-side comparison of different versions of your post.

    How do I optimize and clean all post revisions in WordPress?

    Use database optimization plugins like WP-Optimize or Advanced Database Cleaner to remove unnecessary post revisions and improve overall database performance.

    How do I turn off autosave and revisions in WordPress?

    You can disable autosave by adding disableautosave:true in your theme’s functions.php file and limit revisions to 0 by adding define('WP_POST_REVISIONS', false); in wp-config.php.

  • 10 Best WordPress Management Tools To Easily Manage Multiple Websites

    10 Best WordPress Management Tools To Easily Manage Multiple Websites

    Ever wondered how to make managing multiple WordPress websites easy – whether that involves a handful of sites or many hundreds? You’ve come to the right place.

    The answer is simple, and two-fold:

    1. Use a solution such as RunCloud, which makes it extremely easy to deploy and manage your production-grade cloud infrastructure across cloud providers of your choice, all from a single, centralized dashboard. 
    2. Pair your industry-leading hosting setup with a WordPress management tool.

    In this post, we’ll focus on #2. After all, if you’re reading this post on the RunCloud blog, you already know why RunCloud is the leading way to build your cloud infrastructure.

    Why Should You Use WordPress Management Tools?

    Although managing WordPress websites is becoming significantly easier with the introduction of automatic updates as a part of WordPress core, if you manage multiple websites (even just a couple), the benefits of using a proper WordPress management solution will become clear as you begin to adopt it as a part of your workflow.

    Consider a typical scenario: a web development agency managing 20 client websites, each requiring weekly updates, security checks, and regular backups. Without a management tool, this could consume up to 20 hours per week of manual work – logging in to each site individually, checking for updates, running backups, and monitoring security.

    A WordPress management tool can accomplish these same tasks in under an hour by automating processes and allowing you to perform actions in bulk on multiple sites.

    This dramatic time saving directly translates to improved profitability and the ability to scale operations without being forced to proportionally increase your company headcount.

    And this is just the beginning.

    The benefits of WordPress management tools extend far beyond simple time savings.

    Take, for example, the critical aspect of security monitoring. When a major vulnerability is discovered in a popular plugin, time is of the essence. A management tool can identify all affected sites instantly and apply updates across the entire portfolio within minutes – a process that could take hours or even days if done manually.

    In short: the ROI of WordPress management tools cannot be understated. By combining automation, a better workflow, security, and everything else a good WordPress management solution offers, you can streamline your operation to maintain the sites under your management with less time and fewer people on your team.

    WordPress Multisite vs WordPress Management Tools

    You might wonder why you should use a WordPress management service when WordPress already has built-in multisite network functionality. It’s easy to confuse them since WordPress does allow you to manage multiple sites, but there is one key distinction.

    The multisite network only allows you to manage sub-sites of a single WordPress installation. This means that you can’t use it to manage the websites of different clients, as all the websites in a multisite network belong to a single organization. On the other hand, a WordPress management tool has no such restrictions and can be used with any WordPress site.

    What Are The Best WordPress Management Tools?

    Let’s take a look at some of the best WordPress management tools.

    1. MainWP

    MainWP WordPress management tool

    MainWP is a self-hosted WordPress management solution that allows administrators to handle multiple WordPress sites. It offers a centralized dashboard where users can efficiently manage unlimited WordPress installations, making it invaluable for agencies, developers, and site managers.

    It also has a comprehensive update management system that allows users to update WordPress cores, themes, and plugins across all sites with a single click. What sets MainWP apart is its robust security features, including automated security checks, abandoned update notifications, and proactive monitoring – all while maintaining complete data ownership since it’s self-hosted.

    The pricing structure is particularly attractive. It offers a feature-rich free version and a Pro version starting at $199 yearly or a one-time payment of $599 for lifetime access, making it a cost-effective solution regardless of how many sites you manage.

    While the initial setup and configuration process may require some time investment, the long-term benefits in efficiency and control are substantial. Users can benefit from features such as scheduled automated updates, security scanning, uptime monitoring, and client report generation. It also includes valuable capabilities such as staging site creation, content cloning between sites, and maintenance mode management.

    2. InfiniteWP

    InfiniteWP WordPress management tool

    InfiniteWP is a powerful WordPress management solution that efficiently changes how administrators handle multiple WordPress sites. It offers a robust free version with essential features such as 1-click admin access, updates, and backup/restore capabilities.

    It provides multiple subscription options, ranging from the Starter plan ($147/year for ten sites) to the Enterprise level ($647/year for unlimited sites). It includes essential tools such as malware scanning, uptime monitoring, Google Analytics integration, and client reporting capabilities, which makes it particularly valuable for freelancers and agencies.

    Users can perform bulk actions such as managing users, handling WordPress maintenance, monitoring WordFence security, and simultaneously publishing content across multiple sites.

    It also offers some site monitoring features such as plugin branding, broken link checking, Google PageSpeed monitoring, and integration with various security tools, including iThemes Security and Duo Security 2-Factor Authentication.

    3. ManageWP

    ManageWP is a versatile WordPress management solution that offers tools for managing multiple WordPress websites from a single dashboard. Its free tier includes essential features such as plugin and theme update management, monthly cloud backup, one-click login functionality, and basic security and performance checks.

    What makes ManageWP particularly appealing is its flexible pricing structure, allowing users to start with unlimited websites at no cost and gradually add premium features as needed. ManageWP’s core functionality includes collaboration tools, analytics integration, comment management, code snippet implementation, maintenance mode controls, and vulnerability updates, making it suitable for freelancers, agencies, and WordPress professionals managing multiple sites.

    You can purchase premium add-ons to enhance its capabilities with specialized features priced on a per-website basis at $1-$2 monthly. These premium features include advanced backup solutions, white-label options for agencies, SEO ranking tools, uptime monitoring, automated security and performance checks, and link monitoring.

    ManageWP employs a transparent pricing model. Users only pay for the add-ons they actually use, with payments processed at the beginning of the following month. For larger agencies managing over 25 websites, bundle options provide fixed monthly fees for up to 100 websites.

    4. WP Umbrella

    WP Umbrella is a relatively new and affordable WordPress management solution that offers a comprehensive suite of features at a transparent price point of $1.99 per site per month. It provides essential tools for WordPress maintenance businesses without the complexity of tiered pricing or feature restrictions.

    You can use it to manage and maintain critical aspects of WordPress. For example, it includes a centralized dashboard for monitoring multiple sites, secure bulk updates for WordPress core, plugins, and themes, and robust security features, including vulnerability monitoring and automatic cloud backups.

    Like many other management tools, it offers uptime tracking, Google PageSpeed analysis, and PHP error detection. Its integration capabilities with services such as Slack and Google Analytics make it useful for professional users.

    WP Umbrella’s focus on automation and client management features makes it particularly effective for agencies and freelancers. It provides the functionality to produce maintenance reports, one-click access to all managed sites, and a complete white-label solution that allows agencies to maintain their branding.

    5. WP Remote

    WP Remote offers a WordPress management solution that can streamline the management process of multiple WordPress websites through a unified platform. It offers three distinct plans (Basic at $29, Plus at $49, and Pro at $99 – all monthly for up to five sites) that cater to different management needs.

    WP Remote excels in providing essential management tools, including daily automatic backups, single sign-on capabilities, uptime monitoring, performance checks, and automated updates across all managed sites. Additionally, it combines the functionality of multiple WordPress plugins, making it a one-stop solution. For example, it offers security features such as malware scanning and real-time firewall protection with practical maintenance tools, including visual regression testing and white-label reporting options.

    You can take advantage of its customizable add-on system, which allows users to tailor their management capabilities to specific needs. These add-ons include real-time backups ($10/site/month), more frequent backup and security scans (from $5/site/month for 12-hour intervals), and additional staging sites ($10/site/month).

    Larger agencies and advanced users can sign up for its custom enterprise subscription, which provides API access. Additionally, its comprehensive approach to website management is complemented by its focus on security and reliability, as it offers features like bot protection, vulnerability scans, and activity logs in higher-tier plans.

    6. Solid Central

    Solid Central (formerly iThemes Sync) is one of the most popular WordPress multi-site management solutions that can easily handle 100+ websites from a single, centralized dashboard. Rather than logging in to multiple WordPress installations individually, administrators can perform critical tasks across all their sites simultaneously, including bulk updates, plugin installations, and security monitoring.

    It offers reporting capabilities that help maintain transparency with clients by generating insights and updates about site performance, security status, and maintenance activities. It also offers essential features such as uptime monitoring, performance tracking, and detailed activity timelines that provide real-time visibility into site operations and potential issues.

    If you are part of the broader SolidWP ecosystem, you will appreciate the way Solid Central integrates with other powerful tools, such as Solid Security and Solid Backups, to provide a complete website management solution. This integration enables users to monitor security threats, manage backups, and restore sites remotely, all from the same interface.

    7. Glow

    Glow is a lesser-known WordPress management solution launched in 2020. It allows agencies and developers to efficiently manage 20-100+ WordPress websites and offers critical features such as plugin management, automated backups, and performance monitoring.

    Glow’s integrated support ticket system and time-tracking capabilities set it apart. These enable teams to manage client communications and track work hours directly within the same interface they use for website maintenance. Glow also offers a special two-way core update functionality that allows users to either manually update WordPress sites from their WordPress admin dashboard, or update them all at once.

    If you are working with a team, you will enjoy its collaboration and client reporting tools. Glow offers customizable and automated client reports that display time spent on activities, unlimited client team members, and the ability to run the dashboard under an agency’s own branding.

    Glow offers a flexible pricing structure, including pay-as-you-go options for additional websites, making it accessible to agencies of all sizes. This makes it a great tool for both hobbyists and professionals.

    8. iControlWP

    iControlWP is a powerful tool for managing multiple WordPress websites. It allows users to streamline various essential tasks, saving time and effort. It provides a centralized dashboard for complete visibility and control over all your WordPress sites, eliminating the need for individual logins.

    You can use it to manage plugins and theme updates across your network, ensuring consistent functionality and security. Additionally, you can proactively safeguard your sites with integrated vulnerability scanning and malware detection, and be assured your data is secure with automatic daily backups stored off-site.

    iControlWP goes beyond traditional multi-site management tools, offering advanced features such as:

    • Database Cleanup and Optimization: Maintain optimal website performance by cleaning up and optimizing databases across your network.
    • Mobile Push Notifications: Receive instant alerts on critical updates, security threats, and site performance issues directly to your mobile device.
    • Bulk Management: Perform actions across multiple sites simultaneously, such as updating plugins or resetting passwords, saving you valuable time.

    If you run an agency, you can generate professional reports for your clients showcasing website performance metrics and activity, and customize the platform with your branding for a seamless white-labeled client experience.

    9. WP Central

    WPCentral is a powerful tool designed to simplify the management of multiple WordPress websites. WPCentral provides a centralized dashboard where you can oversee all your sites from one location. This means that you don’t need to individually log in to each one of your WordPress websites to manage plugins and themes.

    You can easily use it to perform local and remote backups and even create pre-configured plugins and themes to apply to new sites. It offers a user-friendly interface and intuitive design, making maintaining consistent functionality and security across your WordPress portfolio much easier.

    WPCentral offers various pricing plans to suit different needs, from a free plan perfect for beginners to a corporate plan for businesses with a large number of sites. The free plan offers essential features, including plugin and theme management, local backups, remote backups, plugin sets, theme sets, and automated backups. Each paid plan offers increased website limits, making it ideal for agencies, freelancers, and businesses managing multiple websites.

    10. Modular DS

    Modular DS is a comprehensive WordPress management solution that streamlines the complex task of maintaining multiple WordPress websites. Its intuitive approach to automation and maintenance makes life easier for developers by combining essential features such as automated backups, bulk updates, and uptime monitoring into a single, user-friendly dashboard.

    This tool effectively transforms hours of repetitive maintenance tasks for agencies and WordPress professionals managing multiple sites into simple one-click operations.

    The bulk management capabilities are particularly handy when you simultaneously update plugins, themes, and WordPress core across multiple sites. What’s especially noteworthy is Modular DS’s holistic approach to website health monitoring, which actively scans for potential issues such as outdated PHP versions, deactivated plugins, and server configuration problems, enabling proactive maintenance rather than reactive problem-solving.

    Perhaps one of Modular DS’s most valuable aspects is its client reporting system. The platform automatically generates professional reports that showcase the maintenance work performed, including uptime statistics, Google Analytics integration, and Core Web Vitals performance metrics. This feature helps justify the value of maintenance services to clients and streamlines client communication through automated report delivery.

    After Action Report – Choosing The Best WordPress Management Software For Your Business

    In this article we have covered a number of excellent tools designed to let you manage multiple WordPress sites in a single place. These ten WordPress management tools are available for all user levels and needs.

    Many tools offer a free basic plan for managing your sites. Professional users can buy selected add-ons or subscribe to a paid plan for all advanced features.

    If you’re looking for a simple, hosted solution that’s easy to get up and running, we’d recommend looking into ManageWP and WP Umbrella. ManageWP has a generous free tier, and WP Umbrella, as a newer solution, has an incredibly motivated team that actively ships improvements to the product every month (the same, sadly, cannot be said about ManageWP).

    If you’d prefer self-hosted WordPress management tools, MainWP is the most affordable tool (nothing beats free). It offers additional features via extensions, supports many popular WordPress plugins, and has good community support.

    Which WordPress management tool are you using now, and how many sites do you manage? Let us know & join the conversation by Tweeting @RunCloud! 💬

    Now that we’ve narrowed down the list of WordPress management tools to consider for your business – we’d love to help you make the second component of managing WordPress websites the best it can possibly be for your business:

    Looking to build your own production-grade infrastructure? Try RunCloud.

    • Pick your cloud provider: Deploy directly to your AWS, GCP, Vultr, UpCloud, and Hetzner platform all directly from your RunCloud dashboard.
    • Easy Cloudflare DNS Integration: Manage your DNS records directly in your RunCloud dashboard and automatically connect domains when spinning up your new web applications.
    • One-Click Staging Environments: Spin up staging environments directly from your dashboard in just a few clicks.
    • Redis Object Caching: Easily enable Redis object caching for as many sites on your server as you’d like (secure by design using Redis ACLs, which have not been properly implemented by the majority of other hosting providers).

    Frequently Asked Questions About WordPress Multi-Site Management

    How do I keep track of plugin updates across all my WordPress sites?

    Managing updates across multiple WordPress sites can be time-consuming and overwhelming. Logging in to each site individually to check for updates is inefficient and risks missing critical security updates. WordPress management tools can easily update and manage multiple WordPress sites.

    What happens if one of my clients’ websites gets hacked or crashes?

    Without a proper backup system, a hacked or crashed website can mean hours or days of lost work and potential loss of business for your clients. Regular automated backups help in quick recovery and give peace of mind.

    How can I manage different client logins and passwords securely?

    Keeping track of multiple WordPress admin credentials for different sites can be a security risk, especially when written down or stored in unsecured documents. Many WordPress management tools have a centralized dashboard with secure single-sign-on capabilities, eliminating this risk.

    How do I prove to my clients that I’m actively maintaining their websites?

    Many WordPress professionals struggle to demonstrate the value of their maintenance work to clients. Automated reporting systems that track updates, security measures, and performance metrics can help justify your services.

    What if I need to install the same plugin across multiple websites?

    Manually installing and configuring the same plugins across multiple WordPress sites is repetitive and time-consuming. WordPress management tools offer bulk installation and configuration functionality, saving work hours and ensuring consistency.

    How can I manage WordPress core updates without breaking my clients’ sites?

    WordPress core updates can sometimes cause compatibility issues with themes and plugins. Modern WordPress Management tools allow testing updates and offer quick rollbacks, which helps maintain site stability.

    What’s the best way to monitor the performance of multiple WordPress sites?

    Tracking performance metrics such as page speed and Core Web Vitals across multiple sites can be challenging when done manually. WordPress management tools offer an integrated performance monitoring system that helps identify and address issues before they impact user experience.

    What if my team needs to collaborate on managing multiple WordPress sites?

    Managing access levels and coordinating maintenance tasks among team members can be complex. WordPress management tools provide a centralized dashboard with team permissions, and activity logging helps maintain security and accountability.

  • ARM64 vs X64 – Everything you need to know

    ARM64 vs X64 – Everything you need to know

    In the rapidly changing world of technology, choosing the right processor architecture can significantly affect performance, efficiency, and cost.

    At RunCloud, we’ve witnessed the impact of CPU architecture choices, particularly in server environments where performance and efficiency directly affect business costs. While consumers might be exploring ARM processors for personal computing, our focus is on the server-side revolution: how different CPU architectures are affecting cloud infrastructure, application performance, and operational efficiency.

    In this comprehensive RunCloud guide, we explore the differences between ARM and x86 architecture. Whether you’re looking to optimize your server fleet or understand the latest computing trends, we’ll provide the insights you need to make informed decisions.

    From performance benchmarks to practical implications, we’ll break down everything you need to know about ARM and x86 architectures in the context of modern computing and cloud infrastructure.

    Let’s get started!

    What is CPU Architecture?

    CPU architecture is the fundamental design and operational blueprint of a computer’s central processing unit. It defines how it processes, manages, and executes instructions at the most elemental hardware level. It dictates the core structural elements that determine how a processor:

    • Interprets machine instructions
    • Manages data flow
    • Handles computational tasks
    • Allocates and uses registers
    • Manages memory interactions

    To understand this, you can think of CPU architecture as the engine design in a car, software as the driver’s instructions, and the operating system as the dashboard and control mechanisms that coordinate everything.

    How is CPU Architecture Different from Software?

    Software operates as an abstract layer on top of the CPU architecture. It is basically a set of instructions translated into machine-level commands. It depends on the underlying architecture for execution and can be compiled or interpreted to match specific CPU instructions.

    How is CPU Architecture Different From The Operating System?

    Operating systems manage hardware resources and provide an interface between other software and the computer’s hardware. Through specialized kernels and drivers, an operating system can support multiple CPU architectures.

    However, this is only possible if the developer creates a specialized version of the operating system for a particular architecture. For example, Windows has a special version of its operating system for Windows on ARM devices.

    Aspect

    CPU Architecture

    Software/OS

    Level of Operation

    Hardware-level

    Logical/Functional level

    Modification Complexity

    Requires physical redesign

    Can be updated/replaced easily

    Dependence

    Direct hardware capabilities

    Dependent on an underlying architecture

    ARM Server Architecture

    ARM64 refers to the 64-bit ARM processor architecture, also known as ARMv8-A. It is a RISC (Reduced Instruction Set Computer) design that provides significant improvements over the previous 32-bit ARM architecture.

    ARM64 processors are widely used in various devices, including smartphones, tablets, laptops, and servers. They are also used in nearly all modern mobile devices, where power efficiency is crucial. Although it still has some rough edges, ARM64 is gaining traction in the embedded system design and cloud computing domains, where its performance and scalability are valuable assets.

    There are two primary reasons why people use the ARM CPUs:

    1. Improved performance: Compared to 32-bit ARM processors, ARM64 processors have a more efficient instruction pipeline and can execute more instructions per clock cycle.
    2. Power efficiency: The ARM64 architecture is designed for low power consumption, making it well-suited for mobile, embedded, and IoT (Internet of Things) applications.

    X86 Server Architecture

    The X64 architecture, also known as AMD64 or Intel 64, is a 64-bit extension of the x86 architecture. It was developed by AMD and later adopted by Intel to develop CPUs. Now, it has become the predominant 64-bit processor architecture for desktop and server computers.

    X86 architecture was predominantly used in the early days of computing, but it was later replaced by X64 architecture for several reasons:

    1. 64-bit registers and address space: X64 processors support 64-bit integer and floating-point data types, allowing them to access significantly more memory (up to 16 exabytes) compared to the 32-bit x86 architecture.
    2. Expanded instruction set: X64 introduces additional instructions and registers that enhance performance for 64-bit applications. This includes support for more general-purpose registers, which can improve the efficiency of arithmetic and logical operations.
    3. Backward compatibility: X64 processors maintain compatibility with the 32-bit x86 instruction set, ensuring that existing software designed for 32-bit systems can run seamlessly on 64-bit platforms.

    ARM vs x64(x86) Server Architecture Comparison Guide

    RunCloud supports both ARM and AMD64 CPU architecture for your servers, but if you are looking to pick between ARM and x86 architecture, then there are several things that you should know:

    Core Architectural Comparison

    The ARM and x86 architectures are two fundamentally different approaches to CPU design, primarily distinguished by their instruction set architectures (ISA).

    • ARM follows a Reduced Instruction Set Computing (RISC) model, which is a simpler, more streamlined instruction that can be executed quickly and with lower power consumption.
    • In contrast, x86 uses a Complex Instruction Set Computing (CISC) approach, which supports more complex, multi-step instructions that can perform sophisticated operations with fewer lines of code.

    While these architectures cannot directly run each other’s machine-level code due to their distinct instruction sets, modern programming languages provide a critical abstraction layer. Compilers can translate high-level code into architecture-specific machine instructions, allowing the same source code to be compiled for both ARM and x86 processors.

    This means a Python, Java, or C++ program can be compiled to generate native instructions specific to ARM or x86 architectures, enabling software portability across different CPU types while maintaining optimal performance for each platform.

    Feature

    ARM Architecture

    x86 Architecture

    Instruction Set

    RISC (Reduced Instruction Set Computing)

    CISC (Complex Instruction Set Computing)

    Power Efficiency

    Typically 30-50% better power efficiency

    Higher power consumption but improving with newer generations

    Cost Structure

    Lower licensing costs, emerging ecosystem

    Mature ecosystem, competitive pricing due to scale

    Market Maturity

    Growing rapidly, especially with AWS Graviton

    Dominant market position, extensive vendor support

    Software Compatibility

    Software compatibility between ARM and x86 architectures has significantly improved, with most modern programming languages and frameworks offering native support for both platforms through cross-compilation techniques.

    Major platforms such as Linux, Windows, and macOS now provide robust toolchains that enable developers to build applications that can be easily recompiled for different CPU architectures.

    While some specialized software and low-level system utilities may still require architecture-specific modifications, the vast majority of high-level applications can now be seamlessly adapted between ARM and x86 with minimal additional engineering effort.

    Software Type

    ARM Support

    x86 Support

    Linux Distributions

    Full support in major distros (Ubuntu, RHEL, etc.)

    Universal support

    Container Support

    Native Docker support, growing ecosystem

    Comprehensive support

    Web Servers

    nginx, Apache, Lighttpd

    All web servers supported

    Databases

    MySQL, PostgreSQL, MongoDB

    All major databases

    Programming Languages

    Most languages supported natively

    Universal support

    Cost Considerations

    ARM-based server architecture is considered a cost-effective alternative to traditional x86 systems, primarily due to its inherently lower power consumption and more efficient chip design. The fundamental energy efficiency of ARM processors allows data centers to significantly reduce electricity costs.

    This reduction in operational expenses is why major cloud providers and enterprise data centers are gradually shifting their infrastructure towards ARM-based solutions.

    But the cost advantages extend beyond just power consumption.

    ARM’s design allows for more compact and thermally efficient chip manufacturing, resulting in lower hardware production costs and the ability to create denser server configurations. This economic incentive is particularly compelling for hyperscale cloud providers and large-scale computing environments that operate thousands of servers simultaneously.

    Factor

    ARM

    x86

    Hardware Costs

    Lower initial investment

    Variable, competitive at scale

    Operating Costs

    Lower power consumption

    Higher power costs

    Support Costs

    It may require specialized knowledge

    Widely available expertise

    Benchmarks: ARM vs x86 Server Performance

    We designed a controlled testing environment that minimized variables and provided a fair assessment of ARM versus x86 server performance.

    We deployed two identical server configurations within the same cloud provider and region, carefully matching specifications including vCPU count, memory allocation, and network parameters.

    After that, we created a standard WordPress installation with 20 blog posts for our performance evaluation.

    We used k6 for load testing and Grafana for performance visualization to execute a 5-minute load test with 20 concurrent virtual users. During our tests, we tracked critical performance metrics, including requests per second, response times, and HTTP failure rates.

    Metric

    ARM

    x86

    Requests Made

    8.8k

    5.7k

    HTTP Failures

    0

    0

    Peak Requests per Second (RPS)

    32

    21.67

    P95 Response Time

    383ms

    893ms

    arm64 vs x64 benchmarks

    The benchmark results show notable performance advantages for ARM-based servers in this specific test scenario. Key observations include:

    1. Request Volume: ARM servers processed approximately 54% more requests compared to x86 servers, indicating a significant throughput improvement.
    2. Request Efficiency: The peak requests per second for ARM servers (32 RPS) substantially outperform x86 servers (21.67 RPS), which shows enhanced computational efficiency.
    3. Latency Performance: The P95 response time for ARM servers (383ms) is markedly lower than that for x86 servers (893ms), representing a dramatic reduction in latency that could improve user experience.

    By maintaining strict control over testing variables and using industry-standard performance analysis tools, we created a transparent and reproducible benchmark methodology. Our goal was not to declare a definitive winner but to provide an objective, data-driven perspective on the current performance capabilities of ARM and x86 server architectures.

    While these benchmarks highlight ARM’s impressive performance, it’s important to understand that server architecture selection is nuanced. x86 server architecture is a robust, mature technology with:

    • Extensive ecosystem support
    • Proven reliability
    • Widespread enterprise adoption
    • Significant ongoing development and optimization

    The results should be interpreted as a demonstration of ARM’s emerging capabilities rather than a wholesale replacement recommendation. When considering architectural transitions, you should evaluate their specific workload requirements, existing infrastructure, compatibility needs, and total cost of ownership.

    Final Thoughts: Navigating Server Architectures with Flexibility

    Throughout this article, we have discussed the different nuances of ARM and x86 architectures, as well as each platform’s strengths and considerations.

    However, the choice between ARM and x86 is no longer a binary decision but a strategic consideration dependent on specific workload requirements, cost structures, and performance needs.

    If you manage a fleet of servers, balancing ARM and x86 environments can quickly become a logistical nightmare. Deployment, optimization, and consistent performance management across different server types demand significant technical expertise – RunCloud is designed to eliminate these complexities.

    RunCloud provides comprehensive support for both ARM and x86 server environments. Whether you’re exploring performance optimizations or scaling your infrastructure, RunCloud ensures seamless deployment, monitoring, and control across different server architectures.

    Learn more about how RunCloud can help you manage your servers.

  • How to Reorder WordPress Dashboard Menu Items

    How to Reorder WordPress Dashboard Menu Items

    If you manage a WordPress website, you’ll be very familiar with the WordPress dashboard, which is used for content creation, site maintenance, and administrative tasks.

    However, many users feel that the default admin menu is cluttered, with many essential tools scattered, while less-used sections of the website consume valuable screen space.

    This comprehensive guide will walk you through multiple strategies to take complete control of your WordPress dashboard menu. From simple drag-and-drop techniques to advanced custom coding methods, you’ll discover how to:

    • Rearrange admin menu items with precision
    • Hide unnecessary menu sections
    • Create role-based menu experiences
    • Implement custom menu orders using PHP
    • Leverage powerful WordPress and plugin-based solutions

    Whether you’re struggling with a cluttered dashboard, seeking to improve team workflow, or simply want a more personalized administrative experience, this guide will provide the tools and knowledge to transform your WordPress backend into a clean dashboard.

    Let’s get started!

    Benefits of Reordering Your WordPress Dashboard Menu

    Rearranging your WordPress dashboard menu improves your administrative experience, as a cluttered interface transforms into a personalized, efficient workspace. This customization saves time and dramatically improves workflow.

    This dashboard customization allows you to:

    • Prioritize the tools and sections you use most frequently, bringing them to the top of the menu for instant access.
    • Reduce cognitive load by organizing menu items in a way that makes logical sense to your specific workflow.
    • Minimize the time spent hunting for specific settings or features.
    • Create a more comfortable and personalized administrative environment that reflects your unique working style.

    Once you modify your site menu according to your needs, content management, site maintenance, and administrative tasks become more intuitive. You’ll focus on creating content, not navigating a complex dashboard.

    Suggested read: Protect Your WordPress Login pages with Cloudflare Zero Trust

    How to Reorder Dashboard Menu Items in WordPress

    So we know why you should re-order your menu items, now let’s see how to do this.

    Method 1: Reorder Dashboard Menu Items via Admin Menu Editor Plugin

    Step 1 – Install Admin Menu Editor Plugin

    Start by navigating to your WordPress dashboard and clicking on “Plugins” in the left-hand menu, then select “Add New“, and use the search bar to find “Admin Menu Editor” by searching for the plugin name.

    WordPress Dashboard Menu

    Click the “Install Now” button next to the plugin, and after installation, activate the plugin by clicking the “Activate” button. This will enable the menu customization features in your WordPress backend.

    Suggested read: Everything You Need To Know About wp-config.php File

    Step 2 – Rearrange the Menu Items from Plugin Settings

    After activation, locate the new “Menu Editor” option that will appear in your WordPress dashboard sidebar and click on it to open the customization menu. On this screen, you’ll see a full representation of your current dashboard menu structure.

    You can use the intuitive drag-and-drop functionality to reorder menu items by simply clicking and holding an item and then dragging it to your desired position. This allows you to prioritize the most frequently used sections and create a more personalized administrative experience that matches your specific workflow and preferences.

    Suggested read: 10 Best WordPress Management Tools To Easily Manage Multiple Websites

    Step 3 – Customize Button Actions

    Admin Menu Editor provides features such as access control based on user roles, multisite settings management, and precise menu positioning. Administrators can use these features to create highly tailored dashboard experiences that enhance security, streamline workflow, and prevent unauthorized access to sensitive site areas.

    For example, a large organization with multiple content creators could use these settings to ensure that writers only see post-related menus, and editors have additional publishing capabilities, while keeping critical settings like plugin management and site-wide configurations exclusively accessible to top-level administrators.

    Additionally, the Admin Menu Editor’s debugging and error verbosity levels allow technical teams to troubleshoot menu permission issues efficiently. Its options range from minimal error reporting to comprehensive diagnostic information, making it invaluable for agencies managing numerous client websites.

    Suggested read: How to Easily Optimize WordPress Website With RunCloud Hub

    Method 2: Manual Theme File Editing (For Advanced Users)

    If you prefer a more technical approach or can’t use plugins, you can manually edit menu items by modifying your theme’s functions.php file using custom PHP code. However, this is a technical method which is only recommended for advanced users as it requires:

    • A good understanding of PHP
    • Permission to edit the WordPress code directly

    Step 1: Accessing the Theme Customization Files

    Open your RunCloud WordPress website’s theme directory, typically located in wp-content/themes/your-theme-name/, and locate the functions.php file using the file manager or via SSH connection. If you’re using a child theme (recommended), open the child theme’s functions.php file to ensure your customizations are not lost during theme updates.

    Suggested read: The Complete WordPress Speed Optimization Guide

    Step 2: Customizing Menu Order with PHP Code

    Add the following custom PHP code to your functions.php file to reorder the WordPress dashboard menu items:

    // RunCloud WordPress Dashboard Menu Customization
    // Enable custom menu ordering
    add_filter( 'custom_menu_order', 'runcloud_custom_menu_order', 10, 1 );
    add_filter( 'menu_order', 'runcloud_custom_menu_order', 10, 1 );
    function runcloud_custom_menu_order( $menu_ord ) {
         if ( !$menu_ord ) return true;
         return array(
              'index.php',            // Dashboard
              'separator1',           // First separator
              'edit.php?post_type=page', // Pages
              'edit.php',             // Posts          // Add or remove menu items as needed
         );
    }

    Step 3: Save The Changes

    After making the necessary changes to your functions.php file, you can save it and refresh your WordPress dashboard. The updated menu list will reflect on your dashboard immediately.

    Advanced WordPress Dashboard Customization Techniques

    WordPress provides a rich set of built-in functions that allow for even more sophisticated menu and page customization beyond basic ordering. Here are some powerful functions to further enhance your dashboard management:

    • add_menu_page() enables you to create entirely new top-level menu items in the WordPress dashboard. It gives you complete flexibility to introduce custom administrative sections tailored to your specific website needs. This function allows you to specify the menu title, capability requirements, unique slug, and even a custom icon for your new menu item.
    • The remove_menu_page() function allows developers to remove specific top-level admin menu items from the WordPress dashboard by providing the menu’s unique slug. By calling this function within the admin_menu action hook, you can selectively hide menu pages and customize sections in the WordPress admin interface.
    • add_media_page() specifically allows you to add custom pages to the Media menu, which can be incredibly useful for creating specialized media management interfaces or implementing custom media-related functionality.
    • add_meta() offers a programmatic way to add custom metadata to posts, which can be particularly helpful for creating advanced content management systems or implementing complex editorial workflows. This function allows you to dynamically attach additional information to your WordPress content that can be used for filtering, sorting, or displaying extra details.
    • add_menu_classes() enables fine-tuned control over the CSS classes applied to top-level administration menu items, allowing you to customize the visual presentation and behavior of your dashboard navigation. This function is particularly useful for advanced theming and creating more intuitive administrative interfaces that match your specific design requirements.

    Wrapping Up

    In this guide, we have provided you with steps to modify and customize your WordPress dashboard. However, when implementing dashboard menu customizations, you should always test your modifications in a staging environment to ensure they don’t disrupt your website’s functionality or user experience.

    If you are using RunCloud, you can simply do this by using our one-click staging feature. RunCloud also makes WordPress installation and updates incredibly straightforward, allowing users to manage complex web infrastructure with remarkable ease.

    What truly distinguishes RunCloud is its atomic deployments functionality, which allows you to create version-controlled WordPress development. You can use this to create staging sites for risk-free testing of customizations.

    Master your WordPress sites with RunCloud! Start your FREE RunCloud trial today

    FAQs About the WordPress Dashboard Menu

    How do I organize my WordPress dashboard?

    Organizing your WordPress dashboard is straightforward and can significantly improve your site management efficiency by allowing you to rearrange menu items to your preferred order. WordPress provides intuitive built-in functionality that lets you customize the menu layout by creating custom child themes with PHP code to prioritize the most frequently used sections and create a more personalized administrative experience that aligns with your specific workflow and needs.

    Can only the admin access the WordPress dashboard?

    WordPress provides multiple levels of dashboard access through its robust user role management system, with the primary administrator having full control, and other roles such as editors, authors, and contributors receiving limited or specific access to dashboard features. The default WordPress user roles are carefully designed to provide granular permissions, ensuring that each team member can access only the sections and functions relevant to their responsibilities, which helps maintain site security while allowing collaborative content management.

    How do I customize my WordPress dashboard menu?

    Customizing your WordPress dashboard menu can be achieved through several methods. Firstly, you can use the “Admin Menu Editor” Plugin in WordPress to use its menu personalization options. Alternatively, advanced users can also use custom code to create a completely tailored dashboard experience. This allows you to not just reorder menu items but also hide, rename, and precisely control every aspect of your administrative interface for maximum efficiency and user-friendliness.

  • What is Fail2Ban with Setup & Configuration? (Detailed Guide)

    What is Fail2Ban with Setup & Configuration? (Detailed Guide)

    Are you tired of brute-force attacks hammering your server? Worried about automated robots crippling your website or application? You’re not alone.

    Millions of servers face relentless attacks daily, but there’s a powerful, free tool that can significantly improve your security: Fail2Ban.

    This comprehensive guide will explore everything you need to know about Fail2Ban, from its basic functionality and installation (on Ubuntu) to more advanced features such as whitelisting IP addresses, as well as its applications for securing various services.

    But first, let’s explore Fail2Ban and how it works with iptables to banish malicious IPs!

    What is Fail2Ban?

    Fail2Ban is an intrusion prevention system that can block attackers from accessing your server. It can be thought of as an automated bouncer that watches your server’s log files for suspicious activity and kicks out bad actors before they can cause trouble.

    It constantly scans your server’s logs, looking for anyone repeatedly trying to guess passwords or force their way in. While it started as a simple SSH protector, Fail2Ban can be configured to monitor almost everything on your server – from your website traffic to email services and file transfer systems.

    Suggested read: How To Use Fail2Ban With WordPress And Cloudflare Proxy

    Benefits of Using Fail2Ban

    Using Fail2Ban brings real, practical benefits to your server security as it stops automated attacks by blocking suspicious IP addresses before they can break in. This means your server isn’t wasting time and power dealing with these attacks, freeing up resources to serve other customers and keeping your server fast and responsive for real users.

    System administrators love that Fail2Ban keeps detailed records of who tried to break in and when. These records help administrators spot patterns in attack attempts. The best part? You can easily tweak its rules to match your specific needs – whether you want to be super strict or a bit more lenient with login attempts. This flexibility makes Fail2Ban very useful in a number of different applications.

    Suggested read: 10 Security Tips to Secure VPS Server in 2024? [Ultimate Guide]

    How Does Fail2Ban Work?

    Fail2Ban does its job through a clever but simple process. It reads your server’s log files in real time and scans for things like failed login attempts or suspicious requests. When it spots someone trying to log in with the wrong password too many times, it automatically blocks their IP address using your server’s firewall.

    This blocking system works through what technicians call “jails” – separate security rules for different services on your server. Each jail acts like a security checkpoint, with its own set of rules about what’s suspicious, how many strikes before you’re blocked, and how long the timeout should last. You can set up these jails differently for each service according to your requirements.

    Suggested read: 3 Ways to Fix Too Many Authentication Failures SSH Root? [SOLVED]

    How to Set Up & Install Fail2Ban on Linux Ubuntu

    In this section, we will explain how to set up and install Fail2Ban on your Ubuntu server.

    Note: If you’re using RunCloud, you’re in luck! Fail2Ban comes pre-installed with all RunCloud servers, so you can skip the installation steps and jump straight to configuration.

    Installing Fail2Ban

    Installing Fail2Ban is as simple as it could be. First, you need to connect to your server’s terminal via SSH and update your package list by executing the following command

    sudo apt update

    Next, you can execute the following command to install Fail2Ban using Ubuntu’s package manager:

    sudo apt install fail2ban -y

    This command will install the necessary packages required for Fail2Ban. Once installation is finished, you can check if it is up and running by executing the following command:

    sudo systemctl status fail2ban

    Setting Up the Configuration Files

    After installing the Fail2Ban system, you can create a local configuration file to store your custom settings. Execute the following command to create a local configuration:

    sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local

    Next, you need to open the local configuration file with your favorite text editor. If this is your first time using a command-line editor, we recommend reading our blog post on editing files on remote servers with SSH and Nano.

    sudo nano /etc/fail2ban/jail.local

    Basic Configuration Settings

    Once you open the configuration file, scroll down until you find the [DEFAULT] section and adjust these common settings:

    bantime = 10m        # how long to ban an IP
    findtime = 10m       # time window to look for attempts
    maxretry = 5         # number of attempts before ban

    The names of each setting in the configuration file are pretty self-explanatory, but if you need additional help, you can refer to Fail2Ban’s official documentation.

    Suggested read: PHP Security – Best Practices To Secure Your Web App in 2024

    Check Active Jails & Banned IPs

    You can easily see all active jails and banned IPs on your server by executing the following command in your terminal:

    sudo fail2ban-client status

    Note: If you’re using RunCloud, you can see the list of banned IP addresses by navigating to the Security > Fail2Ban tab in your server settings.

    Suggested read: 11 Alternatives To reCAPTCHA to Protect Your Site from Spam

    Managing Banned IPs

    You can view all banned IPs in a specific jail (such as SSH) by executing the following command:

    sudo fail2ban-client status sshd

    In the above example, we can see there is no banned IP on the sshd jail list. If you want to check a different jail, you can replace sshd with the name of that jail.

    Suggested read: PHP Security – Best Practices To Secure Your Web App in 2024

    Monitoring Fail2Ban Logs

    Fail2Ban logs provide a real-time window into your server’s security by showing you exactly who’s trying to break in, when they attempted it, and whether they were successfully blocked. You can see these logs by either checking /var/log/fail2ban.log, or you can execute the following command to see the Fail2Ban logs in real time:

    sudo tail -f /var/log/fail2ban.log

    Suggested read: Best Practices to Secure a Docker Container

    How to Configure Fail2Ban

    Let’s see how to configure your Fail2Ban server to add and remove jails.

    Pro Tip: If you’re using RunCloud, most of these configurations come pre-set with sensible defaults. RunCloud also provides an easy-to-use interface for monitoring banned IPs and managing your security settings without touching the command line.

    Configuring SSH Protection

    You can modify SSH jail settings in Fail2Ban to protect your server against brute-force attacks. This method monitors failed login attempts and automatically bans suspicious IPs that exceed the allowed retry limit.

    RunCloud users don’t need to worry about manually configuring SSH protection as it comes pre-configured with optimal security settings. However, if you want to configure it manually, then you can modify the following parameters in your configuration file as per your requirement:

    [sshd]
    enabled = true
    port = ssh
    filter = sshd
    logpath = /var/log/auth.log
    maxretry = 3
    bantime = 24h

    Suggested read: DKIM – What Is It & Why Your Emails Need It

    Setting Up Multiple IP Ignoring

    If you work in an organization, you may have a fixed set of IP addresses for different computers. You can whitelist multiple IP addresses for each of your devices – like your home office, development team, or content managers – to ensure that you never accidentally get banned from accessing your server.

    You can execute the following command to add trusted IP addresses or CIDR blocks, but make sure to replace the provided IP address with your IP address:

    # Under [DEFAULT]
    ignoreip = 127.0.0.1/8 23.45.67.89 your.home.ip.here

    Tip: Want to enhance your WordPress security while using Cloudflare? Check out our detailed guide on “How To Use Fail2Ban With WordPress And Cloudflare Proxy” to learn how to configure Fail2Ban correctly when your website is behind Cloudflare’s proxy. This guide specifically explains how to ensure Fail2Ban correctly identifies potential attackers’ real IP addresses instead of Cloudflare’s IPs.

    Removing Banned IPs in Fail2Ban

    If you accidentally fail too many login attempts, then you will need to wait for the cooldown period to be over before you can try to log in again. Or, if you are in a hurry, you can execute the following command to remove the provided IP address from the ban list:

    sudo fail2ban-client set sshd unbanip 123.123.123.123

    While you could use Fail2Ban commands directly, RunCloud makes this much easier through its intuitive dashboard. Just navigate to the ‘Security’ section, find the banned IP, and click to unban it – no command line is needed!

    Read our post titled “How to Unban IP Address in Fail2Ban” to get step-by-step instructions.

    Enable Recidive Jail

    Recidive jail is like a “super ban” feature in Fail2Ban that tracks repeat offenders who continue to attack your server even after their initial ban expires. When an IP address gets banned multiple times within a specific timeframe, the recidive jail kicks in and implements a much longer ban duration (usually a week or more) to provide stronger protection against persistent attackers.

    Think of it as Fail2Ban’s way of saying, “You’ve been warned multiple times, now you’re really not welcome here.”

    It’s particularly effective against automated bots and aggressive attackers who might otherwise wait out shorter ban periods and resume their attacks.

    You can enable it by adding the following code snippet to your configuration file:

    [recidive]
    enabled = true
    filter = recidive
    logpath = /var/log/fail2ban.log
    bantime = 1w
    findtime = 1d
    maxretry = 3

    Restart/Reload Fail2Ban

    After you make any configuration changes, you must reload the settings for them to take effect. You can do this by running the following command in your terminal:

    sudo systemctl reload fail2ban

    Final Thoughts

    In this comprehensive guide, we’ve covered everything from understanding Fail2Ban’s core functionality to its installation and configuration. We’ve seen how this powerful security tool can protect against brute-force attacks, suspicious activities, and potential security breaches.

    But if all of this sounds complicated, you’ll be delighted to know that you don’t need to be a Linux expert to implement robust server security anymore.

    RunCloud makes server security accessible to everyone by including Fail2Ban pre-installed and pre-configured on all servers.

    But that’s just the beginning of RunCloud’s security features.

    You get SSH key vaults, automated SSL certificate management, web application firewall (WAF) rules, and real-time security monitoring – all managed through an intuitive dashboard. Imagine handling IP bans, checking security logs, and managing firewall rules with just a few clicks instead of complex command lines!

    Ready to Secure Your Server?

    Start your free RunCloud trial today and experience how easy server management can be. With plans starting from as little as the cost of a dinner per month, you get enterprise-grade security features without the enterprise-level complexity.

    FAQs on Fail2Ban

    What is the difference between Fail2Ban jail.conf and jail.local?

    The jail.conf file contains default settings and gets overwritten during system updates, making it unsuitable for custom configurations. The jail.local file, which takes precedence over jail.conf, is where you should store your custom Fail2Ban settings to ensure they persist through updates.

    Is Fail2Ban safe?

    Fail2Ban is considered a safe and reliable security tool that’s widely used by system administrators worldwide. With RunCloud’s pre-configured Fail2Ban settings, you get an additional layer of security that’s been carefully tuned for optimal protection without risking false positives.

    What is the difference between Fail2Ban and UFW?

    Fail2Ban is a dynamic intrusion prevention system that automatically blocks suspicious IP addresses based on their behavior, while UFW (Uncomplicated Firewall) is a static firewall that manages incoming and outgoing traffic based on predefined rules. While they serve different purposes, they work well together, and RunCloud manages both for complete server protection.

    How do I ignore my IP address in Fail2Ban?

    You can add your IP address to the ignoreip list in the jail.local configuration file under the [DEFAULT] section. RunCloud makes this process even easier through its dashboard, where you can whitelist IPs with just a few clicks.

    How do I stop Fail2Ban?

    To stop Fail2Ban on your server, you first need to log in to it via SSH, and then you can use the command sudo systemctl stop fail2ban in your terminal.

    Does Fail2Ban work on SSH?

    Yes, Fail2Ban excellently protects SSH by monitoring login attempts and blocking suspicious IPs trying to brute force their way in. RunCloud servers come with pre-configured SSH protection through Fail2Ban, providing immediate security against SSH attacks right from the start.

    Is Fail2Ban a WAF?

    No, Fail2Ban is not a Web Application Firewall (WAF) but rather an intrusion prevention system that monitors logs for suspicious activity. For comprehensive security, RunCloud provides both Fail2Ban and additional security features that complement WAF functionality.

    Does Fail2Ban need iptables?

    Fail2Ban traditionally uses iptables or similar firewall backends to implement its banning actions. RunCloud handles all the firewall configurations automatically, ensuring Fail2Ban works perfectly with your server’s firewall setup.

    How much does Fail2Ban cost?

    Fail2Ban is completely free and open-source software. When you use RunCloud, Fail2Ban comes pre-installed and pre-configured as part of your server management package, adding professional-grade security at no additional cost.

  • How to Install & Set Up Ghost (NGINX and OpenLiteSpeed)

    How to Install & Set Up Ghost (NGINX and OpenLiteSpeed)

    Ghost is a free and open-source blogging platform built with Node.js. As a fast, modern WordPress alternative, Ghost is focused completely on professional publishing. If you only want to publish content on the web and don’t need the additional features offered by WordPress, then Ghost is a great choice.

    In this post, we will discuss how to install Ghost using RunCloud.

    Let’s get started!

    Create A New User

    Ghost CLI needs sudo privileges, so instead of running your site as a root user, we recommend creating a new user with these sudo privileges. This can be done by running commands in the terminal, but it’s much easier to do within the RunCloud dashboard.

    To create a new user, go to the RunCloud dashboard and open the “System User” menu.

    Once opened, click “Add New System User” to create a new user. Give it a descriptive name and a secure password. Make sure to check the box to allow the execution of privileged commands.After this, click “Save System User” and continue the installation process.

    Create A New Database

    After creating the system user, the next step is to create a new database and database user. To do this, go to the “Database” menu under your server in the RunCloud Dashboard to create a new database user. Give this database user a suitable name and a secure password, and note these credentials, as they will be needed later during the installation.

    After creating the database user, create a new database and grant permission to the user we just created. Save the changes before proceeding to the next step.

    Create An Empty Web App

    After you have created the user, go to the “Web Applications” tab and create a new web application on your server.

    Choose the “Empty Web App” option and give your application a suitable name. Don’t forget to change the application’s owner. Instead of using the default RunCloud user, we will create the user account we just created as the owner of the web application.

    After configuring the application owner, you can manually set up the domain and configure the DNS records on your DNS registrar’s site.

    If you are using RunCloud’s Cloudflare integration, you can take advantage of the automatic DNS update functionality.

    It is also possible to install Ghost using RunCloud’s test domain. If you want to follow this tutorial without setting up your domain or subdomain, use the RunCloud test domain.

    For “Web Application Stack”, we recommend choosing “Native NGINX + Custom Config” to install Ghost CMS and then clicking “Deploy” to finish the set-up process.

    If your server runs on OpenLiteSpeed, we’ve included notes on different steps in this guide.

    After creating the app, go to the settings page and scroll down to the “Linked Database” section. From the dropdown menu, select the database we just created. Remember to click “Update Linked Database” to save the changes.

    Installing Ghost-CLI (for NGINX and OLS servers)

    Note: If you want to install GhostCMS on a Docker server, skip this section and jump to the Docker installation instructions.

    In the previous step, we created a dummy web application in the RunCloud dashboard, which helps us perform administrative tasks such as monitoring the logs from the RunCloud dashboard. Now, we will use Ghost-CLI, a command-line tool, to install and configure Ghost CMS and replace that dummy application.

    To avoid permission conflicts, we will install the Ghost-CLI as the web application’s owner. To do this, log in to your server as the system user assigned to the web application – you can either do this via SSH or use the su (switch user) command.

    # Method 1
    ssh ghostcms-user@<youripaddress>
    # Method 2
    ssh root@<youripaddress>
    sudo su ghostcms-user

    After logging in to the server, navigate to the root directory of your web application using the following command. Replace the “<path to root>” with your path – you can find this in the RunCloud dashboard:

    cd <path to root>

    Once in the correct directory, you can run the following commands to remove the default “index.html” file and begin the installation:

    rm index.html
    sudo npm install ghost-cli@latest -g

    After the installation is complete, you can run “ghost version” on your terminal to check the version of Ghost-CLI and ensure that the CLI works as expected.

    Checking Node.js version

    Ghost CMS needs Node.js to function properly. At the time of writing, the recommended node version was 18; refer to the official website to see the recommended node version.

    Execute the following command to see the version of the node installed on your server:

    node -v

    In the above screenshot, the first number in v18.18.0 indicates the major version number of the software. The major version number reflects the software’s level of compatibility and functionality. The other numbers after the dot (.) are minor version numbers or patch numbers. They do not affect the compatibility or functionality of the software as much as the major version number. Therefore, they can be ignored if you are only interested in the major version number.

    Note: If you created your server before 27 September 2023, you might need to update the node version manually. Refer to our guide for updating the node on your RunCloud server to learn how to do this.

    Installing Ghost CMS

    After installing Ghost-CLI, you can run the following command to start the Ghost CMS installation:

    ghost install

    During the installation, follow the instructions on the screen and enter the necessary information to proceed.

    When asked for the hostname, enter 127.0.0.1. Using the default value causes the Ghost CMS to use the IPv6 address, which leads to an ECONNREFUSED::1:3306 error at a later stage in the installation.

    When asked, “Do you wish to set up Systemd?” please enter “Y”, and when prompted, “Do you wish to start Ghost”, enter “Y” again.

    If you follow the instructions correctly you will get a message that the installation was successful. However, when you visit your site you will see a 404 error message. This is because we skipped the NGINX setup during installation. We can configure this manually to fix it.

    Before we set up the server proxy, we need to know which port Ghost will use for this website. Run the following command to get the details of your web application:

    ghost ls 

    The above command will show an output that looks like this:

    In the example above, the port number is 2368. Note down this port number.

    Installation on Docker

    In addition to installing Ghost directly on an NGINX or OpenLiteSpeed server, you can also deploy Ghost using Docker. This allows you to take advantage of the consistency and portability of containerized applications.

    To deploy Ghost on a Docker server, you must first set up an empty web application on your RunCloud server by following the steps described above. Once that is done, follow these steps:

    1. Log in to the server via SSH: Connect to your RunCloud server using SSH to access the terminal and run Docker commands.
    2. Create a Docker Compose file: Create a docker-compose.yml file that defines the Ghost container. This file should include the necessary environment variables for your database connection and the URL for your Ghost installation.

    Here’s an example docker-compose.yml file:

    services:
      ghost:
        image: ghost:5-alpine
        restart: always
        ports:
          - 8080:2368
        environment:
          database__client: mysql
          database__connection__host: host
          database__connection__user: ghost_user
          database__connection__password: asd123456
          database__connection__database: ghost_db
          url: http://ghost.example.com
        volumes:
          - ghost:/var/lib/ghost/content
        extra_hosts:
          - 'host:host-gateway'
    volumes:
      ghost:
    1. Modify Dockerfile: After creating the above file, you must edit certain sections to ensure your application runs correctly. First, if deploying more than one Ghost container, you must replace 8080 with a unique port number for each container. Next, you must replace http://ghost.example.com with the URL of the web application you deployed earlier.
    2. Create a custom NGINX proxy: Next, create a custom NGINX proxy for your RunCloud app to the custom port you defined in the Docker Compose file (in this case, 8080). You can use the same NGINX configuration as you would for a Ghost non-Docker installation (described below in this tutorial).
    3. Start the Docker container: Finally, run docker-compose up -d in the directory containing the docker-compose.yml file to start the Ghost container.

    Setting Up A Proxy

    You need to configure your server to redirect all the incoming traffic to the given port. This step is different for NGINX and OpenLiteSpeed servers. If you are not sure which server is installed on your machine, you can check this in the RunCloud dashboard and then follow along the instructions corresponding to your server.

    For NGINX

    Return to the RunCloud dashboard, open your web application, and go to the NGINX Config menu. Click the “Create Config” button and follow the steps below.

    • For the “Type” option, select the value “location.root”.
    • For the “Config Name” option, you can use the value “ghost”.
    • Copy and paste the text below into the “ConfigContent” text area. Make sure to change XXXX to the port number we noted earlier:
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header Host $http_host;
    proxy_pass http://127.0.0.1:XXXX;

    You can click “Run and Debug” to see if this custom config has any issues. Then, click the “Add Config” button to finish it.

    For OpenLiteSpeed

    In the RunCloud dashboard, open the empty web application created in the Create An Empty Web App step and look for the “LiteSpeed Config” in the side menu to open the configuration file.

    We need to edit a few lines in this file. Firstly, note down the name of the extprocessor – we will use this later.

    Next, disable the existing configuration by adding # before the type and address line.

    After that, add the following lines below the commented lines. Don’t forget to change xxxx to the port number we noted earlier.

    type                    proxy
    address                 localhost:xxxx

    At this stage, your configuration file should look like this:

    Next, scroll down and add the following code snippet to your configuration file. Be careful not to paste it in the middle of an existing config block. Replace the <my-ghost> with the name of the extprocessor that we noted down earlier.

    context / {
      type                    proxy
      handler                 <my-ghost>
      addDefaultCharset       off
    }

    At this point, your config file will look something like this:

    Click on “Update Config” to save the settings.

    Finally, we need to restart the OpenLiteSpeed service for the changes to take effect. Open the server page in your RunCloud dashboard and look for the “Services” option in the side menu. On that page, click the “…” button next to the OpenLiteSpeed server and “Restart”.

    Log In To Your Ghost Dashboard

    After setting up the proxy config, you can visit your website. To configure the admin account, go to https://example.com/ghost. You must enter basic details on this page, such as the site name and admin login details.

    After setting up the admin account, you can log into the Ghost dashboard and start publishing.

    After Action Report

    Ghost CMS is an effective modern publishing platform powered by Node.js. RunCloud makes it easy to install and configure Ghost CMS. After following the steps mentioned in this article, you will be able to set up your own CMS and start publishing content.

    After installation, you can learn more about Ghost-CLI commands and tutorials to customize your Ghost blog.I

    f you’re tired of managing your own servers, check out RunCloud, a simple yet powerful control panel for cloud servers. RunCloud is built for developers who want to focus on shipping great work, not on managing their infrastructure. Discover painless server configuration and say goodbye to spending hours figuring it out – get started with RunCloud today to get up and running in minutes.

    Ghost Installation FAQs

    What is Ghost blog, and why should I use it?

    Ghost is a free and open-source blogging platform designed to be simple, elegant, and focused on writing. It is a great choice for users who want to create a professional-looking blog without the complexities of traditional content management systems such as WordPress.

    What are the requirements for installing Ghost?

    To install Ghost, you will need a web server running either NGINX or OpenLiteSpeed, Node.js, MySQL, or SQLite. You will also need to configure your server’s domain name and SSL/TLS certificate.

    How do I install Ghost on an NGINX server?

    To install Ghost on an NGINX server, you must first install Node.js and MySQL, then download and install the Ghost NPM package. Next, you will need to configure NGINX to serve the Ghost application and set up the database connection. Finally, you will need to start the Ghost service and configure any additional settings.

    How do I install Ghost on an OpenLiteSpeed server?

    Installing Ghost on an OpenLiteSpeed server is similar to the NGINX process but with a few key differences. First, you must install Node.js and MySQL, then download and extract the Ghost files. Next, you will need to configure OpenLiteSpeed to serve the Ghost application and set up the database connection. Finally, you will need to start the Ghost service and configure any additional settings.

    What are some common issues that can arise when installing Ghost?

    Some common issues that can arise when installing Ghost include problems with the Node.js or MySQL installation, difficulty configuring the web server, and issues with the database connection. It’s important to carefully follow the installation instructions and troubleshoot any errors.

    How do I customize the appearance of my Ghost blog?

    Ghost offers a wide range of themes and customization options, allowing you to easily change the look and feel of your blog. You can install pre-built themes or create custom themes using Ghost’s theme development tools.

    What are the best practices for securing a Ghost blog?

    To secure your Ghost blog, keep your software up-to-date, use strong passwords, and configure your web server with appropriate security settings. You should also consider enabling two-factor authentication and monitoring your blog for suspicious activity.

    How do I integrate my Ghost blog with other tools and services?

    Ghost offers many integrations, allowing you to connect your blog to other tools and services, such as social media platforms, email marketing providers, and analytics tools. You can also use Ghost’s API to build custom integrations and extend your blog’s functionality.

  • The 8 Best Cloudflare Alternatives in 2026

    The 8 Best Cloudflare Alternatives in 2026

    A reliable and performant content delivery network (CDN) is essential if you’re running a business online. Cloudflare CDN has long been a go-to solution for web developers, but what if you’re looking for something different?

    Whether you’re seeking better performance, enhanced security, or more customization options, the market is brimming with Cloudflare alternatives that could be a better fit for your needs.

    In this comprehensive guide, we’ll dive into the world of CDNs, exploring high-performance options, cost-effective free solutions, and specialized platforms for DDoS protection and web application firewall (WAF) capabilities. We’ll also address common Cloudflare issues and highlight the top Cloudflare alternatives to help you avoid these pitfalls.

    Let’s get started!

    What is Cloudflare?

    Cloudflare is a popular content delivery network (CDN) and web security provider that helps improve the performance and security of websites and online applications. It was founded in 2009, and since then, Cloudflare has grown to become one of the largest CDN providers in the world, serving trillions of requests per month across its global network of data centers.

    People use Cloudflare for two main reasons:

    1. Improve Website Performance: Cloudflare’s network of servers around the world can cache static content (such as images, CSS, and JavaScript files) closer to end-users, reducing the distance data has to travel and resulting in faster load times. This particularly benefits websites and web apps with a global user base.
    2. Enhance Website Security: Cloudflare provides a range of security features to protect websites from common threats, including DDoS attacks, malicious bots, and vulnerabilities. It can also help filter out spam, block bad IPs, and provide SSL/TLS encryption.

    Unlike many other cloud providers, Cloudflare has its own backbone network. By routing a website’s traffic through Cloudflare’s own network, website owners can leverage these performance and security benefits without managing the underlying infrastructure themselves.

    Suggested read: How to Use Cloudflare Firewall Rules to Protect Your Web Application

    Disadvantages of Cloudflare

    While Cloudflare is a popular and powerful service, it’s not without its drawbacks. Some of the key disadvantages of using Cloudflare include:

    1. Vendor Lock-in: Integrating a website with Cloudflare can create a degree of vendor lock-in. Migrating away from Cloudflare to another CDN or security provider can be a complex and time-consuming process, which may discourage some users from exploring alternative options.
    2. Single Point of Failure: By routing all of a website’s traffic through Cloudflare’s network, the service becomes a single point of failure. For example, in 2022, Cloudflare experienced an outage, and many websites became unavailable.
    3. Privacy Concerns: Cloudflare’s position as an intermediary between users and a website means it has visibility into a significant amount of user data and web traffic. While Cloudflare has policies to protect user privacy, some users may be uncomfortable with this level of third-party access to their data.
    4. Increased Complexity: Integrating Cloudflare with a website can add an additional layer of complexity to the overall infrastructure. This may make it more challenging to troubleshoot issues or optimize performance, especially for users unfamiliar with Cloudflare’s tools and processes.
    5. Limited Control: By using Cloudflare, website owners relinquish a certain degree of control over their website’s performance and security. While Cloudflare provides a range of configuration options, the ultimate decisions and implementation details are in the hands of the Cloudflare team.
    6. Cost: Cloudflare offers both free and paid plans, but the paid plans can become expensive for websites with high traffic or bandwidth requirements.

    Website owners should carefully weigh the benefits of using Cloudflare against these potential drawbacks and determine if the provided features align with their specific needs and requirements.

    Suggested read: How to Fix Cloudflare Captcha Failure in 2024 [SOLVED]

    8 Best Cloudflare Alternatives

    There are many great CDN providers available in the market. These are our recommendations, with each compared to Cloudflare CDN.

    1. Fastly

    Fastly is a great alternative to Cloudflare for customers looking to improve their website’s performance and security. Fastly is a leading CDN provider that offers several advantages over Cloudflare:

    1. Greater Control and Customization: Fastly provides users with more granular control over their CDN configuration and settings, allowing for greater customization and optimization to meet the unique needs of each website or application. This level of control can be especially beneficial for enterprises or developers who require more advanced features and capabilities.
    2. Improved Performance: Fastly’s global network of Points of Presence (PoPs) is strategically located to minimize latency and improve content delivery speeds for end-users, often outperforming Cloudflare’s network in certain regions or use cases.
    3. Advanced Security Features: Fastly’s security offerings, such as its web application firewall (WAF) and bot management solutions, are highly regarded in the industry and can provide more robust protection against threats compared to Cloudflare’s standard security features.
    4. Reliability and Uptime: Fastly is known for its reliable and highly available network. It has a strong track record of maintaining excellent uptime and minimizing service disruptions, which is crucial for mission-critical websites and applications.
    5. Transparency and Support: Fastly is generally praised for its transparent pricing, comprehensive documentation, and responsive customer support, which can be valuable for users who require more hands-on guidance and assistance.

    While Cloudflare is a reliable and widely used CDN, Fastly’s focus on customization, performance, security, and customer support can make it a more compelling choice for enterprises, developers, and users with complex or specialized requirements.

    Suggested read: Cloudflare R2 vs AWS S3 – Full Comparison

    2. Akamai CDN

    Akamai is another prominent CDN provider that we recommend as an alternative to Cloudflare, particularly for customers with large-scale or high-traffic websites and applications. Some of the key advantages of Akamai over Cloudflare include:

    1. Enterprise-grade Scale and Capacity: Akamai operates one of the world’s largest and most interconnected CDN networks. It can handle massive volumes of traffic and deliver content at scale, making it a preferred choice for enterprises with global reach and high-volume requirements.
    2. Advanced Cybersecurity Solutions: Akamai is renowned for its robust security offerings, including its web application firewall (WAF), DDoS mitigation, and bot management solutions, which are often seen as more comprehensive and effective than Cloudflare’s security features.
    3. Extensive Integrations and Partnerships: Akamai has a wide range of integrations and partnerships with various technology providers, making integrating with existing infrastructure and workflows easier, especially for larger organizations with complex technology stacks.
    4. Dedicated Support and Professional Services: Akamai provides a higher level of dedicated support and professional services compared to Cloudflare, which can be beneficial for customers who require more hands-on guidance, custom configurations, or enterprise-level service-level agreements (SLAs).
    5. Granular Reporting and Analytics: Akamai’s advanced analytics and reporting capabilities can offer more in-depth insights into website and application performance, security threats, and user behavior, which can be valuable for data-driven decision-making and optimization.

    While Akamai’s enterprise-grade features and support come at a higher price point compared to Cloudflare, the investment can be justified for organizations with mission-critical web properties, stringent security requirements, or the need for more comprehensive and tailored CDN solutions.

    Suggested read: Amazon Route 53 vs. Cloudflare DNS – Which Is Better?

    3. Amazon CloudFront (AWS)

    Amazon CloudFront is a CDN service offered by Amazon Web Services (AWS). Some of the key advantages of using CloudFront over Cloudflare include:

    1. Seamless Integration with AWS Ecosystem: For customers who are already deeply invested in the AWS cloud platform and take advantage of other AWS services, CloudFront can offer a more seamless and integrated experience with easier management and optimization within the broader AWS ecosystem.
    2. Robust Security and Compliance Features: CloudFront integrates with various AWS security services, such as AWS Web Application Firewall (WAF) and AWS Shield, providing comprehensive and customizable security solutions that can meet the needs of enterprises with strict security and compliance requirements.
    3. Scalability and Performance: As part of the AWS global infrastructure, CloudFront can leverage the scale and resources of the AWS network to deliver high-performance content delivery, with the ability to handle sudden spikes in traffic or bandwidth demands.
    4. Developer-Friendly Tools and APIs: CloudFront provides a suite of developer-friendly tools, APIs, and integrations that can simplify the deployment, management, and automation of CDN services, particularly for teams already familiar with the AWS ecosystem and toolset.

    While Cloudflare excels in its ease of use and out-of-the-box functionality, CloudFront may be the preferred choice for organizations that are deeply invested in the AWS platform, have complex security and compliance requirements, or prioritize cost optimization and seamless integration with other AWS services.

    Suggested read: Fixing Redirect Loop on Cloudflare SSL

    4. Imperva

    Imperva is another great alternative to Cloudflare CDN, particularly for customers seeking a more comprehensive, enterprise-grade web application security solution.

    1. Advanced Web Application Firewall (WAF): Imperva’s WAF solution is widely regarded as one of the most robust and feature-rich in the market. It offers advanced threat detection, behavioral analysis, and custom rule-creation capabilities to protect against a wide range of web application vulnerabilities and attacks.
    2. DDoS Mitigation and Bot Management: Imperva’s DDoS protection and bot management capabilities are highly effective in defending against sophisticated, large-scale DDoS attacks and malicious bot activity, providing a higher level of protection than Cloudflare’s standard security offerings.
    3. API Security: Imperva offers comprehensive API security features, including API discovery, monitoring, and protection against API-specific threats, which can be particularly valuable for organizations with a significant API-driven infrastructure.
    4. Compliance and Regulatory Support: Imperva has a strong focus on compliance and regulatory requirements, with features and solutions tailored to help customers meet standards such as PCI DSS, GDPR, and HIPAA, making it a preferred choice for enterprises in highly regulated industries.
    5. Professional Services and Support: Imperva provides a higher level of professional services, technical support, and customer success resources compared to Cloudflare, which can be beneficial for organizations that require more hands-on guidance, customization, and enterprise-level support.

    While Cloudflare is a compelling all-in-one CDN and security solution, Imperva’s specialization in web application security and its enterprise-grade features and support can make it more suitable for organizations with complex security requirements, strict compliance needs, or a strong emphasis on API-driven architectures.

    Suggested read: How To Use Fail2ban With WordPress And Cloudflare Proxy

    5. BunnyCDN

    BunnyCDN is a cost-effective and high-performance CDN that you can use as an alternative to Cloudflare, particularly for small to medium-sized websites and applications. Here’s why BunnyCDN can be a great choice:

    1. Affordable Pricing: BunnyCDN offers very competitive pricing, with a pay-as-you-go model that can be more cost-effective than Cloudflare’s plans, especially for websites with lower traffic or bandwidth requirements.
    2. Excellent Performance: BunnyCDN’s global network of servers is designed for speed, with low latency and fast content delivery that can often match or exceed Cloudflare’s performance.
    3. Ease of Use: BunnyCDN’s user-friendly dashboard and simple setup process make it a great option for users who don’t require advanced features or want to minimize the complexity of managing their CDN.
    4. Scalability: Despite its affordability, BunnyCDN can still handle large traffic spikes and scale to meet the needs of growing websites and applications.
    5. Customization Options: While not as extensive as some enterprise-grade CDNs, BunnyCDN still offers a range of customization options, such as custom caching rules and edge computing features, to fine-tune the CDN to specific requirements.

    6. KeyCDN

    KeyCDN is a well-regarded CDN provider that offers a great alternative to Cloudflare, particularly for users who value performance, simplicity, and cost-effectiveness.

    1. High-Performance Delivery: KeyCDN is known for its fast content delivery and low latency, thanks to its global network of servers and advanced caching mechanisms.
    2. Straightforward Pricing: KeyCDN offers a transparent and straightforward pricing model with no hidden fees or complex tiered plans, making it easy for users to understand and predict their CDN costs.
    3. Ease of Use: KeyCDN’s user-friendly interface and simple setup process make it a great choice for users who want to quickly and easily integrate a CDN into their website or application without the need for extensive technical expertise.
    4. Scalability: While not as large as Cloudflare’s global network, KeyCDN’s infrastructure is still capable of handling significant traffic and bandwidth demands, making it a viable option for growing websites and applications.
    5. Specialized Features: KeyCDN offers some specialized features, such as its image optimization tools and advanced caching controls, that may appeal to users with specific content delivery needs.

    8. Sucuri CDN

    Sucuri CDN is a unique offering that can be used as an alternative to Cloudflare. It is particularly well suited for customers who are primarily focused on web application security and are looking for a more specialized security-focused CDN solution.

    1. Comprehensive Security Features: Sucuri CDN’s core strength lies in its advanced security features, including its web application firewall (WAF), DDoS mitigation, and malware detection capabilities. These features can provide a higher level of protection than Cloudflare’s standard security offerings.
    2. Focused on Security-First Approach: Unlike Cloudflare, which provides a broader range of services, Sucuri CDN focuses solely on web security, allowing it to dedicate more resources and expertise to its security-related features and capabilities.
    3. Managed Security Services: Sucuri CDN offers a range of managed security services, such as website monitoring, incident response, and security consulting, which can be valuable for organizations that lack in-house security expertise or resources.
    4. Compliance and Regulatory Support: Sucuri CDN is designed to help customers meet various compliance and regulatory requirements, such as PCI DSS, HIPAA, and GDPR, making it a suitable choice for organizations operating in highly regulated industries.
    5. Seamless Integration: Sucuri CDN can integrate seamlessly with existing website and application infrastructure, allowing customers to leverage its security features without significantly disrupting their current setup or workflow.

    While Cloudflare provides a more comprehensive set of services, including performance and security features, Sucuri CDN’s laser-focused approach to web application security can make it a more appealing choice for organizations prioritizing robust and specialized security solutions.

    Which Cloudflare Alternative CDN is Right For You?

    When it comes to choosing a Cloudflare alternative CDN, the “right” choice can depend on the user’s or organization’s specific needs and requirements.

    Let’s explore some common use cases and which CDN providers might be the best fit for them:

    Small to Medium-Sized Websites/Bloggers – BunnyCDN

    Small to medium-sized website owners and bloggers often prioritize cost-effectiveness, ease of use, and reliable performance. BunnyCDN’s affordable pricing, straightforward setup, and fast content delivery make it an excellent Cloudflare alternative for this user persona.

    Enterprise-Level Organizations – Akamai

    Enterprises with complex security requirements, high-traffic websites, and the need for advanced features and customization often find Akamai to be a strong Cloudflare alternative. These providers offer enterprise-grade security solutions, scalability, and dedicated support.

    AWS-Centric Businesses – Amazon CloudFront

    For organizations that are deeply invested in the AWS ecosystem and are already leveraging other AWS services, Amazon CloudFront can be a natural Cloudflare alternative. Its seamless integration with the broader AWS platform and cost optimization opportunities make CloudFront a compelling choice.

    Security-Focused Customers – Sucuri CDN, Imperva

    Customers prioritizing robust web application security and compliance may find either Sucuri CDN or Imperva to be better Cloudflare alternatives. These providers offer specialized security features, such as advanced web application firewalls (WAFs) and DDoS mitigation, tailored to meet the needs of security-conscious organizations.

    Developers and Tech-Savvy Users – Fastly, KeyCDN

    Developers and technically inclined users who value customization, performance optimization, and developer-friendly tools may prefer Fastly or KeyCDN as Cloudflare alternatives. These providers offer more granular control, advanced features, and streamlined integration with various development workflows.

    Wrapping Up

    In this post, we have provided a list of the best Cloudflare CDN alternatives for websites. Ultimately, the choice of a Cloudflare alternative CDN should be based on a thorough understanding of the user’s specific needs, such as performance requirements, security concerns, budget, and the level of technical expertise within the organization. By carefully evaluating these factors, users can identify the Cloudflare alternative that best suits their unique needs.

    Ready to optimize your web hosting experience? Try RunCloud!

    RunCloud offers more than just server management – we provide a comprehensive solution that works seamlessly with any CDN provider you choose.

    With RunCloud, you’ll get:

    • Simplified server management and deployment
    • Advanced security features and monitoring
    • One-click SSL certificate installation
    • Automated backups and recovery options
    • 24/7 expert technical support

    Join thousands of satisfied users who trust RunCloud for their web hosting management needs. Sign up for RunCloud today!

    FAQs on Cloudflare

    Can I avoid Cloudflare?

    Yes, you can avoid using Cloudflare. As a content delivery network (CDN) and web security provider, Cloudflare is an optional service that website owners can choose to use or not use, depending on their specific needs and requirements.

    What is faster than Cloudflare?

    Other leading CDN providers, such as Fastly, Akamai, and Amazon CloudFront, may offer faster content delivery and lower latency than Cloudflare in certain regions or use cases, depending on factors like network infrastructure, server locations, and optimization techniques.

    Will Cloudflare make my site faster?

    In many cases, yes. Cloudflare’s global network of servers and caching capabilities can significantly improve website performance by reducing the distance between users and the content they’re accessing, resulting in faster load times. However, the extent of the performance improvement can vary based on factors like your website’s architecture, content, and user base.

    Is GoDaddy better than Cloudflare?

    GoDaddy and Cloudflare provide different services, so it’s not a direct comparison. GoDaddy is a domain registrar and web hosting provider, while Cloudflare is a content delivery network and web security service. Cloudflare may offer better website performance and security features. At the same time, GoDaddy may be a more convenient and all-in-one solution for users who need domain registration, hosting, and basic website management.

    Is Google DNS better than Cloudflare CDN?

    Google DNS and Cloudflare CDN are not directly comparable, as they serve different purposes. Google DNS is a free, public Domain Name System (DNS) resolver, while Cloudflare CDN is a content delivery network and web security provider.

    Is Cloudflare a Chinese company?

    No, Cloudflare is not a Chinese company. Cloudflare is an American company founded in 2009 and headquartered in San Francisco, California. It does not have any known Chinese ownership or affiliation.

    Why is Cloudflare blocking my browser?

    Cloudflare may block or challenge your browser if it detects suspicious or potentially malicious activity, such as a DDoS attack, a high volume of requests from a single IP address, or the use of a VPN or proxy. This is part of Cloudflare’s security measures to protect the websites and applications it serves.

    Has Cloudflare ever been hacked?

    While Cloudflare has a strong security record overall, there have been a few isolated incidents where Cloudflare has experienced security breaches or vulnerabilities. However, the company has a history of being transparent about such incidents and working quickly to address and resolve any issues.

  • How To Upload an Image File In Laravel

    How To Upload an Image File In Laravel

    Whether you’re building a portfolio website, an e-commerce platform, or a social media app, the need to handle user-uploaded images is a common requirement.

    In this comprehensive guide, we’ll explore how to upload an image in Laravel, covering everything from setting up your project to troubleshooting common errors.

    By the end of this guide, you’ll know how to use Laravel’s powerful file storage capabilities to integrate image uploads into your projects seamlessly.

    So, let’s get started!

    How to Upload Images in Laravel

    Follow the steps below to add image upload functionality to your Laravel project.

    1. Setting Up Your Laravel Project for Image Upload

    Setting up the necessary file storage and configuration is important when working with image uploads in a Laravel application. Laravel provides a robust file storage system that allows you to manage file uploads, including images, easily.

    First, you’ll need to configure the file storage driver in your config/filesystems.php file. Laravel supports several storage drivers, such as local, Amazon S3, and others. For this example, we’ll use the local storage driver, which stores the uploaded files in the storage/app/public directory.

    Next, you’ll need to create a symbolic link between the storage/app/public directory and the public/storage directory. This allows the uploaded images to be accessible through the web server. You can create this link by running the php artisan storage:link command in your terminal.

    Upload images in laravel

    Suggested read: Laravel With Git Deployment The Right Way

    2. Creating an Image Upload Form

    After creating the symlink, you’ll need to create a form in your Laravel application’s view to allow users to upload images. This form should include an <input> element of type file to allow users to select the image they want to upload.

    You’ll also need to include the CSRF token in your form, which helps protect your application from cross-site request forgery attacks. You can do this by using the @csrf directive in your Blade template.

    For example, if you want to upload images using the POST method to submit them to the upload.store route, you can use the following code snippet:

    <form action="{{ route('upload.store') }}" method="POST" enctype="multipart/form-data">
        @csrf
        <input type="file" name="image" id="image">
        <button type="submit">Upload</button>
    </form>

    Suggested read: How to Check Laravel Project Version Installed in CMD?

    3. Handling Image Upload in Laravel Controller

    Once the user submits the image upload form, you’ll need to handle the file in your Laravel controller. You can use the $request->file() method to access the uploaded file and then store it using the $request->file()->store() method.

    When storing the file, you can specify the storage disk and the path where you want to save the file. For example, you could save the file in the public/images directory using the following code:

    public function store(Request $request)
    {
        $request->validate([
            'image' => 'required|image|max:2048',
        ]);
        $imagePath = $request->file('image')->store('public/images');
       // Save the image path to the database or perform other actions
        return redirect()->route('upload.create')->with('success', 'Image uploaded successfully.');
    }

    This code snippet first validates the incoming request, ensuring that the image field is required, the file is an image, and the file size is no greater than 2MB. It then stores the uploaded image in the public/images directory using the store() method.

    After storing the file, you can save the file path in your database so that you can later retrieve and display the uploaded image.

    Suggested read: Laravel Octane – What It Is, Why It Matters & Getting Started

    4. Displaying Uploaded Images

    To display the uploaded images, you can use the asset() helper function in your Blade template. This function will generate the appropriate URL for the file based on your application’s configuration.

    For example, if you saved the file in the public/images directory, you can display the image using the following code:

    <img src="{{ asset('storage/images/' . $image->filename) }}" alt="{{ $image->filename }}">

    Suggested read: Setting Up Local WordPress Dev in Minutes Using Laravel Valet

    5. Security Considerations for Image Upload in Laravel

    When handling image uploads in your Laravel application, it’s essential to consider security measures to prevent malicious file uploads and other vulnerabilities.

    1. One important security consideration is file validation. You should always validate the file type, size, and other attributes to ensure that the uploaded file is a valid image and doesn’t exceed your application’s size limits.
    2. Another important security consideration is file path sanitization. To prevent directory traversal attacks, you should always sanitize the file path before storing or displaying the uploaded images.
    3. Finally, you should consider implementing additional security measures, such as restricting file types, scanning uploaded files for malware, and limiting the number of uploads per user or per session.

    Suggested read: How To Optimize Laravel for Performance (8 Expert Tips)

    Troubleshooting Common Errors During Laravel Image Upload

    When working with image uploads in a Laravel application, you may encounter various errors and issues. Let’s explore some common errors and how to troubleshoot them.

    “File Too Large” Error

    One common error that can occur during image uploads is the “File too large” error. This typically happens when the uploaded file exceeds the maximum file size allowed by your server configuration or Laravel application settings.

    To troubleshoot this issue, you should first check your php.ini file and ensure that the upload_max_filesize and post_max_size directives are set to values that accommodate your expected file sizes. You can also check the config/filesystems.php file in your Laravel application and update the max_size option for the relevant disk configuration.

    If the issue persists, you can try adding a specific file size validation rule in your form request:

    $request->validate([
        'image' => 'required|image|max:2048',
    ]);

    This will ensure that the uploaded file is no larger than 2MB (2048 kilobytes).

    Suggested read: The 10 Best PHP Frameworks (Complete Guide)

    “Invalid File Type” Error

    Another common error is the “Invalid file type” error, which occurs when the uploaded file is not a valid image format (e.g., JPG, PNG, GIF).

    To troubleshoot this issue, you should first check the mimes validation rule in your form request:

    $request->validate([
        'image' => 'required|image|mimes:jpeg,png,gif',
    ]);

    This rule ensures that the uploaded file is a valid image and that the file extension matches the specified MIME types (in this case, JPEG, PNG, and GIF).

    If the issue persists, you can also try using the image rule instead of the mimes rule, as the image rule performs more comprehensive validation and ensures that the uploaded file is a valid image, regardless of the file extension:

    $request->validate([
        'image' => 'required|image',
    ]);

    File Ownership and Permissions Issues

    Sometimes, you may encounter issues with file ownership and permissions when trying to upload images. This can happen if your web server doesn’t have the necessary permissions to write to the storage directory.

    To troubleshoot this issue, you should first check the file permissions of the storage/app/public directory (or the directory where you’re storing the uploaded images). Ensure that the web server user (e.g., www-data on Ubuntu, apache on CentOS/RHEL) has write permissions to this directory.

    You can also try running the php artisan storage:link command to create a symbolic link between the storage/app/public directory and the public/storage directory, which can help resolve some permission-related issues.

    Tip: If you are using RunCloud, you can resolve this issue by going to the “Tools” tab and clicking the “Fix Ownership” button.

    fix ownership in runcloud

    Inconsistent Image Display

    If you’re experiencing issues with inconsistently displaying uploaded images, it could be due to caching or a misconfiguration in your application’s routing or asset handling.

    To troubleshoot this, you can try adding a timestamp or a unique query parameter to the image URL when displaying the image in your Blade templates:

    <img src="{{ asset('storage/images/' . $image->filename . '?v=' . $image->updated_at->timestamp) }}" alt="{{ $image->filename }}">

    This will ensure that the browser always fetches the latest version of the image rather than relying on a cached version.

    Additionally, you can check your application’s asset configuration in the config/filesystems.php file and ensure that the correct disk and URL are being used for image storage and retrieval.

    Suggested read: How To Configure LSCache for Laravel (Configuration Guide)

    Wrapping up

    In this guide, we’ve explored the ins and outs of image uploads in Laravel, including:

    • Setting up your project to handle file storage
    • Creating image upload forms
    • Processing uploads in your controllers
    • Displaying the uploaded images

    However, the journey doesn’t end here. As your Laravel application grows, managing the infrastructure and hosting environment becomes increasingly important – this is where RunCloud comes in.

    RunCloud is a powerful and user-friendly platform that simplifies the deployment and management of your Laravel applications. Building and launching your Laravel applications is significantly faster and easier with RunCloud.

    It makes complex server tasks, like setting up servers, managing SSL certificates, and integrating with popular cloud providers both quick and simple. This means spending less time on tedious setup and more time building awesome features for your users.

    Experience the benefits of simplified Laravel hosting.

    Learn more & get started with RunCloud today.

    FAQs on Image Upload in Laravel

    How to Display an Image in Laravel

    To display an uploaded image in your Laravel application, you can use the asset() helper function to generate the appropriate URL for the image. This function will generate the correct URL based on your application’s configuration, even if the image is stored outside the public directory. For example, if you stored an image in th storage/app/public/images directory, you can display it using the following code:

    <img src="{{ asset('storage/images/example.jpg') }}" alt="Example Image">

    How to Upload PDF Files using Laravel

    Uploading PDF files in Laravel is very similar to uploading images. You can use the same file upload process, but you’ll need to adjust the file validation to accept PDF files instead of images.

    For example, you can use the mimes rule in your form request validation to ensure that the uploaded file is a PDF:

    $request->validate([
        'file' => 'required|mimes:pdf',
    ]);

    After the file is uploaded, you can store the file path in your database and display a download link for the PDF in your application.

    How to Put Public Images in Laravel

    To make uploaded images publicly accessible in your Laravel application, you can store them in the public directory instead of the storage/app/public directory.
    First, create a new directory, such as public/images, in your public folder. Then, update your file upload logic to store the images in this directory:

    $imagePath = $request->file('image')->store('images', 'public');

    Finally, you can display the images using the asset() helper function, as you would for any other public asset in your application.

    How to Add Image Validation in Laravel

    To add image validation to your Laravel application, you can use the image rule in your form to request validation. This rule ensures that the uploaded file is a valid image and meets certain criteria, such as file size and MIME type.
    Here’s an example of how you can add image validation to your form request:

    $request->validate([
        'image' => 'required|image|max:2048'
    ]);

    This will ensure that the image field is required, the file is a valid image, and the file size is no larger than 2MB.

    You can also use other validation rules, such as mimes or dimensions, to refine your image validation requirements further.

    How to Get Image Type in Laravel

    To get the type of image uploaded to your Laravel application, you can use the getClientOriginalExtension() method on the UploadedFile object.

    For example, in your controller:

    $image = $request->file('image');
    $imageType = $image->getClientOriginalExtension();

    This will give you the file extension of the uploaded image, which you can then use to determine the image type.
    Alternatively, you can use the getMimeType() method to get the MIME type of the uploaded image:

    $image = $request->file('image');
    $imageMimeType = $image->getMimeType();

    This can be useful for additional validation or processing of the uploaded image

  • How To Install Elasticsearch On RunCloud

    How To Install Elasticsearch On RunCloud

    Elasticsearch is a powerful, open-source search engine and analytics platform for storing, searching, and analyzing large volumes of data in real time.

    It’s critical for many modern applications and services that require fast, efficient search and analytics capabilities.

    Although it is a helpful tool for analytics, Elasticsearch is not installed by default on RunCloud servers because most RunCloud users don’t need it, and having it preinstalled would simply consume resources unnecessarily if not needed.

    But installing Elasticsearch on your server is easy. This article provides a step-by-step guide for installing Elasticsearch on a server managed by RunCloud.

    Let’s get started!

    Connect To Server via SSH

    Before installing Elasticsearch, you should have a server connected to RunCloud. If you don’t have a server, you can follow our tutorial on how to set up a Vultr or AWS server on RunCloud.

    Once your server is up and running, you must log in via SSH to install Elasticsearch. If you already know how to do this, jump to the RunCloud section to install Elasticsearch.

    How To Add Your SSH Key To RunCloud Server

    Once your server is connected to RunCloud, you can create new users and grant them access to log in to the server directly from the dashboard. First, go to the account settings and open your SSH key vault.

    In the key vault, you need to add your public SSH key. You can either use your existing key or generate a new one using the following command:

    ssh-keygen -t rsa
    

    After you add the key, it will appear in the key vault. You can create a new user or add this SSH key to an existing user account on your server.

    We will create a new user account to avoid disturbing files or settings in the existing user’s account. To do this, go to your server settings and open the “System User” tab. In this tab, create a new user with sudo privileges.

    After creating the user, go to your server’s SSH tab and click on the “Add New SSH Key” button to use the key we just added to the vault.

    On the next screen, use the saved key from the SSH key vault and select the user we just created.

    After adding the SSH key, log in to your server by running the following command in your terminal. Before executing the command, add the username, IP address, and path to the private key:

    ssh <username>@<ip address> -i <path to private key>

    Installing Elasticsearch on RunCloud

    When you log in to your server, you will see a large banner saying “RunCloud.” This confirms that your login attempt was successful. All the commands executed in this terminal will run on your server.

    Installing elasticsearch via command line in Linux

    Once you log in to the server, you can copy and paste the following commands into your terminal to import the Elasticsearch PGP Key and install it from the APT repository:

    wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elasticsearch-keyring.gpg
    sudo apt-get install apt-transport-https
    echo "deb [signed-by=/usr/share/keyrings/elasticsearch-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-8.x.list
    sudo apt-get update && sudo apt-get install elasticsearch
    

    A lot of people use Elasticsearch with Kibana, an open source visualization tool. If you want to install Kibana on your system, you can run the following command as well:

    sudo apt-get install kibana

    After the installation is complete, pay close attention to the output displayed. The screen displays the default password for the Elasticsearch account. In the above example, the password is 8RF65T*6cB*Y_rjUDedn.

    If you accidentally closed the screen, you can generate a new password using the following command:

    sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic
    

    Now, you can configure the Elasticsearch service to start automatically when the server reboots, and then start it using the following commands. You can optionally run the fourth command in the following block to check whether the service is up and running correctly:

    sudo systemctl daemon-reload
    sudo systemctl enable elasticsearch.service
    sudo systemctl start elasticsearch.service
    sudo systemctl status elasticsearch.service # Check status

    If you see active (running) status, then your service is configured correctly and you can start using it.

    Testing Elasticsearch

    After installing Elasticsearch you can test the installation by running the following command. If you receive an output similar to the screenshot attached below, then your Elasticsearch installation is working correctly.

    sudo curl --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic https://localhost:9200 
    

    Configuring SSL Certificates For Elasticsearch

    When we tested the Elasticsearch instance, as shown in the above example, we connected using the default certificate which is generated automatically. The connection is encrypted using the http_ca.crt certificate file stored in the /etc/elasticsearch/certs/ directory.

    If you’re not working in a production environment, you can turn off the TLS/SSL on the HTTP networking layer by editing the /etc/elasticsearch/elasticsearch.yml file and setting the xpack.security.http.ssl.enabled to false.

    Generating Certificate Signing Requests for Elasticsearch

    If you are using Elasticsearch in a production environment, there is a good chance that many people will connect to your server, so using a self-signed certificate is not a good idea in such cases.

    If you are part of a large organization, you might already have a certification authority (CA) trusted by all the computers, or you might want to use a commercially available certificate authority. Having a CSR file will make issuing certificates much more manageable in both cases.

    Use the following command to create a certificate signing request. The CLI tool will ask you for basic information, such as your domain name and IP address. Fill out all the necessary fields and optionally secure the certificate with a password:

    sudo /usr/share/elasticsearch/bin/elasticsearch-certutil http

    If you didn’t change the default path of the output file, then your elasticsearch-ssl-http.zip file will be stored in the /usr/share/elasticsearch/ directory.

    Use the following commands to unzip the file and view your certificate signing request. (Don’t forget to update the name of the .csr file to match the filename):

    sudo unzip /usr/share/elasticsearch/elasticsearch-ssl-http.zip
    sudo cat /usr/share/elasticsearch/elasticsearch/<mydomain>.csr

    The above command will show you your certificate request document. You can use this to generate certificates – usually these are .pem or .cer files.

    After you get your certificate from your CA, you can put the certificate and the keys (from the zip folder generated above) in the /etc/elasticsearch/certs/ and update the /etc/elasticsearch/elasticsearch.yml to use your new certificate.

    If you configured a password during the key creation, you must add that to the key vault. You can use the following command to do so:

    sudo /usr/share/elasticsearch/bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password

    For more information, refer to the Elasticsearch documentation.

    Configuring Kibana

    After installing and configuring Elasticsearch, we can start configuring Kibana on your server. First, we’ll ensure Kibana starts automatically after the system reboots and is running. Run the following commands to start the Kibana service and verify that it is running correctly:

    # Start Kibana service
    systemctl start kibana.service
    # Enable Kibana to start on boot
    systemctl enable kibana.service
    # Verify Kibana service status
    systemctl status kibana.service

    In the above example, we can see that the service is up and running correctly. Once you are sure that the service is running as expected, you can start the basic configuration by navigating to the Kibana configuration directory using the following command:

    cd /etc/kibana

    Next, you need to edit the kibana.yml configuration file. If you need help with this, refer to our previous article, in which we explained how to edit files via SSH. Run the following command to open the nano text editor:

    sudo nano /etc/kibana/kibana.yml

    After opening the configuration file, you need to add or modify these essential configurations:

    server.host: "0.0.0.0"
    # Define the port Kibana listens on
    server.port: 5601
    server.publicBaseUrl: "https://kibana.yourdomain.com"

    In this configuration, note the port number you used, as we will need it later. Once you add the configuration, you can save and close the configuration file by pressing Ctrl + X and Enter.

    Next, you need to navigate to the Elasticsearch directory and generate a Kibana enrollment token:

    systemctl restart kibana.service
    cd /usr/share/elasticsearch
    bin/elasticsearch-create-enrollment-token -s kibana

    The above command will produce a long string of text in your terminal; copy it and paste it into a notepad somewhere, as you will need it later. After that, you can execute the following commands to generate a verification code:

    cd /usr/share/kibana
    bin/kibana-verification-code

    The above command will generate a 6-digit code. Write it down, as you will need it in the next step.

    Configure a Proxy service

    After configuring the above settings, you can access your Kibana server by navigating to your server’s IP address on the specified port. However, if you want it to be accessible via a simple domain name, you can configure a Nginx reverse proxy from the RunCloud dashboard.

    We have already written a documentation post about setting up a Proxy from the RunCloud dashboard. When following this guide, edit the pre-populated fields to enter the port number you saved earlier. Once you save the Nginx config, you can access your Kibana dashboard via a URL. After configuring this, you can also consider setting up an SSL certificate for your dashboard.

    Accessing Kibana Dashboard

    Navigate to your web application’s specific URL. If you follow this guide correctly, you will be greeted with a Kibana welcome screen.

    On this screen, you will be asked to enter the authentication token and the six-digit verification code you saved earlier. Once you enter them, Kibana will take a minute or so to initialize everything.

    After your installation is complete, you will be asked to enter the login credentials for the dashboard. You must enter the credentials created during the “Installing Elasticsearch” step. For example, in this tutorial, the username is “elastic” and the password (which was automatically generated) is “8RF65T*6cB*Y_rjUDedn”.

    After entering the login credentials, you should be able to access your Kibana dashboard.

    After Action Report

    Elasticsearch is an essential tool for anyone who needs to store, search, and analyze large volumes of data. By following the article’s step-by-step guide, you can quickly and easily set up Elasticsearch on your RunCloud-managed server and take advantage of its powerful capabilities.

    If you’re tired of managing your own servers – check out RunCloud’s fast, efficient, and visual cloud server management service. RunCloud is built for developers who want to focus on shipping great work, not managing their infrastructure.

    With RunCloud’s user-friendly interface and powerful features, managing your server has never been easier. It offers a painless server configuration, so you don’t need to spend hours figuring it out.

    Get started with RunCloud today and get up and running in minutes.