Production Deployment

Follow this checklist step by step every time you deploy to a production server.

1. Generate the application key

php artisan key:generate

Never reuse a key from another environment.

2. Disable debug mode

APP_ENV=production
APP_DEBUG=false

Verify by opening a non-existent URL — you should see a clean 404 page, not a stack trace.

3. Create the storage link

php artisan storage:link

Without this, uploaded images are not publicly accessible.

4. Fix directory permissions

chown -R <web-user>:<web-user> storage bootstrap/cache
chmod -R 775 storage bootstrap/cache

<web-user> is the user running PHP (e.g. www-data on Nginx/Apache).

5. Run the queue worker (systemd)

Create /etc/systemd/system/webcms-queue.service:

[Service]
Type=simple
WorkingDirectory=/path/to/webcms
ExecStart=/usr/bin/php artisan queue:work --sleep=3 --tries=3 --timeout=300
Restart=always
systemctl daemon-reload
systemctl enable --now webcms-queue.service

6. Schedule the cron job

* * * * * cd /path/to/webcms && php artisan schedule:run >> /dev/null 2>&1

7. Enable SSL/HTTPS

Make sure the certificate is active, APP_URL uses https://, then set SESSION_SECURE_COOKIE=true.

8. Take an initial backup

Back up the database and storage/app/public before handing the site over to the client, and keep at least one copy off-server.

Log rotation

Ready-made template: ops/logrotate-webcms in the repository (14-day retention, compressed).

sudo cp ops/logrotate-webcms /etc/logrotate.d/webcms
sudo logrotate -d /etc/logrotate.d/webcms 2>&1 | head -5   # validate the config

Verify worker & scheduler

systemctl is-active webcms-queue.service   # must print: active
php artisan schedule:list                   # must list webcms:backup and sitemap:generate
ls -la storage/app/backups/                 # daily archives appear after 02:00

Rollback in under 15 minutes

When a deploy breaks the site — back to normal in 5–10 minutes:

systemctl stop webcms-queue.service
php artisan webcms:restore --latest --force
php artisan config:clear && php artisan view:clear
systemctl start webcms-queue.service
# verify: homepage + one page + admin login

Final verification

php artisan about          # environment should read "production"
curl -sI https://client-domain/.env | head -1   # must be 404, NEVER 200

Rollback

Back up the files you touch before every risky deploy change:

TS=$(date +%Y%m%d-%H%M%S)
tar -czf /root/webcms-deploy-$TS.tar.gz .env routes/ config/ public/build/
# ... make changes ...
# if something breaks:
tar -xzf /root/webcms-deploy-$TS.tar.gz -C /path/to/webcms
php artisan config:clear && php artisan view:clear