Base image Alpine 3.17: Docker Hub or GitHub
XDEBUG=1The image runs as root or as any UID/GID, for example with Docker Swarm:
services:
php:
image: australproject/php:8.1
user: "3001:3001"
The configuration is rendered at start-up into /tmp/php (writable by any user) from templates stored in the image. When the container is not root, user/group are not set in the FPM pool and chown / su-exec are skipped. Mounted directories must already be writable by the chosen UID.
Quick test:
docker run --rm -u 3001:3001 -e SCRIPT_AUTO=0 australproject/php:8.1 php -i | grep -E "Loaded Configuration|post_max_size"
Application
| Variable | Default | Description |
|---|---|---|
APP_ENV | prod | prod or dev |
APP_DEBUG | false | 0/false or 1/true; enables display_errors and E_ALL |
XDEBUG | 0 | 1 loads Xdebug 3 (client port 9000) |
SCRIPT_AUTO | 1 | 1 runs script-auto/run.sh if it exists. Set 0 on cron and secondary services |
CREATE_LOG_DIR | 0 | 1/true creates docker-log/php in the website directory at start-up. Not created by default |
CREATE_CACHE_DIR | 0 | 1/true creates var/cache in the website directory at start-up. Not created by default |
PHP (php.ini)
| Variable | Default |
|---|---|
PHP_MEMORY_LIMIT | 256M |
PHP_MAX_EXECUTION_TIME | 120 |
PHP_MAX_INPUT_TIME | 60 |
PHP_MAX_INPUT_VARS | 5000 |
PHP_POST_MAX_SIZE | 512M |
PHP_UPLOAD_MAX_FILESIZE | 512M |
PHP_SESSION_SAVE_PATH | /tmp |
OPCACHE_ENABLED | 1 |
OPCACHE_VALIDATE_TIMESTAMPS | 1 |
OPCACHE_MEMORY | 256 (MB) |
OPCACHE_REVALIDATE_FREQ | 2 (seconds) |
OPCACHE_VALIDATE_TIMESTAMPS=0is only safe for immutable deployments: files edited over SFTP would not be reloaded.
PHP-FPM (pool www)
| Variable | Default |
|---|---|
FPM_PM | dynamic |
FPM_MAX_CHILDREN | 20 |
FPM_START_SERVERS | 4 |
FPM_MIN_SPARE_SERVERS | 4 |
FPM_MAX_SPARE_SERVERS | 16 |
FPM_MAX_REQUESTS | 500 |
FPM_REQUEST_TERMINATE_TIMEOUT | 300s |
FPM_LOG_LEVEL | notice |
Keep
FPM_MAX_CHILDREN×PHP_MEMORY_LIMITbelow the container memory limit.
Mount a directory on /overrides (read-only is fine):
Path in /overrides | Effect |
|---|---|
php.ini | Replaces the whole php.ini (copied as is, no variable substitution) |
php-fpm.conf | Replaces the whole php-fpm.conf |
www.conf | Replaces the whole pool configuration |
conf.d/*.ini | Extra PHP settings, loaded after the base configuration |
pool.d/*.conf | Extra FPM pools, added to the base configuration |
For small changes, prefer drop-ins:
; /overrides/conf.d/custom.ini
date.timezone = Europe/Paris
session.save_handler = redis
services:
php:
volumes:
- ./php-overrides:/overrides:ro
Everything goes to the container output (docker logs): FPM errors, PHP errors (/proc/self/fd/2) and workers' stdout/stderr (catch_workers_output).
The default /tmp is not shared between replicas. Use a shared store, for example Redis (extension included):
PHP_SESSION_SAVE_PATH=tcp://redis:6379
and add session.save_handler = redis in /overrides/conf.d/.
Add a script-auto/run.sh file in the project path. It runs at container start-up when SCRIPT_AUTO=1 (as www-data when the container is root, as the current user otherwise).
Supercronic is included and writes job output to stdout/stderr, so it appears in docker logs. Run it in a dedicated service:
services:
cron:
image: australproject/php:8.1
command: supercronic /etc/crontab
environment:
- SCRIPT_AUTO=0
healthcheck:
disable: true
The image checks that FPM listens on port 9900. Disable it on services that do not run FPM (cron).
The commit message must follow the Conventional Commits specification. The following types are allowed:
update: Updatefix: Bug fixfeat: New featuredocs: Change in the documentationspec: Spec changetest: Test-related changeperf: Performance optimizationExamples:
update : Something
fix: Fix something
feat: Introduce X
docs: Add docs for X
spec: Z disambiguation
See License
Created by Matthieu Beurel. Sponsored by Yipikai Studio.
Content type
Image
Digest
sha256:bd1fa36fc…
Size
123.1 MB
Last updated
about 2 hours ago
docker pull australproject/php:8.1