Documentation
Deploy deliberately
Keep code replaceable, state durable, and recovery tested.
Build a release
Install from the committed lockfile with composer install --no-dev --no-interaction --no-plugins --prefer-dist. Run the application's checks before building. Keep each release in its own directory and record its source commit and package versions.
Put the web boundary in one place
Serve only public/ over HTTPS. Use an unprivileged PHP-FPM account. Keep credentials, databases, and uploads outside the web root and release directories. Disable display_errors. Log failures privately without secrets or complete request bodies.
Set the request limits in the web server, PHP, and the application. These are different boundaries: Stage's raw-body limit does not replace PHP's multipart upload limits.
Preserve state
Back up persistent data before a schema migration. Stop writers while making a complete instance copy. A portable CMS export includes content, revisions, and images, but excludes account credentials, sessions, and tokens.
Use one local filesystem with working locks for the CMS SQLite database. Do not spread independent database copies across application servers. Measure write contention before choosing a different persistence design.
Prove the new release
Check health, real page content, sign-in, private preview, publication, denied API access, and a private path. Compare the response with the expected content from the exact release and environment.
Rollback of code is safe only when the previous version can read the current data. Never overwrite edits made after a deployment with a pre-deploy backup. Test recovery with a disposable instance before relying on it.
CMS operations and recovery describes its actual storage and upgrade contract.