Phase 7 · Advanced & PortfolioModule 42~65 min read

Containers, CI/CD & Observability

Containerize PHP, automate quality and releases, and operate applications with logs, metrics, traces, and health checks.

What you'll learn

Package PHP consistently, automate every quality and release gate, and make running behavior observable. Containers define the runtime; CI/CD promotes verified artifacts; logs, metrics, traces, and health checks shorten detection and recovery.

By the end of this lesson, you'll be able to:

  • Build a production PHP container
  • Design a gated CI/CD pipeline and rollback
  • Instrument logs, metrics, traces, and health endpoints

Core mental model

Professional PHP is less about memorizing APIs and more about choosing a clear boundary for each responsibility. Use this table as a decision guide while reading the examples.

ConceptWhat it protectsDecision rule
Container imageImmutable runtime artifactPin base/runtime dependencies and run as non-root.
Pipeline gateAutomated release evidenceStop promotion when tests, analysis, security, or smoke checks fail.
ObservabilityExplain internal state from outputsCorrelate logs, metrics, and traces with request IDs.

Professional workflow

Build the feature in small, verifiable steps. Each step leaves the system in a state you can test.

  1. Describe the production delivery system boundary: its inputs, outputs, invariants, and expected failures.
  2. Implement the smallest happy path behind an explicit contract.
  3. Add validation and translate low-level failures into language the caller understands.
  4. Exercise the boundary with realistic data, then inspect output, logs, and resource cleanup.
  5. Refactor only after behavior is protected by a repeatable check.

Make the boundary visible

Name inputs, outputs, side effects, and failure cases before adding framework or infrastructure code. That habit keeps advanced PHP understandable as the application grows.

Guided code lab

Create a minimal runtime image

A multi-stage build installs production dependencies once and copies only the needed artifact.

Dockerfile
FROM composer:2 AS vendor
WORKDIR /app
COPY composer.json composer.lock ./
RUN composer install --no-dev --prefer-dist --no-scripts --no-interaction

FROM php:8.3-fpm-alpine
WORKDIR /var/www/html
COPY --from=vendor /app/vendor ./vendor
COPY . .
RUN chown -R www-data:www-data storage
USER www-data
CMD ["php-fpm", "-F"]

Gate the artifact in CI

The same revision must pass installation, analysis, tests, build, and a security-aware image scan before deployment.

.github/workflows/ci.yml
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: shivammathur/setup-php@v2
        with: { php-version: '8.3', coverage: none }
      - run: composer install --no-interaction --prefer-dist
      - run: composer check
      - run: docker build --tag course-app:\${{ github.sha }} .
      - run: trivy image --exit-code 1 course-app:\${{ github.sha }}

Production practice

Contract

One commit produces one content-addressed artifact promoted unchanged through environments with auditable approval and rollback.

Verification

Test the image, migration compatibility, health probes, telemetry correlation, canary criteria, and rollback in a staging environment.

Operations

Define service-level indicators, alerts with runbooks, retention/privacy rules, and an incident review loop.

Common failure mode

A health endpoint that always returns 200 proves only that routing works. Readiness must verify the process can serve its required dependencies within bounds.

Independent workshop

Containerize and deliver the course platform through a CI/CD pipeline with canary release and end-to-end telemetry.

Your finished workshop must include:

  • Hardened image and local composition
  • Quality/security/deploy pipeline with rollback
  • Dashboard, alert, trace example, and incident runbook

Definition of done

Run the happy path and at least two failure paths, explain one design tradeoff in a short README, and leave the code formatted and ready for review.

Recap & quick check

Key takeaways

  • Containers package runtime consistency.
  • CI produces evidence; CD controls promotion.
  • Immutable artifacts make rollback reliable.
  • Observability connects symptoms to causes.

Quick check

1. Why promote the same image?

2. What should readiness answer?

3. What correlates a log with a distributed trace?

Keep the workshop: later phases deliberately build on these boundaries, so today's small example can become part of your portfolio architecture.