Production Deployment
Follow this checklist step by step every time you deploy to a production server.
1. Generate the application key
php artisan key:generate
Never reuse a key from another environment.
2. Disable debug mode
APP_ENV=production
APP_DEBUG=false
Verify by opening a non-existent URL — you should see a clean 404 page, not a stack trace.
3. Create the storage link
php artisan storage:link
Without this, uploaded images are not publicly accessible.
4. Fix directory permissions
chown -R <web-user>:<web-user> storage bootstrap/cache
chmod -R 775 storage bootstrap/cache
<web-user> is the user running PHP (e.g. www-data on Nginx/Apache).
5. Run the queue worker (systemd)
Create /etc/systemd/system/webcms-queue.service:
[Service]
Type=simple
WorkingDirectory=/path/to/webcms
ExecStart=/usr/bin/php artisan queue:work --sleep=3 --tries=3 --timeout=300
Restart=always
systemctl daemon-reload
systemctl enable --now webcms-queue.service
6. Schedule the cron job
* * * * * cd /path/to/webcms && php artisan schedule:run >> /dev/null 2>&1
7. Enable SSL/HTTPS
Make sure the certificate is active, APP_URL uses https://, then set
SESSION_SECURE_COOKIE=true.
8. Take an initial backup
Back up the database and storage/app/public before handing the site
over to the client, and keep at least one copy off-server.
Log rotation
Ready-made template: ops/logrotate-webcms in the repository (14-day retention, compressed).
sudo cp ops/logrotate-webcms /etc/logrotate.d/webcms
sudo logrotate -d /etc/logrotate.d/webcms 2>&1 | head -5 # validate the config
Verify worker & scheduler
systemctl is-active webcms-queue.service # must print: active
php artisan schedule:list # must list webcms:backup and sitemap:generate
ls -la storage/app/backups/ # daily archives appear after 02:00
Rollback in under 15 minutes
When a deploy breaks the site — back to normal in 5–10 minutes:
systemctl stop webcms-queue.service
php artisan webcms:restore --latest --force
php artisan config:clear && php artisan view:clear
systemctl start webcms-queue.service
# verify: homepage + one page + admin login
Final verification
php artisan about # environment should read "production"
curl -sI https://client-domain/.env | head -1 # must be 404, NEVER 200
Rollback
Back up the files you touch before every risky deploy change:
TS=$(date +%Y%m%d-%H%M%S)
tar -czf /root/webcms-deploy-$TS.tar.gz .env routes/ config/ public/build/
# ... make changes ...
# if something breaks:
tar -xzf /root/webcms-deploy-$TS.tar.gz -C /path/to/webcms
php artisan config:clear && php artisan view:clear