How to Install a LAMP Server on Ubuntu
Set up Apache, MySQL and PHP on a fresh Ubuntu server, with the security steps most guides leave out. Every command explained, and a check after each one.
LAMP means Linux, Apache, MySQL and PHP. It is the stack behind most of the web, and it is what nearly every other guide on this site assumes you already have.
This takes about 30 minutes. Every command is explained, and after each step there is a way to check it actually worked — so you never get three steps past a silent failure.
What you need
- A VPS running Ubuntu 22.04 or 24.04
- The root password or SSH key from your provider
- An SSH client — the Terminal on Mac and Linux, or PuTTY on Windows
A $5 VPS with 1 GB of RAM is fine for learning. Choose 2 GB if you plan to run WordPress or NextCloud on it later.
Step 1: Connect and update
ssh root@YOUR.SERVER.IP
Then bring the system up to date before installing anything:
sudo apt update
sudo apt upgrade -y
update refreshes the list of available packages; upgrade actually installs the newer ones. Running upgrade without update first is a common mistake and does very little.
Step 2: Create a normal user and stop using root
Most tutorials skip this. Do not. Working as root means one mistyped command can destroy the server, and every automated attack on the internet is trying to log in as root right now.
adduser yourname
usermod -aG sudo yourname
Open a second terminal and confirm you can log in as the new user before closing the first one:
ssh yourname@YOUR.SERVER.IP
sudo whoami
If that prints root, the account has admin rights and you can safely stop using the root login.
Step 3: Turn on the firewall
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status
Allow OpenSSH before enabling the firewall. In the wrong order you lock yourself out of your own server and have to use the provider's rescue console.
Step 4: Install Apache
sudo apt install apache2 -y
Let it through the firewall:
sudo ufw allow in "Apache Full"
Check it worked: open http://YOUR.SERVER.IP in a browser. You should see the Apache default page. If you do not, Apache is not running or the firewall rule did not apply — check with sudo systemctl status apache2.
Step 5: Install MySQL
sudo apt install mysql-server -y
Now secure it. This step matters — a default MySQL install has a test database and permissive settings:
sudo mysql_secure_installation
Answer as follows:
- Validate password plugin? Yes, and choose level 2 (strong)
- Remove anonymous users? Yes
- Disallow root login remotely? Yes
- Remove test database? Yes
- Reload privilege tables? Yes
Check it worked:
sudo mysql -e "SELECT VERSION();"
Step 6: Install PHP
sudo apt install php libapache2-mod-php php-mysql -y
That is the minimum. Real applications need more extensions, so install the common ones now and save yourself a debugging session later:
sudo apt install php-curl php-gd php-mbstring php-xml php-zip php-intl php-bcmath -y
Restart Apache so it picks up PHP:
sudo systemctl restart apache2
Check it worked:
php -v
Step 7: Test PHP through the web server
php -v only proves the command line works. Apache is separate:
echo "<?php phpinfo(); ?>" | sudo tee /var/www/html/info.php
Open http://YOUR.SERVER.IP/info.php. You should see a purple PHP information page.
Now delete it:
sudo rm /var/www/html/info.php
That page lists your PHP version, every extension and your file paths. Leaving it up hands an attacker a map of your server. People forget this constantly.
Step 8: Set up a virtual host for your site
The default setup serves everything from one folder. A virtual host lets you host a real domain, and more than one site later.
sudo mkdir -p /var/www/yourdomain.com
sudo chown -R $USER:$USER /var/www/yourdomain.com
Create the config file:
sudo nano /etc/apache2/sites-available/yourdomain.com.conf
Put this in:
<VirtualHost *:80>
ServerName yourdomain.com
ServerAlias www.yourdomain.com
DocumentRoot /var/www/yourdomain.com
<Directory /var/www/yourdomain.com>
AllowOverride All
Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined
</VirtualHost>
AllowOverride All matters — without it .htaccess files are ignored, which breaks WordPress permalinks and most PHP applications.
Enable the site and switch off the default:
sudo a2ensite yourdomain.com.conf
sudo a2dissite 000-default.conf
sudo apache2ctl configtest
sudo systemctl reload apache2
Always run configtest before reloading. If it says anything other than Syntax OK, fix it first — reloading a broken config takes the server offline.
Step 9: Enable mod_rewrite
Nearly every PHP application needs it for clean URLs, and it is off by default:
sudo a2enmod rewrite
sudo systemctl restart apache2
Step 10: Add SSL
Never run a real site on plain HTTP. Certificates are free and take two minutes — see how to install a free SSL certificate on Ubuntu.
Useful commands to keep
| Command | What it does |
|---|---|
sudo systemctl status apache2 | Is Apache running? |
sudo systemctl restart apache2 | Restart after config changes |
sudo apache2ctl configtest | Check config before reloading |
sudo tail -f /var/log/apache2/error.log | Watch errors as they happen |
sudo mysql | Open the database console |
php -m | List installed PHP extensions |
The tail -f one is the most useful on this page. When something breaks, run it, reload the page, and read what appears.
Common problems
The browser shows nothing at all
Either Apache is not running or the firewall is blocking it. Check sudo systemctl status apache2 and sudo ufw status. Some providers also have their own firewall in the control panel that has to be opened separately.
PHP files download instead of running
Apache does not know about PHP. Install libapache2-mod-php and restart Apache.
"403 Forbidden"
A permissions problem. Apache runs as www-data and must be able to read the folder:
sudo chown -R www-data:www-data /var/www/yourdomain.com
sudo chmod -R 755 /var/www/yourdomain.com
.htaccess rules are ignored
AllowOverride All is missing from the virtual host, or mod_rewrite is not enabled. Both are needed.
"Access denied for user root@localhost"
On modern Ubuntu the MySQL root account uses socket authentication, so it only works with sudo mysql. Create a separate user for your applications rather than fighting this:
sudo mysql -e "CREATE USER 'appuser'@'localhost' IDENTIFIED BY 'strongpassword'; GRANT ALL ON appdb.* TO 'appuser'@'localhost'; FLUSH PRIVILEGES;"
Locked out by the firewall
You enabled UFW without allowing SSH. Use the provider's web console or VNC to get in, then run sudo ufw allow OpenSSH.
Where to go next
With LAMP running you can install almost anything. The usual next steps: