LAMP is Linux, Apache, MariaDB or MySQL, and PHP. On a LochStudios KVM VPS you install that stack yourself. This article puts the three services on Ubuntu or Debian, checks they talk to each other, and shows the default page on this server's IPv4.
This is not the path for shared hosting. Beginner and Standard plans already run Apache, MariaDB, and PHP. Open the hosting service and click Log in to cPanel. Create databases there: Create a MySQL Database and User. WordPress on those plans should use Toolkit or Installatron: Install WordPress.
Credentials, the IPv4, and an out-of-band console sit on the VPS in the portal. Sign in at the portal, open the server, and copy the login from there. Do not guess a hostname.
Need a VPS first? See VPS. Prefer Nginx instead of Apache? Use Install a LEMP stack.
Before you start
- Sign in at the portal, open the VPS service, and copy the IPv4, username, and password.
- Connect over SSH.
- Windows: Connect to your VPS via SSH from Windows
- macOS or Linux: Connect to your VPS via SSH from macOS or Linux
- Patch the image and use a sudo user for daily work: First steps on a new VPS.
- If you are logged in as
root, omitsudofrom the commands below.
Do not install this stack on a box that already has Nginx listening on port 80. One process owns that port. If you want Nginx, stop here and use the LEMP article.
If SSH from your computer will not connect, open the console on the same service. That session does not need port 22 from your network.
Choose MariaDB or MySQL
Install one database engine. Do not install both.
- MariaDB is the usual pick on our images. It matches the engine on our shared hosting, and Ubuntu, Debian, AlmaLinux, and Rocky Linux all ship it from the distro repos.
- MySQL 8 is fine when an application specifically asks for it.
The rest of this article uses MariaDB. Swap in the MySQL package and the mysql systemd unit if you chose that engine. For hardening and remote access in more depth, see Install MySQL or MariaDB and Secure It.
Update package lists
sudo apt update
Install Apache, the database, and PHP
MariaDB:
sudo apt install -y apache2 mariadb-server php libapache2-mod-php php-mysql php-cli php-mbstring php-xml php-curl php-gd php-zip
MySQL (only if you chose it):
sudo apt install -y apache2 mysql-server php libapache2-mod-php php-mysql php-cli php-mbstring php-xml php-curl php-gd php-zip
libapache2-mod-php is the Apache module. Installing php alone is not enough for Apache to run .php files. Extra extensions live in Install PHP and Common Extensions.
The PHP version is whatever this Ubuntu or Debian release ships (for example PHP 8.3 on Ubuntu 24.04). You do not need a third-party repo for a working stack.
On AlmaLinux or Rocky Linux the packages are different (httpd, php-mysqlnd). Use the AlmaLinux or Rocky Linux section later in this article if that is the image on this VPS.
Enable rewrite and start the services
Pretty permalinks and most .htaccess RewriteRule lines need mod_rewrite:
sudo a2enmod rewrite
The PHP module is versioned (php8.3, not php). Confirm it is on:
sudo a2query -m | grep php
If nothing prints, enable the module that matches php -v (example for 8.3):
sudo a2enmod php8.3
Start Apache and MariaDB, and leave them enabled after a reboot:
sudo systemctl enable --now apache2
sudo systemctl enable --now mariadb
If you installed MySQL, the second unit is mysql:
sudo systemctl enable --now mysql
If you are not sure which database unit landed on this image:
systemctl list-units --type=service --all | grep -E 'mysql|mariadb'
Use that name in the rest of this article.
Confirm the services are running
sudo systemctl status apache2
sudo systemctl status mariadb
You want active (running) on both. Press q to leave each status view.
From the server itself:
curl -I http://127.0.0.1
php -v
curl should return HTTP/1.1 200 (or 301 if you already forced HTTPS). php -v should print a PHP 8.x line.
Open it in a browser
Use the IPv4 on the VPS service in the portal:
http://203.0.113.10
Replace that address with yours. You should see the Apache2 default page.
If the service is running and curl on the server works, but your browser does not, the host firewall is usually still closed on port 80.
Allow HTTP and HTTPS on UFW
UFW is the host firewall on our Ubuntu images. Allow SSH before you enable it, or you will cut off SSH from your computer. The console in the portal still works if that happens.
If UFW is already active:
sudo ufw allow 'Apache Full'
sudo ufw status
Apache Full is the package profile for ports 80 and 443. HTTP only:
sudo ufw allow 'Apache'
If UFW is still inactive, do not run sudo ufw enable from this article. Set the defaults and allow SSH first: Set up a UFW firewall on Ubuntu. That guide then opens 80 and 443 the same way.
MariaDB should stay on localhost. Do not open port 3306 to the internet.
Secure the database
The packages ship with open defaults (anonymous users, a test database, remote root). Close those before you create an app database.
sudo mariadb-secure-installation
sudo mysql_secure_installation is the same script on many images. MySQL uses that name.
Recommended answers:
- Current root password: press Enter if you have not set one yet (usual on a new VPS).
- unix_socket authentication:
Yif asked. OS root can then runsudo mysqlwithout a database password. - Set or change the root password: optional when unix_socket is on.
- Remove anonymous users:
Y. - Disallow remote root login:
Y. - Remove the test database:
Y. - Reload privilege tables:
Y.
Use a long unique password if you set one. See Create strong passwords and use a password manager.
Check you can open a prompt:
sudo mysql
SELECT VERSION();
EXIT;
On some MariaDB images the client is mariadb. Either should give you a mysql> or MariaDB [(none)]> prompt.
Create a database and an app user
Do not point a website at the root account. Create one database and one user per app. Keep the user on localhost.
sudo mysql
CREATE DATABASE your_app_db;
CREATE USER 'your_user'@'localhost' IDENTIFIED BY 'choose-a-long-unique-password';
GRANT ALL PRIVILEGES ON your_app_db.* TO 'your_user'@'localhost';
FLUSH PRIVILEGES;
EXIT;
Replace the name, user, and password. That password is not your portal password, and it is not the Linux sudo password.
Test the app user:
mysql -u your_user -p your_app_db
Type the app password when asked. A prompt means the grant worked. EXIT; to leave.
Apps on this VPS should use host localhost or 127.0.0.1. They do not need a public database port. Confirm the listener is local:
sudo ss -tlnp | grep 3306
You want 127.0.0.1:3306. You do not want 0.0.0.0:3306. If it is public, follow the bind-address steps in Install MySQL or MariaDB and Secure It.
Test PHP through Apache
echo "<?php phpinfo(); ?>" | sudo tee /var/www/html/phpinfo.php
Browse to the IPv4 from the portal:
http://203.0.113.10/phpinfo.php
You should see the PHP information page, with mysqli or pdo_mysql listed.
Delete the file as soon as you have checked it. Leaving phpinfo.php on a public vhost shows versions and paths to anyone who finds the URL.
sudo rm /var/www/html/phpinfo.php
Point a name at this VPS
The default page on the IPv4 is enough to prove the stack. A public site needs a name.
- In the portal, open Domains → the domain → DNS. AtlasDNS is the default.
- Set the apex
Arecord (andwwwif you use it) to this VPS IPv4. - Our nameservers, when the domain is on AtlasDNS:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
Full walkthrough: Point your domain at your hosting. Then add a virtual host so Apache answers on that name: Set up Apache virtual hosts.
There is no AutoSSL on a stock VPS. After the name points here, issue TLS with Certbot.
AlmaLinux or Rocky Linux
Package names and the firewall differ. The idea is the same: one web server, one database engine, PHP as an Apache module.
sudo dnf install -y httpd mariadb-server php php-mysqlnd php-cli php-mbstring php-xml php-curl php-gd php-zip
sudo systemctl enable --now httpd
sudo systemctl enable --now mariadb
sudo mysql_secure_installation
If firewalld is running:
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
The document root is /var/www/html. Site snippets live under /etc/httpd/conf.d/ instead of sites-available. Status commands use httpd and mariadb.
If PHP pages return 403 after a fresh AlmaLinux or Rocky install, SELinux may be blocking the files you copied in. Keep the site under /var/www/ and restore the context:
sudo restorecon -Rv /var/www/html
Still blocked? Open a support ticket and tell us the image and what sudo getenforce printed.
If something goes wrong
Address already in use on port 80 or 443
Something else is bound there (often Nginx). Check:
sudo ss -tlnp | grep -E ':80|:443'
Stop the other web server, or pick one stack and stay with it.
Apache is running but .php downloads or shows source
libapache2-mod-php is missing, or the versioned module is off. Re-run the install line above, then sudo a2query -m | grep php and sudo systemctl reload apache2.
a2enmod php failed
That name is not a module. Use php8.3 (or whatever php -v reports), or reinstall libapache2-mod-php.
The database service will not stay running
sudo systemctl status mariadb
sudo journalctl -u mariadb -n 50 --no-pager
Use mysql in both commands if that is the unit on this box. Open a support ticket and paste that output (no passwords).
Browser cannot reach the default page
sudo systemctl is-active apache2should printactive.curl -I http://127.0.0.1should succeed on the server.sudo ufw statusshould allow 80/tcp (and 443/tcp once you want HTTPS).- Browse to the IPv4 shown on the VPS in the portal, not a hostname you have not pointed yet.
The app cannot connect to MariaDB
- Host in the app config must be
localhost(or127.0.0.1). - Username, database name, and password must match what you created. There is no cPanel prefix on a VPS.
- Confirm the user host:
SELECT user, host FROM mysql.user;
Still stuck? Open a support ticket. Tell us the VPS service and what sudo systemctl status apache2 and sudo systemctl status mariadb printed. Do not send database passwords in the ticket.
What to do next
- Name-based sites: Set up Apache virtual hosts
- TLS: Get a Free SSL Certificate with Certbot
- Host firewall: Set up a UFW firewall on Ubuntu
- Automatic package patches: Enable Automatic Security Updates
- WordPress on this VPS: Install WordPress (VPS section)
- Broader habits: Keep your website secure
Unsure about a step? Open a support ticket and we will walk through it with you.