Server configuration and maintenance
Server configuration and maintenance keep web servers, PHP and databases secure and up to date, with every change documented.
Background
Without maintenance, outage and security risks grow every month: versions lose support, certificates expire and disks fill up.
Set-up
Nginx or Apache for HTTPS, redirects and caching
PHP-FPM with OPcache, in a security-supported version
MySQL or MariaDB with separate users and restricted permissions
TLS 1.3 and 1.2, older protocols disabled
log rotation, time synchronisation and automatic security updates
Security headers such as Content Security Policy and HSTS are added, upload sizes are limited and unused features are switched off.
Configuration as code
Configurations are documented and, where useful, kept as code in Git. A server can then be rebuilt reproducibly, and knowledge does not depend on one person.
Ongoing maintenance
On a fixed schedule, we apply updates and check disk space, load, backups and certificates. Major upgrades of PHP or the database are tested on a staging environment first.
Approach
For existing servers, we start with an audit of versions, open ports, configuration and backups. You receive a list of risks with clear recommendations.