- Knowledge
- technology
- OOP
- Tips
- Programming
- Tips
- Tutorial
- SEO
- Ranking
- Knowledge
- Special Day
- Seo
- Bug
- Data science
- Seo
- artificial intelligence
- Machine Learning
- Robotics
- happyNewYear2021
- newYearEve
- 2021
- Automation
- Smart Home
- Career
- Best Practices
- Git
- Logging
- Web Fundamentals
- DNS
- HTTPS
- Performance
- AI Tools
- ChatGPT
- Claude
- Gemini
- Laravel
- Eloquent
- MySQL
- HTTPS
- TLS
- Web Security
- Certificates
- Developer Life
- Debugging
- Docker
- DevOps
- Transactions
- Queues
- LLMs
- AI
- AI Coding
- Developer Tools
- React Native
- Expo
- Kate PMS
- Mobile Apps
- Laravel
- Authentication
- Sanctum
- Cookies
- API Design
- Payments
- Idempotency
- DeepSeek
- Open Source AI
- LLMs
- AI News
- Git
- Version Control
- AI Coding
- Prompting
- PHP
- Checklist
- MCP
- AI Agents
- OpenAI
- Architecture
- Microservices
- Modular Monolith
- Estimation
- Developer Life
- Project Planning
- Humour
- OAuth
- OpenID Connect
- Authentication
- Embeddings
- Vector Search
- RAG
- pgvector
- OpenAI
- GPT-4.1
- Codex CLI
- Events
- Testing
- Clean Code
- Maintainability
- Code Review
- Webhooks
- API
- Security
- Claude Code
- Workflow
- AI
- LLM
- Prompt Injection
- Mobile
- React
- Networking
- TCP
- UDP
- HTTP/3
- CLAUDE.md
- AWS
- Cloud Security
- Backups
- PHPUnit
- Software Engineering
- Leadership
- Communication
- RAG
- Embeddings
- AI Engineering
- IT Infrastructure
- Networking
- Access Control
- CI/CD
- GitHub Actions
- Gemini CLI
- Claude Code
- JavaScript
- Async/Await
- Node.js
- Promises
- Security
- Cryptography
- Passwords
- MySQL
- Database
- Vibe Coding
- Software Quality
- DNS
- Code Reading
- Onboarding
- Productivity
- Background Jobs
- Developer Humour
- Estimates
- Dev Life
- JWT
- o3-mini
- DeepSeek R1
- Rate Limiting
- Kate PMS
- E-Signing
- Audit Trail
- REST
- GraphQL
- API Design
- Laravel 12
- Upgrade Guide
- Open Source
- Self-Hosting
- Task Scheduling
- Cron
- Secrets
- CORS
- PHP
- PHP-FPM
- OPcache
- GitHub Copilot
- Software Architecture
- Engineering
- TypeScript
- JavaScript
- Type Safety
- AI Security
- React Native
- Product Design
- AI Agents
- Kiro
- Queues
- Redis
- RabbitMQ
- AWS SQS
- Nginx
- Apache
- GPT-5
- gpt-oss
- Clean Code
- Architecture
- Naming
- Documentation
- Career
- ADR
- Teamwork
- Supply Chain
- Kate HRM
- HR Software
- Permissions
- System Design
- Pagination
- SSH
- Linux
- Big O
- Databases
- Laravel Boost
- MCP
- Developer Skills
- Validation
- Databases
- Indexes
- Code Quality
- Deployment
- Developer Humour
- Feature Flags
- Code Review
- Pull Requests
- Docker
- Cursor
- Authorization
- RBAC
- Gemini
- Long Context
- PHP 8.4
- Caching
- Dependency Injection
- Web Performance
- Browser
- CSS
- Database
- Migrations
- ChatGPT
- AI for Developers
- Monitoring
- On-Call
- REST
- Backend
- SQL
- NoSQL
- Database Design
- Coding Agents
- Claude 4
- API Resources
- REST API
- Load Balancing
- Scaling
- AWS
- AI Tools
- Claude
- Sora 2
- CTE
- 2FA
- TOTP
- Programming Languages
- Prompts
- Developer Workflow
- API Gateway
- APIs
- Passport
- API Auth
- Learning
- Burnout
- Developer Growth
- Web Development
- SEO
- Kate Mall
- ChatGPT Atlas
- Agent Skills
- Middleware
- Laravel 12
- Collections
- Context Window
- Monitoring
- Commit Messages
- Self Review
- Growth
- Regex
- Programming Basics
- Text Processing
- Database Design
- Normalization
- Linux
- Server Security
- Linux Foundation
- Open Standards
- Legacy Code
- Documentation
- AI Workflow
- File Uploads
- Test Data
- Hashing
- Performance
- Caching
- Enums
- Scope Creep
- Estimation
- Codex
- Gemini CLI
- Timezones
- Carbon
- Bugs
- PHP 8.5
- Gemini 3
- GPT-5.1
- Data Integrity
- Event Loop
- Async
- Opus 4.5
- AI Models
- React
- Forms
- Frontend
- Backups
- AI Images
- DALL-E
- Midjourney
- Race Conditions
- Concurrency
- Legacy Code
- Refactoring
- Senior Engineer
- Scope
- LLM
- CDN
- Web
- Sub-Agents
- Soft Deletes
- Audit Log
- Concurrency
- AI Learning
- NestJS
- AI Evals
- Policies
- SPF DKIM DMARC
- Unicode
- UTF-8
- Knowledge Graph
- Value Objects
- Technical Debt
- Feature Flags
- Laravel Pennant
- Deployment
- Copilot
- Composer
- Dependencies
- Artisan
- Automation
- AWS S3
- Object Storage
- Cloud
- Small Language Models
- Ollama
- Production
- Sessions
- HTTP
- Mentoring
- SQL
- Virtual Machines
- Web Development
- HTTP/2
- QUIC
- Web Performance
- AI Integration
- LLM API
- SOLID
- OOP
- Hosting
- Serverless
- Merge Conflicts
- Temperature
- AI Development
- Reverse Proxy
- Nginx
- Infrastructure
- Verification
- Passkeys
- WebAuthn
- Teams
- Communication
- Stakeholders
- Monorepo
- CI/CD
- Versioning
- JSON Schema
- Livewire
- Inertia
- Meetings
- Distributed Systems
- Privacy
- Full-Stack
- T-Shaped Skills
- Money
- Notifications
- Web Security
- HTTP Headers
- CSP
- Function Calling
- Load Testing
- k6
- Data Extraction
- Debugging
- WebSockets
- SSE
- Real-Time
- Laravel Reverb
- Infrastructure as Code
- Terraform
- Side Projects
- Laravel Pint
- OpenAPI
- Swagger
- UX
- Multimodal
- Jest
- Pair Programming
- APIs
- Rate Limiting
- Resilience
- Dev Humour
- Design Tokens
- JWT
- API Keys
- Sessions
- PHPStan
- Rector
- Incidents
- Reporting
- Dashboards
- Zero Trust
- IAM
- Search
- Laravel Scout
- Junior Developers
- Mentoring
- Images
- WebP
- AVIF
- Bug Reports
- Let's Encrypt
- Design Docs
- Software Design
- Observers
- Replication
- Accountability
- Data Structures
- Reliability
- LLM Memory
- Error Handling
- Payments
- Payment Gateway
- Webhooks
- PCI DSS
- Observability
- OpenTelemetry
- Personal Brand
- Writing
- Conventions
- Dates
- Scheduling
- Disaster Recovery
- Compression
- Brotli
- Deadlines
- Developer Habits
- State Machines
- Tech Roles
- UUID
- ULID
- Horizon
- Planning
- Engineering Culture
- Ownership
- Soft Skills
- Socialite
- Cost Control
- Collations
- Unicode
- Octane
- PostgreSQL
Nginx vs Apache for PHP Apps: What Actually Matters in 2025
About Post
Ask "Nginx or Apache?" in a room full of PHP developers and you'll get strong opinions in both directions. Most of them were formed around 2010, when the answer really did matter a lot.
Here's my slightly unpopular take: for a modern PHP app running on PHP-FPM, the web server is rarely what makes your app slow. But the two servers do behave differently, and a couple of those differences will bite you if you move from one to the other without knowing them.
Where the reputation came from
The classic Apache setup used mod_php: PHP lived inside every Apache process. That forced the prefork model, one process per connection, each one carrying a full PHP interpreter. Serving a tiny CSS file? That's a heavy PHP-loaded process tied up for it. Slow clients on mobile networks? Each one holds a fat process hostage until it finishes.
Nginx was built differently from day one. A few worker processes run an event loop, each juggling thousands of connections at once. It never runs PHP itself. It hands PHP requests to a separate pool of PHP processes over FastCGI.
Under heavy concurrent load, that difference was dramatic, and Nginx earned its reputation honestly.
What changed: PHP-FPM everywhere
Modern Apache doesn't have to work like that. With the event MPM and mod_proxy_fcgi, Apache also hands PHP off to PHP-FPM, exactly like Nginx does. Static files and idle keep-alive connections no longer occupy a PHP process.
Once both servers sit in front of the same PHP-FPM pool, your PHP code runs in the same processes, with the same OPcache, at the same speed. The request that takes 400 ms because of a missing index takes 400 ms behind either one.
The practical truth: if you're comparing Nginx with Apache + mod_php, Nginx wins on concurrency. If you're comparing it with Apache event + PHP-FPM, the gap is small for most apps, and your database queries matter far more.
The real differences, side by side
| Apache | Nginx | |
|---|---|---|
| Connection model | Process/thread based (prefork, worker or event MPM) | Event-driven workers |
| Running PHP | mod_php (legacy) or PHP-FPM via mod_proxy_fcgi | Always PHP-FPM via fastcgi_pass |
| Per-directory config | .htaccess files | None. All config lives in server files |
| Static files | Fine, especially with the event MPM | Excellent, and very light on memory |
| Config style | Directives, modules, <Directory> blocks | server and location blocks |
| Typical home | Shared hosting, XAMPP, older stacks | VPS/cloud setups, reverse proxy in front of anything |
The .htaccess question
.htaccess is Apache's best and worst feature. Best, because you can drop a file in a folder and change rewrites, redirects or headers without touching server config or restarting anything. That's why shared hosting loves it, and why Laravel ships a public/.htaccess that just works.
Worst, because when AllowOverride is on, Apache checks for .htaccess files in the requested directory and every parent, on every request. And config scattered across random folders is hard to review.
If you control the server, put the rules in the virtual host and set AllowOverride None. You get the speed back and the config in one place.
And the gotcha when you migrate: Nginx ignores .htaccess completely. Every rewrite, redirect, deny rule and header in there has to be translated by hand. Forget one that blocks access to a sensitive folder, and it's silently open after the move.
What a Laravel site needs on Nginx
The core of it is short. This is close to the example in the Laravel deployment docs (simplified, without TLS):
server {
listen 80;
server_name example.com;
root /var/www/app/public;
index index.php;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ ^/index\.php(/|$) {
fastcgi_pass unix:/var/run/php/php8.4-fpm.sock;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
include fastcgi_params;
fastcgi_hide_header X-Powered-By;
}
location ~ /\.(?!well-known).* {
deny all;
}
}
Two details worth understanding rather than copying:
try_filesdoes the job of Laravel's.htaccess: serve the file if it exists, otherwise send the request toindex.php.- Only
index.phpis passed to PHP. A genericlocation ~ \.php$block would execute any PHP file it finds underpublic/, including one an attacker managed to upload. Narrow is safer.
The full reference is in the Laravel deployment docs.
So which should you use?
It depends on three things, and here's where I land on each:
- Who controls the server? On shared hosting you get Apache and
.htaccess, end of discussion. On your own VPS or cloud server, I reach for Nginx + PHP-FPM. - What else is it doing? If the same box also proxies to a Node service, terminates TLS for several apps or serves lots of static assets, Nginx's reverse proxy config is clean and light.
- What does the team know? A well-configured Apache beats a copy-pasted Nginx config nobody understands. Familiarity is a valid reason.
Locally I'm happy on XAMPP's Apache, and in production I prefer Nginx in front of PHP-FPM. That combination works fine as long as you remember the .htaccess rules don't travel.
Checklist before you switch
- Move to PHP-FPM first. That's where most of the gain is, on either server.
- List every
.htaccessfile in the project and translate each rule. - Pass only your front controller to PHP.
- Deny dotfiles (except
.well-known), and keep.envoutside the web root anyway. - Load test before and after, so the decision is based on your app, not on a forum thread.
Which one runs your PHP apps today, and was it a deliberate choice or just what the server came with?

Be first to comment it...