4 min read Sep 26, 2026

How to Install a LEMP Stack (Nginx, MariaDB, PHP-FPM) on Your VPS

Install Nginx, MariaDB and PHP 8.3 with PHP-FPM on Ubuntu, Debian, AlmaLinux or Rocky Linux, create your first site, test PHP and fix 502 and 403 errors.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

LEMP stands for Linux, Engine-X (Nginx), MariaDB and PHP. It is a fast, memory-efficient way to run PHP websites such as WordPress, Laravel or custom apps on a VPS. Nginx serves files and passes PHP requests to PHP-FPM, which runs the PHP code.

Allow about 15 minutes. You need a sudo user and an open firewall for ports 80 and 443 (see the firewall guide).

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Which PHP version will I get?

DistributionPHP version from the standard repositoriesPHP-FPM socket
Ubuntu 24.04 LTS8.3/run/php/php8.3-fpm.sock
Ubuntu 22.04 LTS8.1 (still patched by Ubuntu)/run/php/php8.1-fpm.sock
Debian 128.2/run/php/php8.2-fpm.sock
AlmaLinux / Rocky 9.6 or later8.3 (after enabling the php:8.3 module)/run/php-fpm/www.sock

Each distribution backports security fixes to its own PHP version for as long as the release is supported. If your application needs a newer PHP than your distribution ships, you can add a third-party PHP repository, or choose Ubuntu 24.04 or AlmaLinux 9 for a new server.

Step 1: Install the packages

Ubuntu and Debian

sudo apt update
sudo apt install -y nginx mariadb-server php-fpm php-mysql php-curl php-gd \
  php-mbstring php-xml php-zip php-intl php-bcmath
php -v

The services start automatically. The PHP-FPM service is named after the version, for example php8.3-fpm.

AlmaLinux and Rocky Linux 9

sudo dnf install -y nginx mariadb-server
sudo dnf module reset -y php
sudo dnf module enable -y php:8.3
sudo dnf install -y php-fpm php-mysqlnd php-gd php-mbstring php-xml php-intl php-bcmath php-opcache php-cli
sudo systemctl enable --now nginx mariadb php-fpm
php -v

If php:8.3 is not found, your system is older than 9.6: run sudo dnf upgrade -y first, or check the available versions with dnf module list php. On these systems PHP-FPM runs as the apache user, which is normal even when you use Nginx.

Step 2: Secure MariaDB

Run sudo mariadb-secure-installation and create a database user for your site. Full walk-through: How to Secure MySQL or MariaDB on Your VPS.

Step 3: Create the site folder

sudo mkdir -p /var/www/example.com/public
echo '<?php phpinfo();' | sudo tee /var/www/example.com/public/info.php
# Ubuntu / Debian
sudo chown -R www-data:www-data /var/www/example.com
# AlmaLinux / Rocky
sudo chown -R apache:apache /var/www/example.com

Step 4: Add an Nginx server block

Ubuntu and Debian

Create /etc/nginx/sites-available/example.com with sudo nano. Replace the domain, and change php8.3 to your version from the table above:

server {
    listen 80;
    listen [::]:80;
    server_name example.com www.example.com;

    root /var/www/example.com/public;
    index index.php index.html;

    client_max_body_size 64M;

    location / {
        try_files $uri $uri/ /index.php?$args;
    }

    location ~ \.php$ {
        include snippets/fastcgi-php.conf;
        fastcgi_pass unix:/run/php/php8.3-fpm.sock;
    }

    # block hidden files such as .env and .git, but allow Let's Encrypt checks
    location ~ /\.(?!well-known) {
        deny all;
    }
}

Enable it and disable the default welcome site:

sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo nginx -t
sudo systemctl reload nginx

AlmaLinux and Rocky Linux

Create /etc/nginx/conf.d/example.com.conf with the same content, but replace the whole location ~ \.php$ block with this one:

    location ~ \.php$ {
        try_files $uri =404;
        fastcgi_pass unix:/run/php-fpm/www.sock;
        fastcgi_index index.php;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }

Then test and reload with sudo nginx -t && sudo systemctl reload nginx.

Step 5: Test PHP

Point your domain to the VPS (DNS guide) and open http://example.com/info.php. You should see the purple PHP information page. Delete it straight away, because it reveals details about your server:

sudo rm /var/www/example.com/public/info.php

Next, add HTTPS with a free Certbot certificate, then upload your site into /var/www/example.com/public using SFTP or git.

Tuning PHP settings

Common values such as the upload size and memory limit are set in php.ini:

  • Ubuntu/Debian: /etc/php/8.3/fpm/php.ini (use your version number)
  • AlmaLinux/Rocky: /etc/php.ini
upload_max_filesize = 64M
post_max_size = 64M
memory_limit = 256M
max_execution_time = 120

Restart PHP-FPM afterwards: sudo systemctl restart php8.3-fpm (Ubuntu/Debian) or sudo systemctl restart php-fpm (AlmaLinux/Rocky). Keep client_max_body_size in Nginx at least as large as upload_max_filesize.

Common problems

SymptomLikely cause and fix
502 Bad GatewayNginx can't reach PHP-FPM. Check the socket path in fastcgi_pass matches ls /run/php/ or /run/php-fpm/, and that PHP-FPM is running: systemctl status php8.3-fpm.
Browser downloads the .php fileThe PHP location block is missing or the server block isn't enabled. Recheck Step 4 and run sudo nginx -t.
403 ForbiddenNo index.php/index.html in the folder, or wrong ownership. On AlmaLinux, also check SELinux labels with ls -Z and fix with sudo restorecon -Rv /var/www.
413 Request Entity Too LargeRaise client_max_body_size and reload Nginx.
The default Nginx page showsYour server_name doesn't match the domain, or the default site is still enabled.

Error details are in /var/log/nginx/error.log. See How to Read Server Logs on Your VPS.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer