Xperience.cloud
Setup
[edit]2FA, Multi- oder Zwei-Faktor-Authentifizierung
[edit]For 2FA, Twilio must be Setup to send SMS Text Messages and do automated Voicecalls:
Login
[edit]https://www.twilio.com/console
Ask Sebastian Druschel or David Smith for your user account.
Setup for the xperience.cloud
[edit]Setup a Alpha Sender ID (Showing a Name instead of a Number as SMS Sender)
[edit]Please mind that Alpha Sender ID's does not work global. For Details read here: https://support.twilio.com/hc/en-us/articles/223133767-International-support-for-Alphanumeric-Sender-ID.
- Goto Messaging Services: https://www.twilio.com/console/sms/services
- "Create a Messaging Service", if non exists for your Client. Mind to use our Agentursoftware Common Client Name.
- "Add Senders to Service" and choose "Alpha Sender" as "Sender Type".
- Add your senders name to the "Sender Pool", please mind that there is a max of 11 characters.
- Add one or more Long Code Fallback Senders to your "Sender Pool"
- Choose "Messaging Services"/"Properties" to get the "Messaging Service SID".
- Configure "(Global) Event Settings"/"Twilio (SMS/ Voice) Seetings"/"Alpha Sender ID (Messaging/ Messaging Services/ SID)" in your xperience.cloud Subsite.
- Test!
Cookie Consent Bar
[edit]Setup Usercentrics for the xperience.cloud
[edit]Due to mission Multisite Support, Usercentrics is configured to show a generic Cookie Consent Bar pointing to two relative url's.
- The "Cookies Policy" is pointing to /cookie-policy/
- The "Privacy Policy" is pointing to /privacy/
Due to this relative url's, the link will point to https://{your_sites_url}/cookie-policy/ and https://{your_sites_url}/privacy/. If you have to forward this urls to a different location, e.g. an url or pdf, please use the "Redirection" Plugin:
- Goto "Tools"/"Redirection"
- "Add New"
- "Source URL": /cookie-policy/ or /privacy/
- "Query Parameters": "Exact match all parameters in any order"
- "Target URL": Your Target URL. If you point to an url within your xperience.cloud Subsite, please use a relative url.
- "Group": "Redirections" or something else. Important! All Groups must use "Module" for redirects.
Helpdesk
[edit]Freshdesk
[edit]For the Helpdesk we use Freshdesk. Or a general support email is:
support@xperience.cloud
If your client likes to use an individual support email to address, he can just forward it to the general support email address. Most support cases are email related. We only offer email support to ensure that we can generally communicate with the customer via email.
File:Xperience.cloud-Freshdesk Support.mov
Login
[edit]To login into Freshdesk, use the following URL:
https://xperiencecloud.freshdesk.com
Support can be done by "Agents". Agents are configured here:
https://xperiencecloud.freshdesk.com/a/admin/agents/filter/active
Mind to buy enough "day passes" to give those Agents access.
Tagging
[edit]For later evaluation of the support case, all support requests are adjourned according to the following pattern. If the support case does not fit this pattern, please do not invent new tags, but leave them blank for later evaluation.
Channel
Email, SMS, Browser
Behaviour/Reason
Deliverability/Missing, Fatal system error, Poor Audio/Sound Quality, Usability, Spam, Poor Video/Stream Quality
Usage Scenario
Registration, Login, 2FA, Invitation, Upload, Calendar, Chat
Message Tracking
[edit]The xperience.cloud tracks every message (Email, SMS, Voice) with it's Meta Payload Summary like the Login URL or the 2FA Code. Support Agents can use the Message Tracking Log (Backend/ Tools/ Logs Table) to manually give Users their Payload via his Support Ticket, etc.
File:Xperience.cloud LogsTable.mov
Modules/Components
[edit]Live Components
[edit]Live Components are currently Polls, Wordclouds and Reactions. To get an Idea, how Live Components work, watch this 6 Minutes Video:
File:Xperience.cloud - Live Components 480p.mov
Wp-Rocket
[edit]Mind to enable "WP Rocket | Common Cache For Logged-in Users" Plugin!
WP-Rocket Structure
[edit]Caching Pages and the API. Location is {CONTENTDIR}/cache/wp-rocket/. For debugging the following headers are set (By nginx):
x-rocket-nginx-file: {FILEPATH}
x-rocket-nginx-serving-static: Yes|No
x-rocket-nginx-reason: {DESCRIPTION}
The following API Calls are cached in the wp-json directory
/wp-json/calendar/v1/ ?wpnonce & ?post
Holding the users personal calendar including his bookmarks.
/wp-json/chat/v1/ ?wpnonce & ?post
Holding the users chattrooms, his role, chatusers, ...
/wp-json/directory/v1/ ?wpnonce
Holding the userdirectory used for the chatbar.
/wp-json/users/v1/ ?wpnonce & ?pos
Holding the userstatus, permission, ...
WP-Rocket Config
[edit]/WP-Rocket/Cache/Enable caching for logged-in WordPress users = True
/WP-Rocket/Cache/Cache Lifespan = 24h
/WP-Rocket/Media/Emoji = True
/WP-Rocket/Preload Cache/Activate Preloading = True
/WP-Rocket/Preload Cache/Prefetch DNS Requests
//aggregator.service.usercentrics.eu //jax.cloudflare.com //api.usercentrics.eu //app.usercentrics.eu //directions.here-events.com //fonts.gstatic.com //graphql.usercentrics.eu //tsock.us1.twilio.com //www-live.xperience.cloud //www.google.com //www.gstatic.com
/WP-Rocket/Preload Cache/Preload Fonts
/platform-content/themes/here-2020/fonts/subset-FiraGO-Book.woff2 /platform-content/themes/here-2020/fonts/subset-FiraGO-Medium.woff2 /platform-content/themes/here-2020/fonts/subset-FiraGO-Bold.woff2 /platform-content/themes/here-2020/fonts/subset-FiraGO-Light.woff2
/WP-Rocket/Advanced Rules/Cache Query String(s) post token short_token type recipient
/WP-Rocket/Heartbeat/Control Heartbeat = True
/WP-Rocket/Heartbeat/Reduce or disable Heartbeat activity = Reduce activity
/WP-Rocket/Add-ons/Cloudflare = True
/WP-Rocket/Add-ons/Cloudflare/Cloudflare credentials
Account email: admin@xperience.cloud Zone ID: f9de33b70adc80d98ca3269f5f1db69e
/WP-Rocket/Add-ons/Cloudflare/Cloudflare settings/Optimal settings = True
/WP-Rocket/Add-ons/Cloudflare/Cloudflare settings/Relative protocol = True
Streaming
[edit]3Q Streaming Provider
[edit]Generell kann die xperience.cloud mit jedem Streaming Provider streamen und jedes VOD Format integrieren.
Gute Erfahrung für das Live Video Streaming in Europa haben wir mit 3Q erzieht.
Setup
[edit]"Video Livestream" Projekt anlegen. Folgende Parameter sind wichtig:
Eingangssignal/Stream Typ
[edit]| RTMP PUSH von Ihrem Encoder | Der normale RTMP Stream aus bsp. OBC oder Wirecast. |
| RTMP PUSH von Ihrem Encoder mit Low-Latency | "Low-Latency" bezieht sich auf den Wiedergabe Puffer, das Video hat also weniger Latenz beim User. Zwischen Aufnahme und Wiedergabe liegt also weniger Zeit. Dies kann insbesondere bei Live Interaktionen (Chat, Live Components, ...) wichtig sein. |
| SRT | Sofern möglich unterstützt 3Q auch SRT. |
Billing Template (Streaming)
[edit]| EUR | ||
|---|---|---|
| Live Video Streaming Setup | EUR 200,00 | Event |
| Transcoding/ Minute (6 Auto-Transcoder) | EUR 0,04 | Minute |
| Bandwidth/ GB | EUR 0,10 | GB |
| Handlingfee Live Streaming | 10% |
Billing Template (VOD)
[edit]| EUR | Einheit | |
|---|---|---|
| Bandwidth/ GB | EUR 0,10 | GB |
| Storage | EUR ?? | GB |
| Encoding | EUR ?? | Minute |
Hosting
[edit]AWS
[edit]Server
[edit]Preview Server
[edit]Preview/Development Server
Stage Server
[edit]stage.xperience.cloud
Live Server(s)
[edit]All Live Servers live on AWS.
service.xperience.cloud
[edit]Doing service jobs like gearman.
matomo.xperience.cloud
[edit]Hosting the matomo Logfile analyser for "transparent", cookie free analytics.
Loadbalancer/ Autoscaler
[edit]Here you edit the current, minimum and maximum EC2 Webservers Instances:
Please Mind, there are running at least 2, one BASE and one of the x Autoscale Images.
Cloudflare
[edit]Cloudflare Debugging
[edit]Cloudflare caches all img, js, css, ... Files. Version Strings are important here to invalidate old code. For debugging the following headers are set (By Cloudflare):
cf-cache-status: {DESCRIPTION}
| {DESCRIPTION} | Description |
|---|---|
| HIT | Your resource was found in Cloudflare’s cache. This means that it has been previously accessed from your original server and loaded into Cache. It has all not expired. |
| MISS | Cloudflare looked for your resource in cache but did not find it. Cloudflare went back to your origin server to retrieve the resource. The next time this resource is accessed its status should be HIT. |
| BYPASS | Cloudflare has been instructed to not cache this asset. It has been served directly from the origin. This is usually because something like a existing NO-CACHE header is being respected. |
| EXPIRED | Cloudflare has previously retrieved this resource, but it’s cache has expired. Cloudflare will go back to the origin to retrieve this resource again. The next this resource is access its status should be HIT. |
| DYNAMIC | This resource is not cached by default and there are no explicit settings configured to cache it. You will see this frequently when Cloudflare is handling a POST request. This request will always go to the origin. |
Mandatory Settings
[edit]SSL-TLS
[edit]Edge Certificates
[edit]Always Use HTTPS
[edit]Redirect all requests with scheme “http” to “https”. This applies to all http requests to the zone.
Mandatory: On
HTTP Strict Transport Security (HSTS)
[edit]Enforce web security policy for your website.
Mandatory: On with the following settings:
Enable HSTS (Strict-Transport-Security)
Serve HSTS headers with all HTTPS requests
Mandatory: On
Max Age Header (max-age)
Specify the duration HSTS headers are cached in browsers
Mandatory: 6 Months
No-Sniff Header
Send the “X-Content-Type-Options: nosniff” header to prevent Internet Explorer and Google Chrome from MIME-sniffing away from the declared Content-Type.
Mandatory: On
Minimum TLS Version
[edit]Only allow HTTPS connections from visitors that support the selected TLS protocol version or newer.
Mandatory: 1.2
Opportunistic Encryption
[edit]Opportunistic Encryption allows browsers to benefit from the improved performance of HTTP/2 by letting them know that your site is available over an encrypted connection. Browsers will continue to show “http” in the address bar, not “https”.
Mandatory: On
TLS 1.3
[edit]Enable the latest version of the TLS protocol for improved security and performance.
Mandatory: On
Automatic HTTPS Rewrites
[edit]Automatic HTTPS Rewrites helps fix mixed content by changing “http” to “https” for all resources or links on your web site that can be served with HTTPS.
Mandatory: On
Recommended Settings
[edit]xperience.cloud Cloudflare Settings
[edit]To use Cloudflare's CDN, enable /Page Rules/ (Mind the Order!)
1. *.{url}/wp-json/* > Cache Level: Bypass
2. *.{url}/wp-admin/* > Cache Level: Bypass
3. *.{url}/* > Cache Level: Cache Everything
Formidable Forms
[edit]Mind to change
General Setting/Load form styling
to "only on applicable pages" or "Don't use form styling on any page"
Gearman (Parallel worker execution)
[edit]The xperience.cloud runs a parallel worker execution service using http://gearman.org
Enviroment
[edit]Stage and Live-Servers are using separate Gearman instances.
Stage
[edit]The Stage Servers Gearman is configured as "GEARMAN_SERVER" in the .env file and is pointing to
GEARMAN_SERVER = ip-172-31-34-64.eu-central-1.compute.internal
what is the private DNS for the Stage-Server himself.
Prod
[edit]The Prod Servers Gearman is configured as "GEARMAN_SERVER" in the .env file and is pointing to
GEARMAN_SERVER = ip-172-31-27-199.eu-central-1.compute.internal
what is the service.xperience.cloud EC2 Instances private DNS.
Worker
[edit]Gearman Jobs are called "Worker". The workers are located in "/gearman/jobs/" and will be initialised by "gearman/worker.php".
New Worker Code / Restarting the Workers
[edit]To use new code, you have to restart the workers. You can restart the workers by just killing them using
sudo pkill -f worker.php
on the corresponding gearman machine.
Logging
[edit]The Gearman Worker's php code should log into the syslog ("/var/log/syslog"). The Gearman Job Server itself is logging into his own log at "/var/log/gearman-job-server/gearmand.log". To watch your Gearman Jobs running or debug them, you can use<syntaxhighlight lang="shell"> sudo tail -f /var/log/syslog /var/log/php7.3-fpm.log /var/log/gearman-job-server/gearmand.log </syntaxhighlight>
Using
[edit]You can use the Gearman worker in your code by adding a new Client <syntaxhighlight lang="php" line="1"> $client = new GearmanClient(); $client->addServer(getenv('GEARMAN_SERVER')); </syntaxhighlight> and sending your payload to it <syntaxhighlight lang="php" line="1"> $result = $client->doBackground('send_twilio_sms_or_voice', json_encode(array(
"meta" => array(
'twilio_number_voice' => $phone_from_voice
),
"data" => array(
'phone_to' => $telephone,
'phone_type' => 'voice',
'phone_body' => $phone_body
)
))); </syntaxhighlight> Please mind, that Gearman workers do not give an execution result.
Current Workers
[edit]There are two workers for
- Sending (RAW) Emails via Amazon AWS / SES (gearman/jobs/send_aws_ses.php)
- Sending SMS and doing Voicecalls via Twilio (gearman/jobs/send_twilio_sms_or_voice.php)
Performance Log
[edit]| AWS/ EFS (MiB/Sek) | AWS/ RDS | AWS/ ElastiCache/ Redis | AWS/ EC2 | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Event-Datum | Event-Name | ca. Teilnhemer | Bereitgestellt | Max. Auslastung | Bereitgestellt | Max. Auslastung (CPU) | Bereitgestellt | Max. Auslastung (CPU) | Bereitgestellt | Max. Auslastung (CPU) | xpcl.service. | xpcl.matomo. |
| StandBy Config | 50 MiB/s | db.m6g.large | cache.t2.small | 2 * c5.2xlarge | ||||||||
| 20.01.2020 | https://www.brandsummit2021.com | 2.500 | 100 MiB/s | 6% | db.m5.xlarge | 1% | cache.t2.small | 16% | 4 * c5.2xlarge | 8% | 3,7% | 60% (Fixed with "Number of requests that are processed in one batch: 150") |
| 09.02.2021 | https://mitgeredet.schalke04.de | 3*1.000 | ||||||||||