Joomla is an open source PHP content management system with built-in multilingual support, user access levels and a large extension directory. In this tutorial you will install Joomla on Ubuntu 24.04 with Apache, PHP-FPM 8.3 and MariaDB, complete the web installer, enable search engine friendly URLs, and secure the site with a free Let's Encrypt certificate.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS with at least 1 GB of RAM, for example a CubePath VPS.
  • A non-root user with sudo privileges.
  • A domain name with an A record pointing to the server, referred to as your_domain.
  • Ports 80 and 443 open to the internet.

Current Joomla releases require PHP 8.1 or newer (PHP 8.3 for Joomla 6) and MariaDB 10.4 or newer. Ubuntu 24.04 ships PHP 8.3 and MariaDB 10.11, so no third-party repositories are needed.

Step 1 - Installing Apache, PHP-FPM and MariaDB

Install the web server, PHP-FPM with the extensions Joomla checks for during installation, and the database server:

sudo apt update
sudo apt install apache2 php-fpm php-mysql php-xml php-gd php-mbstring php-curl php-zip php-intl mariadb-server unzip

Enable the Apache modules for PHP-FPM (proxy_fcgi), URL rewriting and HTTP headers, then activate the PHP-FPM configuration snippet:

sudo a2enmod proxy_fcgi setenvif rewrite headers
sudo a2enconf php8.3-fpm
sudo systemctl restart apache2

Check that all three services are running:

systemctl is-active apache2 php8.3-fpm mariadb
active
active
active

Open the firewall for SSH and web traffic:

sudo ufw allow OpenSSH
sudo ufw allow 'Apache Full'
sudo ufw enable

Step 2 - Adjusting PHP settings

Joomla's installer and system information page recommend a few PHP settings that differ from Ubuntu's defaults, in particular turning output buffering off. Put them in an override file so package upgrades do not revert them:

sudo nano /etc/php/8.3/fpm/conf.d/90-joomla.ini
memory_limit = 256M
upload_max_filesize = 32M
post_max_size = 32M
max_execution_time = 120
output_buffering = Off

Restart PHP-FPM and verify one of the values:

sudo systemctl restart php8.3-fpm
sudo php-fpm8.3 -i | grep ^output_buffering
output_buffering => 0 => 0

Step 3 - Creating the database

Open the MariaDB shell. On Ubuntu the root account authenticates through the system root user:

sudo mariadb

Create a database with full Unicode support and a user that can access only that database. Replace your_strong_password with a long random password:

CREATE DATABASE joomla CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'joomla'@'localhost' IDENTIFIED BY 'your_strong_password';
GRANT ALL PRIVILEGES ON joomla.* TO 'joomla'@'localhost';
FLUSH PRIVILEGES;
EXIT;

Confirm that the new user can connect:

mariadb -u joomla -p -e "SHOW DATABASES;"
+--------------------+
| Database           |
+--------------------+
| information_schema |
| joomla             |
+--------------------+

Step 4 - Downloading Joomla

Go to the official download page at https://downloads.joomla.org, choose the latest stable release and copy the link of the Full Package in ZIP format. Download it on the server, pasting the link between the quotes:

cd /tmp
wget -O joomla.zip "paste_the_full_package_link_here"

Extract the archive into the web root:

sudo mkdir -p /var/www/joomla
sudo unzip -q /tmp/joomla.zip -d /var/www/joomla

Joomla ships its Apache rules as htaccess.txt. Rename it to .htaccess so Apache applies them; this is required for search engine friendly URLs and blocks several common exploit patterns:

sudo mv /var/www/joomla/htaccess.txt /var/www/joomla/.htaccess

Joomla updates itself and installs extensions through the admin panel, so the web server user needs to own the files. Set the ownership and standard permissions (no world-writable files):

sudo chown -R www-data:www-data /var/www/joomla
sudo find /var/www/joomla -type d -exec chmod 755 {} +
sudo find /var/www/joomla -type f -exec chmod 644 {} +

Check that the files are in place and owned by www-data:

ls -ld /var/www/joomla/installation /var/www/joomla/.htaccess
drwxr-xr-x 6 www-data www-data 4096 Sep 25 10:12 /var/www/joomla/installation
-rw-r--r-- 1 www-data www-data 3006 Sep 25 10:12 /var/www/joomla/.htaccess

Step 5 - Configuring the Apache virtual host

Create a virtual host for the site:

sudo nano /etc/apache2/sites-available/joomla.conf
<VirtualHost *:80>
    ServerName your_domain
    ServerAlias www.your_domain
    DocumentRoot /var/www/joomla

    <Directory /var/www/joomla>
        Options FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>

    # Never execute PHP from the media upload directory
    <Directory /var/www/joomla/images>
        <FilesMatch "\.(php|phtml|phar)$">
            Require all denied
        </FilesMatch>
    </Directory>

    ErrorLog ${APACHE_LOG_DIR}/joomla_error.log
    CustomLog ${APACHE_LOG_DIR}/joomla_access.log combined
</VirtualHost>

Options FollowSymLinks without Indexes prevents Apache from listing directory contents, and the second Directory block stops uploaded PHP files in images/ from ever being executed. Enable the site, disable the default one and test the syntax:

sudo a2ensite joomla.conf
sudo a2dissite 000-default.conf
sudo apache2ctl configtest
Syntax OK

Reload Apache:

sudo systemctl reload apache2

Step 6 - Enabling HTTPS with Let's Encrypt

Get a certificate before running the web installer, so the administrator password is never sent over plain HTTP. Install Certbot with the Apache plugin:

sudo apt install certbot python3-certbot-apache

Request the certificate. Certbot creates an HTTPS copy of the virtual host (including the images restriction) and redirects HTTP to HTTPS:

sudo certbot --apache -d your_domain -d www.your_domain

Certificates renew automatically through a systemd timer. Test the renewal process:

sudo certbot renew --dry-run
Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/your_domain/fullchain.pem (success)

Step 7 - Running the web installer

Open https://your_domain in a browser. The Joomla installer starts automatically and asks for:

  1. Site name and language.
  2. Login data: the Super User's real name, username, password and email. Use a username other than admin and a password manager generated password.
  3. Database configuration: type MySQLi, host localhost, username joomla, the password from Step 3, database name joomla. Keep the random table prefix it proposes.

Click Install Joomla. When it finishes, the installer writes configuration.php and removes the installation directory. Verify on the server:

ls -d /var/www/joomla/installation 2>/dev/null || echo "installation directory removed"
installation directory removed

If the directory still exists, delete it with sudo rm -rf /var/www/joomla/installation, because leaving the installer reachable is a security risk. Finally, make sure the configuration file, which contains the database password, is not readable by other system users:

sudo chmod 640 /var/www/joomla/configuration.php

Step 8 - Configuring URLs and HTTPS in Joomla

Log in to the administrator panel at https://your_domain/administrator and open System > Global Configuration.

On the Site tab, under SEO Settings, set:

  • Search Engine Friendly URLs: Yes.
  • Use URL Rewriting: Yes. This works because you renamed htaccess.txt in Step 4 and allowed overrides in Apache. It removes index.php from the URLs.

On the Server tab, set Force HTTPS to Entire Site, and fill in the Mail Settings with your SMTP server so that password resets and notifications are delivered. Use the Send Test Mail button to confirm the SMTP settings.

Save and close. Test a friendly URL by requesting a page that does not exist:

curl -sI https://your_domain/this-page-does-not-exist | head -n 1
HTTP/2 404

A Joomla 404 page (and not an Apache "Not Found" page) confirms that rewrites reach Joomla.

Step 9 - Checking the system and updates from the command line

Joomla includes a console application, cli/joomla.php, which is useful for scripting and for checking the site over SSH. Run it as www-data so any files it writes keep the correct owner. Check for core updates:

sudo -u www-data php /var/www/joomla/cli/joomla.php core:check-updates

List all available commands with:

sudo -u www-data php /var/www/joomla/cli/joomla.php list

For day-to-day maintenance, apply core updates from System > Update > Joomla and extension updates from System > Update > Extensions, after taking a backup.

Troubleshooting

The installer shows red items in the pre-installation check. A PHP extension is missing or a setting is wrong. Install the missing php-* package, restart php8.3-fpm and reload the page.

Friendly URLs return Apache 404 errors. Either .htaccess is missing from /var/www/joomla, AllowOverride All is not set in both the HTTP and HTTPS virtual hosts, or mod_rewrite is not enabled.

Extensions fail to install with a permissions error. Some files are not owned by www-data, often after copying files as root. Repeat the chown command from Step 4.

Conclusion

Joomla is now running on Ubuntu 24.04 with Apache, PHP-FPM 8.3 and MariaDB, served over HTTPS with friendly URLs and hardened file permissions. As next steps, set up regular backups of the database and the /var/www/joomla directory, enable two-factor authentication for Super User accounts, and install a template for your site's design.