Coolify-doc-driven production hardening of the deploy stack: - run the whole stack as non-root www-data; nginx on 8080 (non-privileged), pid in /tmp, user directive dropped (Coolify routes to any port) - docker/healthcheck.sh: hit real /health route via PHP (not just port probe) - split OPcache config into docker/php/opcache.ini - graceful shutdown: supervisord stopsignal/stopwaitsecs + worker stop_grace_period - APCu intentionally not added (Symfony cache uses redis) - DEPLOY.md: 8080 port, non-root, resource-limit guidance Verified on linux/amd64: non-root uid=82, /health 200, migrations run, worker process healthcheck OK. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
12 lines
265 B
INI
12 lines
265 B
INI
; Production PHP settings for ClinicPro on Coolify
|
|
memory_limit = 1024M
|
|
upload_max_filesize = 16M
|
|
post_max_size = 32M
|
|
max_execution_time = 60
|
|
expose_php = Off
|
|
date.timezone = Asia/Tehran
|
|
|
|
; Realpath cache (perf)
|
|
realpath_cache_size = 4096k
|
|
realpath_cache_ttl = 600
|