Jump to content

Xperience.cloud

From Parasol

Setup

[edit]

2FA, Multi- oder Zwei-Faktor-Authentifizierung

[edit]

For 2FA, Twilio must be Setup to send SMS Text Messages and do automated Voicecalls:

Login

[edit]

https://www.twilio.com/console

Ask Sebastian Druschel or David Smith for your user account.

Setup for the xperience.cloud

[edit]

Setup a Alpha Sender ID (Showing a Name instead of a Number as SMS Sender)

[edit]

Please mind that Alpha Sender ID's does not work global. For Details read here: https://support.twilio.com/hc/en-us/articles/223133767-International-support-for-Alphanumeric-Sender-ID.

  1. Goto Messaging Services: https://www.twilio.com/console/sms/services
  2. "Create a Messaging Service", if non exists for your Client. Mind to use our Agentursoftware Common Client Name.
  3. "Add Senders to Service" and choose "Alpha Sender" as "Sender Type".
  4. Add your senders name to the "Sender Pool", please mind that there is a max of 11 characters.
  5. Add one or more Long Code Fallback Senders to your "Sender Pool"
  6. Choose "Messaging Services"/"Properties" to get the "Messaging Service SID".
  7. Configure "(Global) Event Settings"/"Twilio (SMS/ Voice) Seetings"/"Alpha Sender ID (Messaging/ Messaging Services/ SID)" in your xperience.cloud Subsite.
  8. Test!
[edit]

Setup Usercentrics for the xperience.cloud

[edit]

Due to mission Multisite Support, Usercentrics is configured to show a generic Cookie Consent Bar pointing to two relative url's.

  1. The "Cookies Policy" is pointing to /cookie-policy/
  2. The "Privacy Policy" is pointing to /privacy/

Due to this relative url's, the link will point to https://{your_sites_url}/cookie-policy/ and https://{your_sites_url}/privacy/. If you have to forward this urls to a different location, e.g. an url or pdf, please use the "Redirection" Plugin:

  1. Goto "Tools"/"Redirection"
  2. "Add New"
  3. "Source URL": /cookie-policy/ or /privacy/
  4. "Query Parameters": "Exact match all parameters in any order"
  5. "Target URL": Your Target URL. If you point to an url within your xperience.cloud Subsite, please use a relative url.
  6. "Group": "Redirections" or something else. Important! All Groups must use "Module" for redirects.

Helpdesk

[edit]

Freshdesk

[edit]

For the Helpdesk we use Freshdesk. Or a general support email is:

support@xperience.cloud

If your client likes to use an individual support email to address, he can just forward it to the general support email address. Most support cases are email related. We only offer email support to ensure that we can generally communicate with the customer via email.

File:Xperience.cloud-Freshdesk Support.mov

Login

[edit]

To login into Freshdesk, use the following URL:

https://xperiencecloud.freshdesk.com

Support can be done by "Agents". Agents are configured here:

https://xperiencecloud.freshdesk.com/a/admin/agents/filter/active

Mind to buy enough "day passes" to give those Agents access.

Tagging

[edit]

For later evaluation of the support case, all support requests are adjourned according to the following pattern. If the support case does not fit this pattern, please do not invent new tags, but leave them blank for later evaluation.

Channel

Email, SMS, Browser

Behaviour/Reason

Deliverability/Missing, Fatal system error, Poor Audio/Sound Quality, Usability, Spam, Poor Video/Stream Quality

Usage Scenario

Registration, Login, 2FA, Invitation, Upload, Calendar, Chat

Message Tracking

[edit]

The xperience.cloud tracks every message (Email, SMS, Voice) with it's Meta Payload Summary like the Login URL or the 2FA Code. Support Agents can use the Message Tracking Log (Backend/ Tools/ Logs Table) to manually give Users their Payload via his Support Ticket, etc.


File:Xperience.cloud LogsTable.mov

Modules/Components

[edit]

Live Components

[edit]

Live Components are currently Polls, Wordclouds and Reactions. To get an Idea, how Live Components work, watch this 6 Minutes Video:

File:Xperience.cloud - Live Components 480p.mov

Wp-Rocket

[edit]

Mind to enable "WP Rocket | Common Cache For Logged-in Users" Plugin!

WP-Rocket Structure

[edit]

Caching Pages and the API. Location is {CONTENTDIR}/cache/wp-rocket/. For debugging the following headers are set (By nginx):

x-rocket-nginx-file: {FILEPATH} 
x-rocket-nginx-serving-static: Yes|No
x-rocket-nginx-reason: {DESCRIPTION}

The following API Calls are cached in the wp-json directory

/wp-json/calendar/v1/ ?wpnonce & ?post

Holding the users personal calendar including his bookmarks.

/wp-json/chat/v1/ ?wpnonce & ?post

Holding the users chattrooms, his role, chatusers, ...

/wp-json/directory/v1/ ?wpnonce

Holding the userdirectory used for the chatbar.

/wp-json/users/v1/ ?wpnonce & ?pos

Holding the userstatus, permission, ...

WP-Rocket Config

[edit]

/WP-Rocket/Cache/Enable caching for logged-in WordPress users = True

/WP-Rocket/Cache/Cache Lifespan = 24h

/WP-Rocket/Media/Emoji = True

/WP-Rocket/Preload Cache/Activate Preloading = True

/WP-Rocket/Preload Cache/Prefetch DNS Requests

//aggregator.service.usercentrics.eu 
//jax.cloudflare.com 
//api.usercentrics.eu 
//app.usercentrics.eu 
//directions.here-events.com 
//fonts.gstatic.com 
//graphql.usercentrics.eu 
//tsock.us1.twilio.com 
//www-live.xperience.cloud 
//www.google.com 
//www.gstatic.com

/WP-Rocket/Preload Cache/Preload Fonts

/platform-content/themes/here-2020/fonts/subset-FiraGO-Book.woff2 
/platform-content/themes/here-2020/fonts/subset-FiraGO-Medium.woff2 
/platform-content/themes/here-2020/fonts/subset-FiraGO-Bold.woff2 
/platform-content/themes/here-2020/fonts/subset-FiraGO-Light.woff2

/WP-Rocket/Advanced Rules/Cache Query String(s) post token short_token type recipient

/WP-Rocket/Heartbeat/Control Heartbeat = True

/WP-Rocket/Heartbeat/Reduce or disable Heartbeat activity = Reduce activity

/WP-Rocket/Add-ons/Cloudflare = True

/WP-Rocket/Add-ons/Cloudflare/Cloudflare credentials

Account email: admin@xperience.cloud
Zone ID: f9de33b70adc80d98ca3269f5f1db69e

/WP-Rocket/Add-ons/Cloudflare/Cloudflare settings/Optimal settings = True

/WP-Rocket/Add-ons/Cloudflare/Cloudflare settings/Relative protocol = True

Streaming

[edit]

3Q Streaming Provider

[edit]

Generell kann die xperience.cloud mit jedem Streaming Provider streamen und jedes VOD Format integrieren.

Gute Erfahrung für das Live Video Streaming in Europa haben wir mit 3Q erzieht.

Setup
[edit]

"Video Livestream" Projekt anlegen. Folgende Parameter sind wichtig:

Eingangssignal/Stream Typ
[edit]
RTMP PUSH von Ihrem Encoder Der normale RTMP Stream aus bsp. OBC oder Wirecast.
RTMP PUSH von Ihrem Encoder mit Low-Latency "Low-Latency" bezieht sich auf den Wiedergabe Puffer, das Video hat also weniger Latenz beim User. Zwischen Aufnahme und Wiedergabe liegt also weniger Zeit. Dies kann insbesondere bei Live Interaktionen (Chat, Live Components, ...) wichtig sein.
SRT Sofern möglich unterstützt 3Q auch SRT.

Billing Template (Streaming)

[edit]
EUR
Live Video Streaming Setup EUR 200,00 Event
Transcoding/ Minute (6 Auto-Transcoder) EUR 0,04 Minute
Bandwidth/ GB EUR 0,10 GB
Handlingfee Live Streaming 10%

Billing Template (VOD)

[edit]
EUR Einheit
Bandwidth/ GB EUR 0,10 GB
Storage EUR ?? GB
Encoding EUR ?? Minute

Hosting

[edit]

AWS

[edit]

Server

[edit]

Preview Server

[edit]

Preview/Development Server

Stage Server

[edit]

stage.xperience.cloud

Live Server(s)

[edit]

All Live Servers live on AWS.

service.xperience.cloud
[edit]

Doing service jobs like gearman.

matomo.xperience.cloud
[edit]

Hosting the matomo Logfile analyser for "transparent", cookie free analytics.

Loadbalancer/ Autoscaler

[edit]

Here you edit the current, minimum and maximum EC2 Webservers Instances:

https://eu-central-1.console.aws.amazon.com/ec2autoscaling/home?region=eu-central-1#/details/autoscale-group-deb10?view=details

Please Mind, there are running at least 2, one BASE and one of the x Autoscale Images.

Cloudflare

[edit]

Cloudflare Debugging

[edit]

Cloudflare caches all img, js, css, ... Files. Version Strings are important here to invalidate old code. For debugging the following headers are set (By Cloudflare):

cf-cache-status: {DESCRIPTION}
{DESCRIPTION} Description
HIT Your resource was found in Cloudflare’s cache. This means that it has been previously accessed from your original server and loaded into Cache. It has all not expired.
MISS Cloudflare looked for your resource in cache but did not find it. Cloudflare went back to your origin server to retrieve the resource. The next time this resource is accessed its status should be HIT.
BYPASS Cloudflare has been instructed to not cache this asset. It has been served directly from the origin. This is usually because something like a existing NO-CACHE header is being respected.
EXPIRED Cloudflare has previously retrieved this resource, but it’s cache has expired. Cloudflare will go back to the origin to retrieve this resource again. The next this resource is access its status should be HIT.
DYNAMIC This resource is not cached by default and there are no explicit settings configured to cache it. You will see this frequently when Cloudflare is handling a POST request. This request will always go to the origin.

Mandatory Settings

[edit]

SSL-TLS

[edit]

Edge Certificates

[edit]
Always Use HTTPS
[edit]

Redirect all requests with scheme “http” to “https”. This applies to all http requests to the zone.

Mandatory: On

HTTP Strict Transport Security (HSTS)
[edit]

Enforce web security policy for your website.

Mandatory: On with the following settings:

Enable HSTS (Strict-Transport-Security)
Serve HSTS headers with all HTTPS requests

Mandatory: On

Max Age Header (max-age)
Specify the duration HSTS headers are cached in browsers

Mandatory: 6 Months

No-Sniff Header
Send the “X-Content-Type-Options: nosniff” header to prevent Internet Explorer and Google Chrome from MIME-sniffing away from the declared Content-Type.

Mandatory: On

Minimum TLS Version
[edit]

Only allow HTTPS connections from visitors that support the selected TLS protocol version or newer.

Mandatory: 1.2

Opportunistic Encryption
[edit]

Opportunistic Encryption allows browsers to benefit from the improved performance of HTTP/2 by letting them know that your site is available over an encrypted connection. Browsers will continue to show “http” in the address bar, not “https”.

Mandatory: On

TLS 1.3
[edit]

Enable the latest version of the TLS protocol for improved security and performance.

Mandatory: On

Automatic HTTPS Rewrites
[edit]

Automatic HTTPS Rewrites helps fix mixed content by changing “http” to “https” for all resources or links on your web site that can be served with HTTPS.

Mandatory: On

[edit]

xperience.cloud Cloudflare Settings

[edit]

To use Cloudflare's CDN, enable /Page Rules/ (Mind the Order!)

1. *.{url}/wp-json/* > Cache Level: Bypass
2. *.{url}/wp-admin/* > Cache Level: Bypass
3. *.{url}/* > Cache Level: Cache Everything

Formidable Forms

[edit]

Mind to change

General Setting/Load form styling

to "only on applicable pages" or "Don't use form styling on any page"

Gearman (Parallel worker execution)

[edit]

The xperience.cloud runs a parallel worker execution service using http://gearman.org

Enviroment
[edit]

Stage and Live-Servers are using separate Gearman instances.

Stage
[edit]

The Stage Servers Gearman is configured as "GEARMAN_SERVER" in the .env file and is pointing to

GEARMAN_SERVER = ip-172-31-34-64.eu-central-1.compute.internal

what is the private DNS for the Stage-Server himself.

Prod
[edit]

The Prod Servers Gearman is configured as "GEARMAN_SERVER" in the .env file and is pointing to

GEARMAN_SERVER = ip-172-31-27-199.eu-central-1.compute.internal

what is the service.xperience.cloud EC2 Instances private DNS.

Worker
[edit]

Gearman Jobs are called "Worker". The workers are located in "/gearman/jobs/" and will be initialised by "gearman/worker.php".

New Worker Code / Restarting the Workers
[edit]

To use new code, you have to restart the workers. You can restart the workers by just killing them using

sudo pkill -f worker.php

on the corresponding gearman machine.

Logging
[edit]

The Gearman Worker's php code should log into the syslog ("/var/log/syslog"). The Gearman Job Server itself is logging into his own log at "/var/log/gearman-job-server/gearmand.log". To watch your Gearman Jobs running or debug them, you can use<syntaxhighlight lang="shell"> sudo tail -f /var/log/syslog /var/log/php7.3-fpm.log /var/log/gearman-job-server/gearmand.log </syntaxhighlight>

Using
[edit]

You can use the Gearman worker in your code by adding a new Client <syntaxhighlight lang="php" line="1"> $client = new GearmanClient(); $client->addServer(getenv('GEARMAN_SERVER')); </syntaxhighlight> and sending your payload to it <syntaxhighlight lang="php" line="1"> $result = $client->doBackground('send_twilio_sms_or_voice', json_encode(array(

   "meta" => array(
       'twilio_number_voice' => $phone_from_voice
   ),
   "data" => array(
       'phone_to' => $telephone,
       'phone_type' => 'voice',
       'phone_body' => $phone_body
   )

))); </syntaxhighlight> Please mind, that Gearman workers do not give an execution result.

Current Workers
[edit]

There are two workers for

  • Sending (RAW) Emails via Amazon AWS / SES (gearman/jobs/send_aws_ses.php)
  • Sending SMS and doing Voicecalls via Twilio (gearman/jobs/send_twilio_sms_or_voice.php)

Performance Log

[edit]
AWS/ EFS (MiB/Sek) AWS/ RDS AWS/ ElastiCache/ Redis AWS/ EC2
Event-Datum Event-Name ca. Teilnhemer Bereitgestellt Max. Auslastung Bereitgestellt Max. Auslastung (CPU) Bereitgestellt Max. Auslastung (CPU) Bereitgestellt Max. Auslastung (CPU) xpcl.service. xpcl.matomo.
StandBy Config 50 MiB/s db.m6g.large cache.t2.small 2 * c5.2xlarge
20.01.2020 https://www.brandsummit2021.com 2.500 100 MiB/s 6% db.m5.xlarge 1% cache.t2.small 16% 4 * c5.2xlarge 8% 3,7% 60% (Fixed with "Number of requests that are processed in one batch: 150")
09.02.2021 https://mitgeredet.schalke04.de 3*1.000