Skip to content

Instantly share code, notes, and snippets.

@nowthatsamatt
Created January 25, 2012 16:42
Show Gist options
  • Select an option

  • Save nowthatsamatt/1677162 to your computer and use it in GitHub Desktop.

Select an option

Save nowthatsamatt/1677162 to your computer and use it in GitHub Desktop.
rails_env = ENV['RAILS_ENV'] || 'production'
#worker_processes (rails_env == 'production' ? 2 : 2)
worker_processes 4
# Load app into memory for super fast worker spawns
preload_app true
# Restart any workers that haven't responded in 30 seconds
timeout 30
# Listen on a Unix data socket
listen '/etc/unicorn/hecklersports_unicorn.sock', :backlog => 2048
# Set pid location to Capistrano / Rails default
pid '/var/run/hecklersports_unicorn.pid'
# Setup logging paths
stderr_path '/var/log/unicorn/hecklersports_error.log'
stdout_path '/var/log/unicorn/hecklersports_access.log'
working_directory '/srv/heckler/current'
before_fork do |server, worker|
##
# When sent a USR2, Unicorn will suffix its pidfile with .oldbin and
# immediately start loading up a new version of itself (loaded with a new
# version of our app). When this new Unicorn is completely loaded
# it will begin spawning workers. The first worker spawned will check to
# see if an .oldbin pidfile exists. If so, this means we've just booted up
# a new Unicorn and need to tell the old one that it can now die. To do so
# we send it a QUIT.
#
# Using this method we get 0 downtime deploys.
old_pid = '/var/run/hecklersports_unicorn.pid.oldbin'
if File.exists?(old_pid) && server.pid != old_pid
begin
Process.kill("QUIT", File.read(old_pid).to_i)
rescue Errno::ENOENT, Errno::ESRCH
# someone else did our job for us
end
end
end
after_fork do |server, worker|
##
# Unicorn master loads the app then forks off workers - because of the way
# Unix forking works, we need to make sure we aren't using any of the parent's
# sockets, e.g. db connection
ActiveRecord::Base.establish_connection
# Redis and Memcached would go here but their connections are established
# on demand, so the master never opens a socket
##
# Unicorn master is started as root, which is fine, but let's
# drop the workers to ubuntu:ubuntu
begin
uid, gid = Process.euid, Process.egid
user, group = 'ubuntu', 'ubuntu'
target_uid = Etc.getpwnam(user).uid
target_gid = Etc.getgrnam(group).gid
worker.tmp.chown(target_uid, target_gid)
if uid != target_uid || gid != target_gid
Process.initgroups(user, target_gid)
Process::GID.change_privilege(target_gid)
Process::UID.change_privilege(target_uid)
end
rescue => e
if RAILS_ENV == 'development'
STDERR.puts "couldn't change user, oh well"
else
raise e
end
end
end
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment