Running nine sites on one server

Every hosted Domma CMS site, this one included, runs on one server under the Domma Manager. What that looks like day to day, and what it has taught us.

This site is one of nine Domma CMS sites that run on a single server. They include a photography and events business, a plasterer, a tutoring service, a DJ and compere, a personal site, a JavaScript game engine's documentation and a few of our own. You can see them all on the showcase. They are managed by the Domma Manager, which is itself a Domma CMS site with extra powers. This is a look at how that works, and what running it has taught us.

A process per site

Each site runs as its own Node.js process, started and watched by the Manager. Sites do not share memory, a cache or a crash: if one misbehaves, the others carry on. The Manager checks each one's health, restarts a site that falls over with a back-off, and gives up after a handful of failed attempts in a short time so that a broken site cannot spin forever.

That cap once caught us out. During a busy day of work on this site, a set of automated jobs restarted it eight times in about four minutes. The Manager did exactly what it was built to do: it decided something was wrong and stopped trying. The site was down for about three minutes. The fix was on our side - restarts now go through the Manager, at most one every two minutes, and requests that arrive close together are combined into one. The lesson was that a safety limit is only useful if everything that touches the system respects it.

Each site's data is its own

Every site keeps its content in its own folder and, when it uses MongoDB, in its own database with its own login - a database user that can reach that site's data and nothing else. The Manager holds the administrative credentials; the sites never do. A problem in one site's data cannot spill into another's.

Tools that are signed and licensed per site

Pro Tools reach a site as signed packages. The site checks the signature before it will install one, and a Pro Tool runs only with a licence issued for that site. Granting a Tool to a site is one operation in the Manager - the licence and the install together - and revoking the licence switches it off again without deleting anything. If a Pro licence lapses, the free version it replaced comes back with every post, contact and order intact.

One update, every site

When a new version of Domma CMS is released, the Manager updates itself first, then each site. It restarts only the sites whose code actually changed, checks every one answers afterwards, and stops the whole run if the Manager's own update fails - because a stale Manager could otherwise push old code back to the sites. Every update starts with a dry run that shows what would happen without changing anything.

Most weeks that means several releases reach every site the same day they are made, which is the only reason a small team can keep nine sites current.

What we learned about backups

For a long time, every backup of every site sat on the same disk as the sites themselves. A failed disk would have taken the sites and their backups together. It is the kind of thing that is easy to know and easy to put off, and it is why Backup Pro exists: scheduled, encrypted backups of every site, restores that are tested regularly in a sealed-off copy, and - because it matters to the people who own the sites - a record they can read of every backup and every restore.

Why tell you this

Because if you host with us, this is what your site sits on, and because if you run sites for clients, the same Manager is what makes it manageable. The Operations feature page covers the updater and the command line, and the Partners pages cover working with us if you want to sell Domma CMS yourself.