What you'll learn
Package PHP consistently, automate every quality and release gate, and make running behavior observable. Containers define the runtime; CI/CD promotes verified artifacts; logs, metrics, traces, and health checks shorten detection and recovery.
By the end of this lesson, you'll be able to:
- Build a production PHP container
- Design a gated CI/CD pipeline and rollback
- Instrument logs, metrics, traces, and health endpoints
Core mental model
Professional PHP is less about memorizing APIs and more about choosing a clear boundary for each responsibility. Use this table as a decision guide while reading the examples.
| Concept | What it protects | Decision rule |
|---|---|---|
| Container image | Immutable runtime artifact | Pin base/runtime dependencies and run as non-root. |
| Pipeline gate | Automated release evidence | Stop promotion when tests, analysis, security, or smoke checks fail. |
| Observability | Explain internal state from outputs | Correlate logs, metrics, and traces with request IDs. |
Professional workflow
Build the feature in small, verifiable steps. Each step leaves the system in a state you can test.
- Describe the production delivery system boundary: its inputs, outputs, invariants, and expected failures.
- Implement the smallest happy path behind an explicit contract.
- Add validation and translate low-level failures into language the caller understands.
- Exercise the boundary with realistic data, then inspect output, logs, and resource cleanup.
- Refactor only after behavior is protected by a repeatable check.
Make the boundary visible
Guided code lab
Create a minimal runtime image
A multi-stage build installs production dependencies once and copies only the needed artifact.
FROM composer:2 AS vendor
WORKDIR /app
COPY composer.json composer.lock ./
RUN composer install --no-dev --prefer-dist --no-scripts --no-interaction
FROM php:8.3-fpm-alpine
WORKDIR /var/www/html
COPY --from=vendor /app/vendor ./vendor
COPY . .
RUN chown -R www-data:www-data storage
USER www-data
CMD ["php-fpm", "-F"]Gate the artifact in CI
The same revision must pass installation, analysis, tests, build, and a security-aware image scan before deployment.
jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: shivammathur/setup-php@v2
with: { php-version: '8.3', coverage: none }
- run: composer install --no-interaction --prefer-dist
- run: composer check
- run: docker build --tag course-app:\${{ github.sha }} .
- run: trivy image --exit-code 1 course-app:\${{ github.sha }}Production practice
Contract
One commit produces one content-addressed artifact promoted unchanged through environments with auditable approval and rollback.
Verification
Test the image, migration compatibility, health probes, telemetry correlation, canary criteria, and rollback in a staging environment.
Operations
Define service-level indicators, alerts with runbooks, retention/privacy rules, and an incident review loop.
Common failure mode
Independent workshop
Containerize and deliver the course platform through a CI/CD pipeline with canary release and end-to-end telemetry.
Your finished workshop must include:
- Hardened image and local composition
- Quality/security/deploy pipeline with rollback
- Dashboard, alert, trace example, and incident runbook
Definition of done
Recap & quick check
Key takeaways
- Containers package runtime consistency.
- CI produces evidence; CD controls promotion.
- Immutable artifacts make rollback reliable.
- Observability connects symptoms to causes.
Quick check
1. Why promote the same image?
2. What should readiness answer?
3. What correlates a log with a distributed trace?
Keep the workshop: later phases deliberately build on these boundaries, so today's small example can become part of your portfolio architecture.