Documentation

Deploy deliberately

Keep code replaceable, state durable, and recovery tested.

Build a release

Install from the committed lockfile with composer install --no-dev --no-interaction --no-plugins --prefer-dist. Run the application's checks before building. Keep each release in its own directory and record its source commit and package versions.

Put the web boundary in one place

Serve only public/ over HTTPS. Use an unprivileged PHP-FPM account. Keep credentials, databases, and uploads outside the web root and release directories. Disable display_errors. Log failures privately without secrets or complete request bodies.

Set the request limits in the web server, PHP, and the application. These are different boundaries: Stage's raw-body limit does not replace PHP's multipart upload limits.

Preserve state

Back up persistent data before a schema migration. Stop writers while making a complete instance copy. A portable CMS export includes content, revisions, and images, but excludes account credentials, sessions, and tokens.

Use one local filesystem with working locks for the CMS SQLite database. Do not spread independent database copies across application servers. Measure write contention before choosing a different persistence design.

Prove the new release

Check health, real page content, sign-in, private preview, publication, denied API access, and a private path. Compare the response with the expected content from the exact release and environment.

Rollback of code is safe only when the previous version can read the current data. Never overwrite edits made after a deployment with a pre-deploy backup. Test recovery with a disposable instance before relying on it.

CMS operations and recovery describes its actual storage and upgrade contract.