LAMP (Linux, Apache, MySQL and PHP) still runs a large share of the web, from WordPress sites to custom business applications. Getting a LAMP site to work is easy; running one that is fast, secure and easy to deploy takes a few more skills. This guide is a roadmap from the fundamentals to the advanced topics that matter in 2026, with pointers to our detailed guides for each part.
An advanced LAMP stack in 2026 means a current Linux LTS release, Apache with PHP-FPM rather than the old mod_php, a supported MySQL or MariaDB release with InnoDB and utf8mb4, and a supported PHP 8 version with OPcache and Composer. Master each layer's configuration, then learn indexing, caching, security hardening and repeatable deployments. On Domain India shared hosting most of the server layer is managed for you; on a VPS you run every layer yourself.
1. How the four layers fit together
When a visitor opens a page, Apache receives the request. Static files such as images and CSS are sent straight back. PHP requests are passed to PHP-FPM, a separate pool of PHP processes, which runs your code. The code queries MySQL (or its close relative MariaDB) for data, builds the page and hands it back to Apache. Linux underneath manages users, file permissions, processes and the network.
Knowing that flow tells you where to look when something goes wrong: a 403 is usually permissions or Apache rules, a 500 is usually PHP, a slow page is usually PHP or the database, and a connection error is the database or the network.
2. Linux: the foundation
Pick a current long-term-support distribution such as Ubuntu LTS, AlmaLinux or Rocky Linux, and keep it updated. The skills that matter most:
- Users and permissions. Run each site as its own user, keep files at 644 and folders at 755, and never make anything 777.
- Package updates. Apply security updates regularly, and reboot when the kernel is updated.
- Firewall. Open only what you need, usually 22, 80 and 443, using firewalld or ufw.
- SSH keys. Log in with keys, not passwords, and disable direct root login.
- Logs. Know where the system, web server and PHP logs live, and how to follow them with
tail -forjournalctl. - Shell scripting. Small Bash scripts for backups and deployments save hours and reduce mistakes.
3. Apache: configuration that scales
| Topic | The older way | The current way |
|---|---|---|
| Running PHP | mod_php inside Apache | PHP-FPM with the event MPM |
| Protocol | HTTP/1.1 only | HTTP/2 over TLS |
| Certificates | Paid certificates renewed by hand | Free Let's Encrypt certificates renewed automatically |
| Site rules | Everything in .htaccess | Virtual host files where you control the server; .htaccess where you do not |
Learn virtual hosts, mod_rewrite for clean URLs and redirects, response compression, and cache headers for static files. On a server you control, rules in the virtual host are faster than .htaccess, because Apache reads .htaccess files on every request.
Because PHP runs through PHP-FPM, a php_value or php_flag line in .htaccess no longer works and causes a 500 error. Set PHP options in a .user.ini file or in the PHP-FPM pool instead. For rewrite rules, see How can I enable the mod_rewrite module; for server-level tuning on your own server, see Tuning Apache and Nginx for high-traffic websites.
4. MySQL and MariaDB: data that stays fast
- Use a supported release. MySQL 8.0 reached end of life in April 2026, so new servers should use the current MySQL LTS release or a current MariaDB LTS release.
- Use InnoDB and utf8mb4. InnoDB gives transactions and crash recovery; utf8mb4 stores every language and emoji correctly.
- Index for your queries. Add indexes on the columns you filter, join and sort by, and check each slow query with
EXPLAIN. - Avoid
SELECT *in application code, and paginate large result sets. - Give each application its own database user with rights only to its own database.
- Back up with a dump tool such as
mysqldumpormariadb-dump, and test that the dump restores.
Deleting ibdata1 or the InnoDB log files does not repair a database; it destroys it. Restore from a backup or get expert help instead.
For finding and fixing slow queries, see MySQL performance optimisation; for connecting from code and tools, see How to connect to the MySQL database.
5. PHP: modern language, modern tooling
Use a PHP 8 version that still receives security fixes, and upgrade at least once a year. The advanced skills:
- Composer and autoloading. Manage libraries with Composer and follow PSR-4 autoloading, so code is organised and dependencies are pinned in
composer.lock. - A framework for anything non-trivial. Laravel and Symfony give routing, validation, database access and security defaults you would otherwise write yourself.
- Prepared statements. Always use PDO or mysqli prepared statements; never build SQL by joining strings with user input.
- OPcache. Keeps compiled code in memory and is the single biggest PHP speed gain. See PHP OPcache configuration.
- Errors to logs, not screens. In production, set
display_errorsoff andlog_errorson. - Asynchronous work through queues. Send emails and process uploads in a background worker instead of inside the web request.
6. Security across the stack
Security is a layer of its own: keep every component updated, validate all input, escape all output, use HTTPS everywhere, store passwords with password_hash(), and keep secrets in environment files outside the web root. The full checklist is in Protecting LAMP stack web apps from security vulnerabilities.
7. Deployment and operations
Advanced LAMP work is as much about how code reaches the server as about the code itself:
- Keep code in Git.Every change is tracked and can be rolled back.
- Build outside the live site.Run
composer install --no-devand any front-end build on your computer or in CI, not on the production server. - Deploy to a new release folder.Upload the release, run database migrations, then switch a symlink to the new folder, so visitors never see a half-updated site.
- Keep configuration out of Git.Use an environment file per server for database passwords and API keys.
- Monitor and back up.Watch error logs and uptime, and keep automated database and file backups off the server.
8. Running LAMP on Domain India
| Where | What you manage | Good to know |
|---|---|---|
| cPanel and DirectAdmin shared hosting | Your code and database only | Apache (with nginx in front on cPanel); PHP runs through PHP-FPM or CGI, not as an Apache module; mod_rewrite and .htaccess enabled; PHP up to 8.5 on cPanel (default 8.3) and up to 8.3 on DirectAdmin |
| VPS | Every layer, from Linux upwards | Self-managed with full root access; no cPanel on VPS |
| App Platform | Your app and its build | PHP apps deploy with a Dockerfile; only Node.js is detected automatically |
A few shared-hosting facts that change how you work:
- Composer isn't pre-installed on shared hosting, and the process functions its scripts need are disabled. Over jailed SSH you can run
php composer.phar install, adding--no-scriptsif it stops with a proc_open message, or build locally or in CI and upload the project with itsvendor/folder. See PHP disabled functions on shared hosting. - SSH is available on request. Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. Login is by SSH key. See Enabling and accessing jailed SSH.
- Remote Database Access on port 3306 is closed from outside. Connect through an SSH tunnel instead.
- Cron jobs run at most every 4 minutes. Jobs set to every 1, 2 or 3 minutes are changed to every 4 minutes.
To build a full LAMP server yourself, follow Setting up a LAMP stack with Laravel on a Domain India VPS.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
The price on the card is live and excludes 18% GST. For your own server, see VPS plans. Support is on 24/7 live chat, and tickets get a first response within 15 minutes; there is no phone support.
Frequently asked questions
What is a LAMP stack?
LAMP is a set of four open-source components for running websites: Linux as the operating system, Apache as the web server, MySQL or MariaDB as the database, and PHP as the programming language. WordPress and most PHP applications run on it.
Should I use mod_php or PHP-FPM with Apache?
Use PHP-FPM. It runs PHP in a separate pool of processes, works with Apache's efficient event MPM, and lets each site run as its own user. mod_php is the older approach and is not used on Domain India shared servers.
Why does php_value in .htaccess cause a 500 error?
php_value and php_flag only work when PHP runs as an Apache module. When PHP runs through PHP-FPM, Apache does not understand those lines and returns a 500 error. Put PHP settings in a .user.ini file or the PHP-FPM pool instead.
Which PHP version should I use?
Use a PHP 8 version that still receives security fixes, and test your application before switching. On Domain India, cPanel hosting offers PHP up to 8.5 with 8.3 as the default, and DirectAdmin offers up to 8.3.
Can I run Composer on Domain India shared hosting?
Yes, over jailed SSH (on request). Composer isn't pre-installed, so download composer.phar and run php composer.phar install; if it stops with a proc_open message, run it again with --no-scripts. Or run composer install on your computer or in CI and upload the project with its vendor folder, or use a VPS or the App Platform.
Can I connect to MySQL remotely on shared hosting?
Port 3306 is closed from outside on Domain India shared servers. Use an SSH tunnel: ask support to enable jailed SSH for your account, add your SSH key, and forward a local port to the database.
Ready to build? Compare cPanel hosting for managed LAMP, VPS plans for full control, or open a support ticket to have SSH enabled on your account.
Apache, PHP-FPM and MySQL are set up and maintained for you, so you can focus on your code.
See cPanel hosting