Apache2安装配置及LAMP环境、SSL证书与WordPress部署咨询
Hey there! Let’s walk through setting up Apache 2, PHP, MySQL (I’ll use MariaDB, a reliable drop-in replacement), virtual hosts, SSL with Let’s Encrypt, and finally deploying WordPress—all step by step. I’m assuming you’re on a Debian/Ubuntu-based system since that’s the most common for this stack, but I’ll note if commands shift for RHEL/CentOS variants.
First, let’s get Apache installed and running:
- Update your package list to make sure you’re grabbing the latest versions:
sudo apt update - Install Apache:
sudo apt install apache2 - Start the service and enable it to run on boot (so it starts automatically if your server restarts):
sudo systemctl start apache2 sudo systemctl enable apache2 - Test it out: Open your server’s public IP address in a browser. You should see Apache’s default welcome page—if you do, you’re good to go!
Next, we need PHP for dynamic content and a database to store WordPress data.
2.1 Install PHP
WordPress needs several PHP extensions to function properly, so we’ll install those along with PHP itself:
- Run this command to install PHP and required extensions:
sudo apt install php libapache2-mod-php php-mysql php-curl php-gd php-mbstring php-xml php-xmlrpc php-zip - Verify PHP is working: Create a quick test file with
sudo nano /var/www/html/info.php, then paste<?php phpinfo(); ?>into it. Save and close the file, then visithttp://your-server-ip/info.phpin your browser. You should see a detailed page about your PHP setup. Important: Delete this file once you confirm it works—exposing PHP info publicly is a security risk:sudo rm /var/www/html/info.php
2.2 Install MariaDB
MariaDB is a fully compatible replacement for MySQL, and it’s the default on most Debian/Ubuntu systems now:
- Install MariaDB:
sudo apt install mariadb-server - Secure your installation with the built-in script—this helps lock down common security gaps:
sudo mysql_secure_installation
Follow the prompts:- Set a strong root password for your database.
- Remove anonymous users (they don’t belong on a production server).
- Disallow remote root login (keep root access limited to localhost).
- Delete the test database (it’s unnecessary).
- Reload privilege tables to apply all changes.
- Test access to MariaDB: Run
sudo mysql -u root -p, enter your root password, and you should get a MariaDB command prompt. TypeEXIT;to leave when you’re done.
Virtual hosts let you host multiple websites on a single server. Let’s set one up for your domain (replace example.com with your actual domain everywhere below):
- Create a directory to store your site’s files:
sudo mkdir -p /var/www/example.com/public_html - Set ownership to your user account (so you don’t have to use
sudofor every file edit):sudo chown -R $USER:$USER /var/www/example.com/public_html - Set proper permissions to keep your site secure:
sudo chmod -R 755 /var/www/example.com - Create the virtual host configuration file:
sudo nano /etc/apache2/sites-available/example.com.conf
Paste this configuration (swapexample.comand the email address with your own):<VirtualHost *:80> ServerAdmin your-email@example.com ServerName example.com ServerAlias www.example.com DocumentRoot /var/www/example.com/public_html ErrorLog ${APACHE_LOG_DIR}/example.com_error.log CustomLog ${APACHE_LOG_DIR}/example.com_access.log combined </VirtualHost> - Enable the new site:
sudo a2ensite example.com.conf - Disable the default Apache site (optional but keeps things clean):
sudo a2dissite 000-default.conf - Enable the rewrite module (required for WordPress permalinks to work):
sudo a2enmod rewrite - Test your Apache configuration for errors:
sudo apache2ctl configtest
If you seeSyntax OK, reload Apache to apply all changes:sudo systemctl reload apache2
Let’s Encrypt provides free, trusted SSL certificates, and Certbot makes installing and renewing them a breeze:
- Install Certbot and its Apache plugin:
sudo apt install certbot python3-certbot-apache - Run Certbot to get and install your SSL certificate:
sudo certbot --apache
Follow the prompts:- Enter your email address (for renewal alerts and important notices).
- Agree to the Let’s Encrypt terms of service.
- Choose whether to redirect all HTTP traffic to HTTPS (highly recommended—this ensures visitors always use a secure connection).
- Verify auto-renewal: Certbot automatically sets up a cron job to renew your certificate before it expires. Test this with:
sudo certbot renew --dry-run
If the test succeeds, you’re all set—no manual renewal needed!
Now let’s get WordPress up and running on your new virtual host.
5.1 Create a Database & User for WordPress
Never use the root database user for applications—it’s a huge security risk. Instead, create a dedicated user and database for WordPress:
- Log into MariaDB:
sudo mysql -u root -p - Run these SQL commands (replace
wordpress_db,wordpress_user, andyour_strong_passwordwith your own values):CREATE DATABASE wordpress_db; CREATE USER 'wordpress_user'@'localhost' IDENTIFIED BY 'your_strong_password'; GRANT ALL PRIVILEGES ON wordpress_db.* TO 'wordpress_user'@'localhost'; FLUSH PRIVILEGES; EXIT;
5.2 Download & Configure WordPress
- Navigate to your site’s public directory:
cd /var/www/example.com/public_html - Download the latest WordPress archive:
wget https://wordpress.org/latest.tar.gz - Extract the archive:
tar -xzvf latest.tar.gz - Move all WordPress files to the public_html directory (so they’re directly accessible):
mv wordpress/* . - Clean up the now-empty WordPress folder and the archive file:
rm -rf wordpress latest.tar.gz - Copy the sample configuration file to create your wp-config.php:
cp wp-config-sample.php wp-config.php - Edit wp-config.php to add your database details:
nano wp-config.php
Find these lines and replace them with your database info:define( 'DB_NAME', 'wordpress_db' ); define( 'DB_USER', 'wordpress_user' ); define( 'DB_PASSWORD', 'your_strong_password' ); define( 'DB_HOST', 'localhost' ); - Optional but recommended: Replace the default security keys in wp-config.php with unique ones. You can generate these using WordPress’s secret key tool—just replace the dummy lines starting with
define('AUTH_KEY', ...)with the unique keys you generate.
5.3 Set Correct Permissions for WordPress
WordPress needs proper file permissions to upload media, install plugins, and more:
- Set ownership of the files to the Apache user (
www-data):sudo chown -R www-data:www-data /var/www/example.com/public_html - Adjust file and directory permissions for security:
sudo find /var/www/example.com/public_html -type d -exec chmod 750 {} \; sudo find /var/www/example.com/public_html -type f -exec chmod 640 {} \;
5.4 Complete Installation via Browser
- Open your browser and visit
https://example.com(your domain with HTTPS). - Follow the on-screen wizard:
- Choose your language.
- Enter a site title, admin username, password, and email address.
- Click “Install WordPress” and log into your new dashboard!
- If Apache won’t start, check the error log for clues:
sudo tail -f /var/log/apache2/error.log - If PHP isn’t parsing (you see raw PHP code in the browser), make sure
libapache2-mod-phpis installed and you’ve reloaded Apache. - If WordPress can’t connect to the database, double-check your wp-config.php credentials and ensure the database user has full privileges on the WordPress database.
内容的提问来源于stack exchange,提问作者vidarlo

