Runtime
| Component | Requirement | Recommendation |
|---|---|---|
| PHP | 8.1 or newer | A currently supported PHP branch with security updates |
| Database | MySQL-compatible, InnoDB | Dedicated database and user; strict mode disabled for the current installer |
| Web server | Apache or Nginx | HTTPS, URL rewriting, compression, and sensible static-asset caching |
| Scheduler | PHP CLI | Run every five minutes; do not expose scheduler scripts publicly |
| Memory | 128 MB minimum | 256 MB or more for reports, imports, updates, and large attachments |
PHP extensions
The installer verifies cURL with SSL, JSON, PDO, PDO MySQL, GD, XML, and Sodium. Sodium is required to authenticate signed license responses; a server without it must not proceed past preflight. WBAMS also benefits from OpenSSL, Mbstring, Intl, Fileinfo, and ZIP where available.
php -v
php -m
php -r "echo PHP_VERSION, PHP_EOL;"
Filesystem
The web-server user must be able to write to the configured compiled-template, attachment, download, and storage locations. Keep sensitive storage outside the public document root whenever practical. Never grant broad world-write permissions to the whole application tree.
OPcache
OPcache is recommended in production after deployment is stable. Disable CLI OPcache during maintenance and release validation if the environment shows stale code or CLI crashes. Reset the web-server cache after deploying changed PHP files.
php -d opcache.enable_cli=0 install/bin/installer.php --status
Network and DNS
- Resolve the public hostname to the WBAMS web server.
- Issue a valid TLS certificate and redirect HTTP to HTTPS.
- Allow outbound HTTPS for license verification, gateways, identity providers, analytics, and update metadata.
- Maintain a current CA certificate store; never work around a TLS failure by disabling certificate verification.
- Restrict database access to the application host or private network.
- Configure trusted proxy addresses before honoring forwarded client-IP headers.