PrestaShop is an open-source e-commerce platform written in PHP, popular in Europe for its large module and theme marketplace and its modest hardware requirements. In this tutorial you will install PrestaShop 9 on Ubuntu 24.04 with Nginx, PHP 8.3 FPM and MariaDB, configure Nginx with the rewrite rules PrestaShop needs, enable HTTPS with Let's Encrypt and finish the installation securely.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 2 GB of RAM and 20 GB of free disk space. Use 4 GB or more for catalogs with thousands of products.
- A non-root user with
sudoprivileges. - A domain such as
your_domainwith a DNS A record (and optionallywww) pointing toyour_server_ip.
NotePrestaShop 9 requires PHP 8.1 to 8.4, so it runs on the PHP 8.3 that Ubuntu 24.04 ships. PrestaShop 8.x only supports up to PHP 8.1 and would need a third-party PHP repository on this release, which this guide avoids.
Step 1 - Installing Nginx, PHP 8.3 and MariaDB
Install the web server, PHP-FPM with the extensions PrestaShop checks for, MariaDB and unzip:
sudo apt update
sudo apt install nginx mariadb-server unzip php8.3-fpm php8.3-mysql php8.3-curl php8.3-gd php8.3-intl php8.3-mbstring php8.3-xml php8.3-zip php8.3-bcmath
Verify that the services are running:
systemctl is-active nginx php8.3-fpm mariadb
active
active
active
Allow HTTP and HTTPS through UFW if it is enabled:
sudo ufw allow OpenSSH
sudo ufw allow 'Nginx Full'
Step 2 - Configuring PHP for PrestaShop
PrestaShop needs more memory, bigger uploads for product images and module archives, and a higher max_input_vars than the PHP defaults, because some admin forms (translations, carriers, combinations) post thousands of fields. Create a drop-in file for PHP-FPM:
sudo nano /etc/php/8.3/fpm/conf.d/99-prestashop.ini
memory_limit=512M
upload_max_filesize=32M
post_max_size=32M
max_input_vars=10000
max_execution_time=300
opcache.memory_consumption=256
opcache.max_accelerated_files=20000
Restart PHP-FPM and check one of the values:
sudo systemctl restart php8.3-fpm
php-fpm8.3 -i | grep max_input_vars
max_input_vars => 10000 => 10000
Step 3 - Creating the database
Ubuntu's MariaDB authenticates the root account through the Unix socket, so you can open the client with sudo without a password. Create a database and a dedicated user for the store, replacing your_db_password with a strong password:
sudo mariadb
CREATE DATABASE prestashop CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'prestashop'@'localhost' IDENTIFIED BY 'your_db_password';
GRANT ALL PRIVILEGES ON prestashop.* TO 'prestashop'@'localhost';
FLUSH PRIVILEGES;
EXIT;
Check that the new user can log in:
mariadb -u prestashop -p -e "SHOW DATABASES;"
+--------------------+
| Database |
+--------------------+
| information_schema |
| prestashop |
+--------------------+
Step 4 - Downloading PrestaShop
PrestaShop releases are published on GitHub. Open https://github.com/PrestaShop/PrestaShop/releases, find the latest 9.x release and note its version number. Download the release archive to a temporary directory, replacing 9.0.0 with that version:
cd /tmp
PS_VERSION=9.0.0
wget "https://github.com/PrestaShop/PrestaShop/releases/download/${PS_VERSION}/prestashop_${PS_VERSION}.zip"
If the download returns 404, the asset has a different name in that release: copy the exact link of the .zip asset from the release page instead.
The release archive contains another archive, prestashop.zip, with the actual application. Extract the outer archive, then extract the inner one into the web root:
unzip "prestashop_${PS_VERSION}.zip" -d /tmp/prestashop-release
sudo mkdir -p /var/www/prestashop
sudo unzip -q /tmp/prestashop-release/prestashop.zip -d /var/www/prestashop
PHP-FPM runs as www-data and must be able to write to the cache, uploads, modules and themes directories. Give it ownership of the application:
sudo chown -R www-data:www-data /var/www/prestashop
ls -d /var/www/prestashop/admin /var/www/prestashop/install /var/www/prestashop/index.php
/var/www/prestashop/admin /var/www/prestashop/index.php /var/www/prestashop/install
Step 5 - Configuring Nginx
PrestaShop routes friendly URLs through index.php, but product images use SEO-friendly paths like /12-home_default/blue-shirt.jpg that Nginx must rewrite to the real files under /img/p/. The rules below follow the configuration recommended in the PrestaShop developer documentation.
Create the server block:
sudo nano /etc/nginx/sites-available/prestashop
server {
listen 80;
listen [::]:80;
server_name your_domain www.your_domain;
root /var/www/prestashop;
index index.php;
client_max_body_size 32M;
# Product and category images with friendly URLs
rewrite ^/(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$1$2.jpg last;
rewrite ^/(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$1$2$3.jpg last;
rewrite ^/(\d)(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$3/$1$2$3$4.jpg last;
rewrite ^/(\d)(\d)(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$1$2$3$4$5.jpg last;
rewrite ^/(\d)(\d)(\d)(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$1$2$3$4$5$6.jpg last;
rewrite ^/(\d)(\d)(\d)(\d)(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$6/$1$2$3$4$5$6$7.jpg last;
rewrite ^/(\d)(\d)(\d)(\d)(\d)(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$6/$7/$1$2$3$4$5$6$7$8.jpg last;
rewrite ^/(\d)(\d)(\d)(\d)(\d)(\d)(\d)(\d)(-[\w-]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$6/$7/$8/$1$2$3$4$5$6$7$8$9.jpg last;
rewrite ^/c/([\w.-]+)/.+\.jpg$ /img/c/$1.jpg last;
# Web service API
rewrite ^/api/?(.*)$ /webservice/dispatcher.php?url=$1 last;
location / {
try_files $uri $uri/ /index.php$is_args$args;
}
# Block hidden files and internal directories
location ~ /\. {
deny all;
}
location ~ ^/(app|bin|cache|classes|config|controllers|docs|localization|override|src|tests|tools|translations|var|vendor)/ {
deny all;
}
location ~ \.(tpl|twig|yml|log|sql)$ {
deny all;
}
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.3-fpm.sock;
}
location ~* \.(css|js|gif|jpe?g|png|webp|avif|svg|woff2?|ico)$ {
expires 30d;
access_log off;
try_files $uri =404;
}
}
The deny rules keep configuration files, logs and templates out of reach even though they live inside the web root. Enable the site, disable the default one and reload Nginx:
sudo ln -s /etc/nginx/sites-available/prestashop /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo nginx -t
sudo systemctl reload nginx
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
Step 6 - Enabling HTTPS with Let's Encrypt
Get the certificate before running the installer, so the store is configured with HTTPS from the start and the admin password is never sent in clear text. Install Certbot and request a certificate for both names:
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d your_domain -d www.your_domain
Certbot adds the TLS settings and an HTTP to HTTPS redirect to the server block, and installs a systemd timer for renewals. Test renewal:
sudo certbot renew --dry-run
Step 7 - Running the web installer
Open https://your_domain/install in your browser. The installer walks you through these screens:
- Choose your language and accept the licenses.
- System compatibility: every check should be green. A red item usually means a missing PHP extension or a directory
www-datacannot write; fix it and click Refresh. - Store information: enter the shop name, activity, country and the administrator account. Use a strong password and an email address you control.
- Content of your store: choose whether to install demo products. They help while you learn the admin, but you will delete them later.
- System configuration: enter
localhostas the server,prestashopas database name and login, andyour_db_password. Click Test your database connection now before continuing.
The installation takes a few minutes. When it finishes, PrestaShop renames the admin directory to a random name such as admin123abc so bots cannot find the login page. Note this name, because it is part of your admin URL.
For security, the installer directory must not remain on the server. Remove it if it still exists:
sudo rm -rf /var/www/prestashop/install
ls -d /var/www/prestashop/admin*
/var/www/prestashop/admin123abc
Step 8 - Routing the admin through Nginx
The PrestaShop back office is a Symfony application that also routes its URLs through its own index.php. Tell Nginx about the renamed directory. Open the site configuration again:
sudo nano /etc/nginx/sites-available/prestashop
Add this block inside the HTTPS server block, next to location /, replacing admin123abc with your directory name:
location /admin123abc/ {
try_files $uri $uri/ /admin123abc/index.php$is_args$args;
}
Test and reload:
sudo nginx -t
sudo systemctl reload nginx
Sign in at https://your_domain/admin123abc/. In the back office, go to Shop Parameters > General and make sure SSL is enabled for the whole store if your version shows that option. Then go to Shop Parameters > Traffic & SEO and enable Friendly URL. Open a product page on the storefront and confirm that the URL is readable and the product images load: if images are missing, the rewrite rules from Step 5 are not being applied.
Step 9 - Final performance and security settings
In the back office, open Advanced Parameters > Performance and check that:
- Debug mode is set to No.
- Template compilation is set to Never recompile template files once you have finished editing the theme.
- Cache is set to Yes.
- Smart cache for CSS and JavaScript is enabled under CCC (Combine, Compress and Cache).
After changing these settings, click Clear cache in the top right corner of the same page.
PrestaShop runs several tasks (currency rate updates, search reindexing, some module jobs) through cron URLs provided by the modules that need them. When a module gives you such a URL, schedule it with the crontab of www-data, for example with curl -fsS every hour, rather than relying on visitors to trigger it.
Finally, schedule backups of both the database and the img/, upload/ and download/ directories, and store them off the server. A simple nightly database dump:
sudo mariadb-dump --single-transaction prestashop | gzip > prestashop-$(date +%F).sql.gz
Troubleshooting
The installer shows a blank page or a 500 error. Read sudo tail -n 50 /var/log/nginx/error.log and sudo journalctl -u php8.3-fpm -n 50. A missing PHP extension or wrong file ownership are the usual causes; repeat Steps 1 and 4.
Product images return 404 with friendly URLs enabled. The image rewrite rules are missing or were placed outside the HTTPS server block that Certbot created. Check that they are in the server block that listens on 443.
The back office shows 404 Not Found after login. The location block for the admin directory is missing or uses the old name admin. Repeat Step 8 with the real directory name.
Invalid token or session errors in the back office. Usually the store URL does not match the one you use, for example www versus non-www. Use the domain configured in Shop Parameters > Traffic & SEO > Set shop URL, and redirect the other one.
Conclusion
You have installed PrestaShop 9 on Ubuntu 24.04 with Nginx, PHP 8.3 and MariaDB, served over HTTPS, with the installer removed and the admin directory routed correctly. As next steps, configure your payment and shipping modules, set up transactional email through an SMTP provider under Advanced Parameters > E-mail, and add a Redis or Memcached server if your catalog grows large.
