पाठ 23 / 25

Deployment and Configuration

Deploy PHP applications with containers, environment configuration and zero-downtime releases.

Shipping PHP reliably

A typical modern deployment runs NGINX plus PHP-FPM (or FrankenPHP or Apache with PHP-FPM) in containers or on VMs. Build steps: install dependencies with composer install --no-dev --optimize-autoloader, build frontend assets, warm framework caches (configuration, routes, views), and package everything into an immutable artefact such as a Docker image. Keep configuration out of code: read environment variables for database credentials, API keys and feature settings (frameworks load .env files in development, but production should inject real environment variables or secrets from a secret manager), and never commit secrets. Tune PHP-FPM pools: pm.max_children limits concurrent requests per server and must fit in memory (roughly available RAM divided by memory per worker). Run database migrations as a separate, controlled step. For zero downtime, deploy new containers behind a load balancer and shift traffic, or use symlink-switching release directories on VMs. Run background queue workers and scheduled tasks as separate processes, supervised and restarted on deploy so they pick up new code.

A multi-stage Dockerfile for a PHP application

Dependencies installed without dev packages; OPcache enabled; runs as an unprivileged user.

FROM composer:2 AS vendor
WORKDIR /app
COPY composer.json composer.lock ./
RUN composer install --no-dev --no-scripts --prefer-dist --optimize-autoloader

FROM php:8.4-fpm-alpine
RUN apk add --no-cache icu-dev postgresql-dev \
 && docker-php-ext-install intl pdo_pgsql opcache
COPY docker/php/opcache.ini /usr/local/etc/php/conf.d/opcache.ini
COPY docker/php/www.conf /usr/local/etc/php-fpm.d/www.conf

WORKDIR /var/www/shop
COPY --from=vendor /app/vendor ./vendor
COPY . .
RUN chown -R www-data:www-data var/
USER www-data
# NGINX runs in a separate container and forwards *.php to this one on port 9000
CMD ["php-fpm"]

A sealed lunch box

An immutable image is a packed, sealed lunch box: what you tested is exactly what gets eaten. Copying files onto a running server is like adding ingredients to a plate that is already on the table.

त्वरित जाँच: Why install production dependencies with composer install --no-dev?

  • It makes tests run faster
  • It leaves out development tools such as PHPUnit, reducing size and attack surface
  • It updates all packages to the latest versions
  • It is required by PHP-FPM
Answer

It leaves out development tools such as PHPUnit, reducing size and attack surface — Development dependencies are not needed in production and add unnecessary code.