A collection of production-ready WordPress Docker images optimized for Kubernetes deployments with enhanced PHP settings, automation capabilities, security hardening, and dynamic hostname support.
mcloudllc/wordpress:php8.4-apacheProduction-ready WordPress with optimized PHP configuration based on official wordpress:php8.4-apache.
Key Features:
PHP Configuration:
| Setting | Value | Description |
|---|---|---|
memory_limit | 512M | Total memory available to PHP scripts |
upload_max_filesize | 64M | Maximum file upload size |
post_max_size | 128M | Maximum POST request size |
max_execution_time | 120 | Script execution timeout (seconds) |
max_input_time | 120 | Input parsing timeout (seconds) |
max_input_vars | 3000 | Maximum input variables (for page builders) |
opcache.enable | 1 | PHP OPcache enabled |
opcache.memory_consumption | 128 | OPcache memory allocation |
Security Hardening:
| Feature | Description |
|---|---|
| Disabled Functions | exec, passthru, shell_exec, system, proc_open, popen |
expose_php | Off - Don't reveal PHP version |
allow_url_fopen | Off - Disable remote file access |
open_basedir | Restricted to /var/www/html:/tmp |
| Security Headers | X-Frame-Options, X-Content-Type-Options, X-XSS-Protection |
| ServerTokens | Prod - Minimal server info exposed |
| Uploads Protection | Script execution blocked in uploads directory |
Dynamic URL Environment Variables:
| Variable | Default | Description |
|---|---|---|
WP_DYNAMIC_URL | true | Enable dynamic hostname support |
WP_ALLOW_ANY_HOST | true | Allow any incoming hostname |
WP_ALLOWED_HOSTS | - | Comma-separated whitelist (supports wildcards: *.example.com) |
MEMCACHED_HOST | - | Memcached server hostname for sessions |
MEMCACHED_PORT | 11211 | Memcached server port |
mcloudllc/wordpress:cliEnhanced WP-CLI image optimized for automation and management operations.
Key Features:
Optimized For:
mcloudllc/wordpress:initSpecialized init container for automated WordPress installation and configuration in Kubernetes.
Key Features:
What It Does:
The images include a must-use plugin that enables WordPress to respond to any incoming hostname. This is useful for:
dynamic-url.php must-use plugin intercepts all URL generationHTTP_HOST or X-Forwarded-Host headershome_url() and site_url() to match the incoming requestX-Forwarded-Proto header (for reverse proxy setups)The plugin includes host validation to prevent host header injection attacks:
WP_ALLOWED_HOSTS environment variable to restrict allowed hostnames*.example.comlocalhost and 127.0.0.1 for developmentversion: '3.8'
services:
wordpress:
image: mcloudllc/wordpress:php8.4-apache
ports:
- "8080:80"
environment:
WORDPRESS_DB_HOST: db:3306
WORDPRESS_DB_NAME: wordpress
WORDPRESS_DB_USER: wordpress
WORDPRESS_DB_PASSWORD: your_password
volumes:
- wordpress_data:/var/www/html
depends_on:
- db
db:
image: mariadb:12
environment:
MYSQL_ROOT_PASSWORD: root_password
MYSQL_DATABASE: wordpress
MYSQL_USER: wordpress
MYSQL_PASSWORD: your_password
volumes:
- db_data:/var/lib/mysql
volumes:
wordpress_data:
db_data:
apiVersion: apps/v1
kind: Deployment
metadata:
name: wordpress
spec:
replicas: 2
selector:
matchLabels:
app: wordpress
template:
metadata:
labels:
app: wordpress
spec:
initContainers:
- name: wordpress-install
image: mcloudllc/wordpress:init
env:
- name: WORDPRESS_DB_HOST
value: mariadb:3306
- name: WORDPRESS_DB_NAME
value: wordpress
- name: WORDPRESS_DB_USER
valueFrom:
secretKeyRef:
name: wordpress-db
key: username
- name: WORDPRESS_DB_PASSWORD
valueFrom:
secretKeyRef:
name: wordpress-db
key: password
- name: WORDPRESS_ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: wordpress-admin
key: password
- name: WORDPRESS_SITE_URL
value: https://mysite.com
- name: WORDPRESS_TITLE
value: "My Awesome Site"
- name: WORDPRESS_PLUGINS
value: "akismet:activate,jetpack:activate"
- name: WORDPRESS_THEMES
value: "twentytwentyfour"
- name: WORDPRESS_ACTIVE_THEME
value: "twentytwentyfour"
- name: WP_DYNAMIC_URL
value: "true"
- name: WP_ALLOW_ANY_HOST
value: "true"
volumeMounts:
- name: wordpress-data
mountPath: /var/www/html
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 250m
memory: 512Mi
containers:
- name: wordpress
image: mcloudllc/wordpress:php8.4-apache
ports:
- containerPort: 80
env:
- name: WORDPRESS_DB_HOST
value: mariadb:3306
- name: WORDPRESS_DB_NAME
value: wordpress
- name: WORDPRESS_DB_USER
valueFrom:
secretKeyRef:
name: wordpress-db
key: username
- name: WORDPRESS_DB_PASSWORD
valueFrom:
secretKeyRef:
name: wordpress-db
key: password
volumeMounts:
- name: wordpress-data
mountPath: /var/www/html
resources:
requests:
cpu: 250m
memory: 512Mi
limits:
cpu: 500m
memory: 1Gi
volumes:
- name: wordpress-data
persistentVolumeClaim:
claimName: wordpress-pvc
# Install a plugin
docker run --rm \
-v $(pwd):/var/www/html \
mcloudllc/wordpress:cli \
plugin install akismet --activate
# Export database
docker run --rm \
-v $(pwd):/var/www/html \
-e WORDPRESS_DB_HOST=db:3306 \
mcloudllc/wordpress:cli \
db export backup.sql
# Search and replace URLs
docker run --rm \
-v $(pwd):/var/www/html \
mcloudllc/wordpress:cli \
search-replace 'http://oldsite.com' 'https://newsite.com'
# Update all plugins
docker run --rm \
-v $(pwd):/var/www/html \
mcloudllc/wordpress:cli \
plugin update --all
Standard WordPress environment variables:
WORDPRESS_DB_HOST - Database host (required)WORDPRESS_DB_NAME - Database name (required)WORDPRESS_DB_USER - Database user (required)WORDPRESS_DB_PASSWORD - Database password (required)WORDPRESS_TABLE_PREFIX - Table prefix (default: wp_)WORDPRESS_DEBUG - Enable debug mode (default: 0)WORDPRESS_CONFIG_EXTRA - Additional wp-config.php definesRequired:
WORDPRESS_DB_HOST - Database host and port (e.g., mariadb:3306)WORDPRESS_DB_NAME - Database nameWORDPRESS_DB_USER - Database usernameWORDPRESS_DB_PASSWORD - Database passwordWORDPRESS_ADMIN_PASSWORD - WordPress admin passwordOptional:
WORDPRESS_SITE_URL - Site URL (default: http://localhost)WORDPRESS_TITLE - Site title (default: My WordPress Site)WORDPRESS_ADMIN_USER - Admin username (default: admin)WORDPRESS_ADMIN_EMAIL - Admin email (default: [email protected])WORDPRESS_PLUGINS - Plugins to install (format: plugin1:activate,plugin2:noactivate)WORDPRESS_THEMES - Themes to install (format: theme1,theme2)WORDPRESS_ACTIVE_THEME - Theme slug to activateWP_DYNAMIC_URL - Enable dynamic URL support (default: true)WP_ALLOW_ANY_HOST - Allow any incoming hostname (default: true)WP_ALLOWED_HOSTS - Comma-separated whitelist of allowed hostnamesFORCE_SSL_ADMIN - Force HTTPS for admin (default: true)WP_DEBUG - Enable WordPress debug mode (default: false)WP_DEBUG_LOG - Enable debug logging (default: false)| Image | Tags | Description |
|---|---|---|
| WordPress | php8.4-apache, php8.4-apache-<sha>, latest | Latest stable with PHP 8.4 |
| WP-CLI | cli, cli-<sha> | Latest WP-CLI build |
| Init Container | init, init-<sha> | Latest init container |
All images use the same repository with different tags: mcloudllc/wordpress:<tag>
WordPress Container:
WP-CLI Container:
Init Container:
The WordPress image includes a built-in health check:
HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \
CMD curl -f http://localhost/readme.html || exit 1
resources:
requests:
cpu: 250m
memory: 512Mi
limits:
cpu: 500m
memory: 1Gi
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 250m
memory: 512Mi
All images can be scanned for vulnerabilities:
# Using Trivy
trivy image mcloudllc/wordpress:php8.4-apache
trivy image mcloudllc/wordpress:cli
trivy image mcloudllc/wordpress:init
# Using Docker Scout
docker scout cves mcloudllc/wordpress:php8.4-apache
GPL-2.0 - Same as WordPress and WP-CLI
Content type
Image
Digest
sha256:ba9565b98…
Size
259.9 MB
Last updated
8 months ago
docker pull mcloudllc/wordpress