Difference between revisions of "Tomcat"

Line 39: Line 39:
  
 
=Server configuration=  
 
=Server configuration=  
 
 
==Create users and user-rights==
 
Manual installation
 
<syntaxhighlight lang="bash">
 
vim /opt/tomcat/conf/tomcat-users.xml
 
</syntaxhighlight>
 
 
Automatic installation
 
<syntaxhighlight lang="bash">
 
vim /etc/tomcat7/tomcat-users.xml
 
</syntaxhighlight>
 
 
 
Add / uncomment:
 
<syntaxhighlight lang="bash">
 
<role rolename="manager" />
 
<role rolename="admin" />
 
<role rolename="manager-gui" />
 
<role rolename="manager-script" />
 
<role rolename="admin-gui" />
 
 
<user username="tomcat" password="password"  roles="admin, admin-gui, manager, manager-gui, manager-script" />
 
</syntaxhighlight>
 
 
 
 
==Increase permgen space==
 
 
===Manual install===
 
Add JAVA_OPTS parameters as environment variable
 
<syntaxhighlight lang="bash">
 
vim /etc/profile
 
</syntaxhighlight>
 
 
Add following line:
 
<syntaxhighlight lang="bash">
 
export JAVA_OPTS="-Xms1024m -Xmx1024m -XX:NewSize=256m -XX:MaxNewSize=256m -XX:PermSize=256m -XX:MaxPermSize=512m -XX:+DisableExplicitGC"
 
</syntaxhighlight>
 
 
Take changes into account
 
<syntaxhighlight lang="bash">
 
source /etc/profile
 
</syntaxhighlight>
 
 
Check changes
 
<syntaxhighlight lang="bash">
 
echo $JAVA_OPTS
 
</syntaxhighlight>
 
 
 
===Automatic install===
 
 
<syntaxhighlight lang="bash">
 
vim /etc/default/tomcat7
 
</syntaxhighlight>
 
 
Add following line:
 
<syntaxhighlight lang="bash">
 
JAVA_OPTS="-server -Djava.awt.headiless=true -XX:+UseConcMarkSweepGC -XX:+CMSIncrementalMode -XX:+CMSPermGenSweepingEnabled -XX:+CMSClassUnloadingEnabled"
 
JAVA_OPTS="${JAVA_OPTS} -Xms256m -Xmx2048m"
 
JAVA_OPTS="${JAVA_OPTS} -XX:NewSize=128m -XX:MaxNewSize=256m"
 
</syntaxhighlight>
 
 
Take changes into account
 
<syntaxhighlight lang="bash">
 
service tomcat7 restart
 
</syntaxhighlight>
 
 
 
==Add UTF-8 support on Tomcat==
 
By default Tomcat will rely on the O.S locale.
 
 
In order to support UTF-8 URLs, you’ve to manually update the server’s configuration.
 
* automatic install: $Tomcat = /etc/tomcat7
 
 
<syntaxhighlight lang="bash">
 
vim $TOMCAT/conf/server.xml
 
</syntaxhighlight>
 
 
~ Line 70 change the “<connector port=”8080” …” value.
 
 
*Before
 
<syntaxhighlight lang="bash">
 
<Connector port="8080" protocol="HTTP/1.1"
 
              connectionTimeout="20000"
 
              redirectPort="8443" />
 
</syntaxhighlight>
 
 
*After
 
<syntaxhighlight lang="bash">
 
<Connector port="8080" protocol="HTTP/1.1"
 
              connectionTimeout="20000"
 
              redirectPort="8443" URIEncoding="UTF-8" />
 
</syntaxhighlight>
 
 
 
Restart Tomcat server
 
<syntaxhighlight lang="bash">
 
service tomcat7 restart
 
</syntaxhighlight>
 
 
  
  
Line 164: Line 62:
 
</multipart-config>  
 
</multipart-config>  
 
</syntaxhighlight>
 
</syntaxhighlight>
 
 
 
=add JMX management=
 
 
Tomcat can be remotely monitored through JMX.
 
That’s useful to check the status of the server: memory, threads and processes, performances, etc.
 
 
 
==Restricted access configuration==
 
You should restrict the JMX access.
 
 
Create the JMX users rights
 
<syntaxhighlight lang="bash">
 
vim /var/lib/tomcat7/conf/jmxremote.access 
 
</syntaxhighlight>
 
 
Put the following
 
<syntaxhighlight lang="bash">
 
monitorRole readonly → replace monitorRole by your ''userName''
 
controlRole readwrite 
 
</syntaxhighlight>
 
 
Create the JMX users password
 
<syntaxhighlight lang="bash">
 
vim /var/lib/tomcat7/conf/jmxremote.password
 
</syntaxhighlight>
 
 
Put the following
 
<syntaxhighlight lang="bash">
 
monitorRole tomcat         → replace monitorRole by username | replace tomcat by password
 
controlRole tomcat
 
</syntaxhighlight>
 
 
Set rights and permissions upon login files
 
<syntaxhighlight lang="bash">
 
chmod 600 /var/lib/tomcat7/conf/jmxremote.*
 
chown tomcat7:tomcat7 /var/lib/tomcat7/conf/jmxremote.*
 
</syntaxhighlight>
 
 
==Tomcat launcher configuration==
 
 
Just edit your default Tomcat launcher:
 
<syntaxhighlight lang="bash">
 
vim /etc/default/tomcat7
 
</syntaxhighlight>
 
 
Add the following lines:
 
<syntaxhighlight lang="bash">
 
JAVA_HOME=/usr/lib/jvm/default-jvm/           → That must be the ORACLE JDK
 
 
# JMX configuration
 
JAVA_OPTS="${JAVA_OPTS} -Dcom.sun.management.jmxremote"
 
JAVA_OPTS="${JAVA_OPTS} -Dcom.sun.management.jmxremote.port=8090"
 
JAVA_OPTS="${JAVA_OPTS} -Dcom.sun.management.jmxremote.ssl=false"
 
JAVA_OPTS="${JAVA_OPTS} -Djava.rmi.server.hostname=preprodrtd.vehco.com"
 
JAVA_OPTS="${JAVA_OPTS} -Dcom.sun.management.jmxremote.authenticate=true"
 
JAVA_OPTS="${JAVA_OPTS} -Dcom.sun.management.jmxremote.access.file=/var/lib/tomcat7/conf/jmxremote.access"
 
JAVA_OPTS="${JAVA_OPTS} -Dcom.sun.management.jmxremote.password.file=/var/lib/tomcat7/conf/jmxremote.password"
 
</syntaxhighlight>
 
 
!! The ''rmi.server.hostname'' must match /etc/hostname !!
 
 
 
Restart tomcat
 
<syntaxhighlight lang="bash">
 
Service tomcat7 restart
 
</syntaxhighlight>
 
 
 
==Open firewall==
 
Edit your firewall script
 
<syntaxhighlight lang="bash">
 
vim /etc/firewall/firewall-start.sh
 
</syntaxhighlight>
 
 
'''Incoming connections'''
 
<syntaxhighlight lang="bash">
 
$IPTABLES -A INPUT -p tcp --dport 8090 -j ACCEPT    # Tomcat JMX
 
</syntaxhighlight>
 
 
'''Outgoing connections'''
 
<syntaxhighlight lang="bash">
 
$IPTABLES -t filter -A OUTPUT -p tcp -m state --state NEW --dport 8090 -j ACCEPT      # Tomcat JMX
 
</syntaxhighlight>
 
 
Just restart your firewall to apply changes
 
<syntaxhighlight lang="bash">
 
firewall restart
 
</syntaxhighlight>
 
 
 
==Access JMX data==
 
Just execute '''jvisualvm''' or ''jconsole''.
 
Fill up the information and use a none-secure connection.
 
  
  

Revision as of 17:13, 31 March 2015


Tomcat is a Java servlet container, it can be used to display simple JSP and run Spring applications.

However, it cannot run JavaEE, you'll need a proper application server such IBM WAS, Glassfish, Jboss, etc. to do so.



Installation Server configuration Application configuration Other
Linux apt-get setup Users management MySQL datasource Apache 2 proxy
Linux manual setup UTF-8
Linux Tomcat on boot IPv4 over IPv6 Example Example
Windows setup JMX configuration Example Example
Increase PermGen Example Example



Server configuration

War deployment

There is 2 ways to deploy a war:


If you plan to use the graphical tool then you have to adjust the war file max size. Edit:

${Tomcat root} / webapps / manager / WEB-INF / web.xml


Adjust following values ~line 54 :

<multipart-config>
    <max-file-size>104857600</max-file-size>
    <max-request-size>104857600</max-request-size>
    <file-size-threshold>0</file-size-threshold>
</multipart-config>


Add MySQL datasource

Setup MySQL JDBC connector

1. Download MySQL JDBC driver http://dev.mysql.com/downloads/connector/j/

2. Decompress content and extract mysql-connector-java-XXX-bin.jar

3. Copy this file into $TOMCAT/libs Automatic install: /usr/share/tomcat7/lib

Declare MySQL datasource

Server.xml

Automatic install: /etc/tomcat7/server.xml

$TOMCAT/server.xml

Add

<host>
... 
<GlobalNamingResources>
...

<!-- ####################################################################### -->
<!--                              MySQL datasource                           -->
<!-- ####################################################################### -->

<!-- maxActive: Maximum number of database connections in pool. Set to -1 for no limit. -->
<!-- maxIdle: Maximum number of idle database connections to retain in pool. Set to -1 for no limit.  -->
<!-- maxWait: Maximum time to wait for a database connection to become available in ms. Set to -1 to wait indefinitely. -->
<!-- driverClassName: Class name for the official MySQL Connector/J driver is com.mysql.jdbc.Driver. -->

<Resource name="jdbc/myDataSource" 
	      auth="Container" type="javax.sql.DataSource"
	      username="user" password="password" 
	      url="jdbc:mysql://localhost:3306/mySchema" 
	      maxActive="50" maxIdle="30" maxWait="10000"
	      driverClassName="com.mysql.jdbc.Driver"
              factory="org.apache.tomcat.dbcp.dbcp2.BasicDataSourceFactory"
              removeAbandoned="true"
              validationQuery="select 1" validationInterval="30000"
              testOnBorrow="true" testWhileIdle="true" 
              timeBetweenEvictionRunsMillis="60000"
              numTestsPerEvictionRun="5"
              poolPreparedStatements="true"
/>

</GlobalNamingResources>
  • Tomcat 8 : factory="org.apache.tomcat.dbcp.dbcp2.BasicDataSourceFactory"
  • Tomcat 7 >= 7.0.52 : factory="org.apache.tomcat.dbcp.dbcp.BasicDataSourceFactory"
  • Tomcat 6,7 < 7.0.52 : factory="org.apache.commons.dbcp.BasicDataSourceFactory"


Context.xml

Edit:

$TOMCAT/context.xml

Add the following declaration

<!-- ####################################################################### -->
<!--                              MySQL datasource                           -->
<!-- ####################################################################### -->
<ResourceLink name="jdbc/myDataSource" 	
              global="jdbc/myDataSource"
              type="javax.sql.datasource" />


web.xml

Edit

$TOMCAT/web.xml

Add the following declaration

<!-- ####################################################################### -->
<!--                              MySQL datasource                           -->
<!-- ####################################################################### -->

    <resource-ref>
	    <description>RTD database</description>
	    <res-ref-name>jdbc/VehcoData</res-ref-name>
	    <res-type>javax.sql.DataSource</res-type>
	    <res-auth>Container</res-auth>
    </resource-ref>


Take changes into account

Restart tomcat

service tomcat7 restart

Check result: http://localhost:8080/manager/text/resources


Use datasource

To use the datasource with a JNDI name you must prefix it with: java:comp/env/

      java:comp/env/jdbc/myDataSource


Datasource improvements

You can tweak the datasource using some specific config parameters. Edit:

$TOMCAT/server.xml

Edit your JDBC resource:

<Resource auth="Container"
   name="jdbc/APP_NAME"
   username="user"
   password="password"
   type="javax.sql.DataSource"

   url="jdbc:oracle:thin:@server.domain:1521:development"    	→ ORACLE database
   driverClassName="oracle.jdbc.driver.OracleDriver"

   url="jdbc:mysql://localhost:3306/rtd"		→ MySQL database
   driverClassName="com.mysql.jdbc.Driver"

   maxActive="50" maxIdle="30" maxWait="10000"		→ Connection pool
   maxIdle="10"
   maxWait="5000"
   maxActive="30"   	             → To remove none close connections

   logAbandoned="true" 		     To report the stacktrace of the faulty code
   removeAbandoned="true"	     To remedy connection starvation while leaky code is not fixed
   removeAbandonedTimeout="60"	     Interval for fixing connection starvation

   validationQuery="select 1 from dual"     custom query to perform regular checks
   validationInterval="30000"		    To be adjusted!  Interval in ms.
   testOnBorrow="true"
   testOnReturn="false"
   testWhileIdle="true"
   timeBetweenEvictionRunsMillis="5000"
   numTestsPerEvictionRun="3"
   minEvictableIdleTimeMillis="30000"
/>

More tweaks: http://commons.apache.org/proper/commons-dbcp/configuration.html


Basic tasks

Files location

The applications files are in $Tomcat/webapps

  • Automatic installation: /var/lib/tomcat/webapps

Remove old temp files

In case of bugs, you can remove the working directory: $Tomcat/work/Catalina/localhost/*

rm -Rf /var/lib/tomcat7/work/Catalina/localhost/*

Server access

http://server:8080