RE:NODE

Web hosting11 min read

Joomla hosting guide: install, configuration.php, updates

Host Joomla 6 or 5.4: requirements, a manual install, configuration.php settings, SEF URLs on nginx, extensions, caching, scheduled tasks and safe updates.

0 readers

Joomla 6 needs PHP 8.3 or newer (8.4 recommended), a MySQL 8.0.13+, MariaDB or PostgreSQL database, a PHP memory_limit of 256 MB, and the usual handful of PHP extensions. Installation is the classic PHP routine: upload one archive, unpack it in the web root, create an empty database, and walk through a browser installer that writes configuration.php for you. On a normal connection the whole job is fifteen minutes.

The parts that cause trouble later are elsewhere: search-engine-friendly URLs on nginx, where Joomla's .htaccess does nothing; extensions installed from wherever a search result pointed; caching and session settings left on defaults that do not fit the site; and updates applied without a backup. This guide does the install and then each of those properly.

Joomla 6 or Joomla 5.4#

Joomla 6.0 and 5.4 were released together in October 2025. Joomla 6 is the current major version; 5.4 is the last of the 5 series, which moved to maintenance. According to the project's published roadmap, Joomla 5 receives bug fixes until October 2026 and security fixes until October 2027 - confirm the current dates on joomla.org before you plan around them.

For a new site, install Joomla 6. Use 5.4 only if an extension you cannot do without has not been updated for 6 yet, and plan the move. Moving from 5.4 to 6 is an in-place update through the Joomla Update component once the Pre-Update Check reports that your extensions are compatible; it is far smaller than the jump from Joomla 3 to 4 was.

Joomla 6 requirements, from the official technical requirements page:

SoftwareMinimumRecommended
PHP8.3.08.4
MySQL8.0.138.4
MariaDB10.4 (10.6 supported)12.0
PostgreSQL12.0 (14.0 supported)17.6
nginx1.26 supported1.29
Apache2.42.4

Required PHP extensions are json, simplexml, dom, zlib, gd and one of mysqlnd, pdo_mysql or pdo_pgsql; mbstring is recommended. The manual recommends a memory_limit of at least 256 MB. Raise upload_max_filesize and post_max_size to something like 32-64 MB as well, or installing a large extension package fails with an unhelpful error. The php.ini settings that matter covers where those live.

Resource use is moderate. A small Joomla site runs comfortably on 1 GB of memory; a site with a page builder, a shop extension and logged-in members wants 2 GB. Disk is about 100 MB for Joomla itself, plus images and whatever backup archives you keep on the server - and backup archives are what fills small disks.

Before you start: database and PHP version#

Create the database first. Joomla does not create one for you on most hosting; it needs an existing empty database and a user with full rights on it. Write down the host, port, database name, user and password.

On RE:NODE, the Engines plans are the line sized for a CMS like Joomla, and each carries two database slots created from the panel with a generated host, user and password. The Open in phpMyAdmin button signs you in with a single-use token that expires after sixty seconds, so you can check the database is there and empty without typing the password into a form. You install Joomla yourself - there is no one-click installer, which also means nobody else decides when your version changes.

Check the PHP version your plan actually runs before downloading anything: a file containing <?php phpinfo();, loaded once in the browser and then deleted, shows the version, the loaded extensions and the effective memory_limit. Joomla 6 will refuse to install on PHP 8.2.

Installing Joomla#

  1. Download the full package from downloads.joomla.org, never from a third-party mirror. A tampered CMS archive is the most direct way to start life compromised.
  2. Upload the zip to the web root and unpack it in place. A file manager that extracts server-side turns several thousand small files into one upload. Over SFTP, upload the zip and extract it in the file manager, rather than uploading the extracted tree. SFTP and the file manager covers both.
  3. Visit the site. The installer starts automatically. Choose the language and set the site name.
  4. Create the Super User. Not admin; a long generated password; a real email address you read.
  5. Database settings. Type MySQLi or MySQL (PDO) for MySQL and MariaDB, PostgreSQL (PDO) for PostgreSQL. Host, user, password and database name from your panel. Keep the random table prefix the installer suggests.
  6. Prove you own the site, if asked. When the database host is anything other than localhost, Joomla creates a file with a random name beginning _Joomla in the installation folder and asks you to delete it before it continues. This stops someone who finds a half-finished install from pointing it at their own database. Delete it with the file manager and click Install again.
  7. Finish. The last screen offers to open the site or the administrator. Make sure the installation folder is gone afterwards; if it is still there, delete it.

The administrator lives at /administrator. Sign in, go to System, then Global Configuration, and work through the settings below before you add any content.

configuration.php and Global Configuration#

Everything you set in Global Configuration is stored in configuration.php in the site root, as properties of a PHP class. You can edit the file directly - useful when a wrong setting has locked you out of the administrator - but make it writable first, edit carefully, and make it read-only again.

configuration.php
public $sitename = 'Example';public $offline = false;public $dbtype = 'mysqli';public $host = 'db.example.internal:3306';public $user = 'joomla_site';public $password = 'from-the-panel';public $db = 'joomla';public $dbprefix = 'x7k2q_';public $secret = 'generated-at-install';public $live_site = '';public $force_ssl = 2;public $sef = true;public $sef_rewrite = true;public $tmp_path = '/path/to/site/tmp';public $log_path = '/path/to/site/administrator/logs';public $error_reporting = 'none';public $debug = false;public $caching = 0;public $cache_handler = 'file';public $lifetime = 30;public $session_handler = 'database';public $behind_loadbalancer = true;

The ones that matter:

  • `host` takes a hostname with the port after a colon when the database is not on the default port. As with every PHP CMS, localhost is only right when the database runs on the same machine.
  • `secret` is generated at install and used in hashing and tokens. Do not copy it between sites; do keep it when you move one.
  • `force_ssl`: 0 none, 1 administrator only, 2 the entire site. Use 2 once HTTPS works, and not before - setting it on a site without a certificate locks you out, and the fix is editing this file.
  • `tmp_path` and `log_path` are absolute paths. After moving a site to a new server these are the classic cause of "cannot install extension" errors, because they still point at the old server's directories. Update them after every migration.
  • `error_reporting`: none or simple in production. maximum or development only while debugging, because it prints paths and queries to visitors.
  • `lifetime` is the session lifetime in minutes, 15 by default. Administrators tired of being logged out raise it; 30 to 60 is reasonable.
  • `behind_loadbalancer`, labelled Behind Load Balancer under the Server tab, tells Joomla to trust X-Forwarded-For and X-Forwarded-Proto. Turn it on when a reverse proxy terminates TLS in front of the site, or Joomla sees every visitor as the proxy and may build http:// URLs on an HTTPS site.

SEF URLs on nginx#

Search Engine Friendly URLs come in two parts. sef turns index.php?option=com_content&view=article&id=12 into index.php/my-article. sef_rewrite removes the index.php/ - and that needs the web server to send unknown paths to index.php.

On Apache, Joomla ships the rules in htaccess.txt; rename it to .htaccess. On nginx, .htaccess is ignored, and the equivalent is:

nginx
location / {    try_files $uri $uri/ /index.php?$args;}

If you switch on Use URL Rewriting and every page except the home page returns a 404, this rule is missing. On managed hosting you may not edit the nginx configuration yourself: test by turning rewriting on and visiting an article - if it loads, the rule is already there. If not, leave sef_rewrite off (URLs keep the index.php/ segment but work) and ask the host. A domain and certificate in front of the site come next; on RE:NODE the proxy slot issues and renews the certificate automatically once your A record points at it, and your domain and its certificate covers the DNS side.

Extensions: installing them safely#

Joomla's extension types are components, modules, plugins, templates and language packs, all installed from System, then Install, then Extensions - by uploading a package, from a folder, from a URL or from the Install from Web tab, which browses the Joomla Extensions Directory.

Rules that keep a Joomla site maintainable:

  • Install from the developer or the JED only. "Free" copies of commercial extensions from download sites are the most common source of backdoors in Joomla sites.
  • Check the last update date and Joomla 6 compatibility before installing. An extension last updated three years ago will block your next major upgrade.
  • Fewer, better extensions. Each one is code that runs on every page and an update you have to apply.
  • Commercial extensions use download keys. Enter the key under System, then Update Sites, or the extension cannot update itself.
  • Uninstall rather than disable what you no longer use. Disabled code is still on disk and still exploitable if it has a flaw that is reachable directly.

A backup extension is the one most sites should add on day one. Akeeba Backup is the long-standing choice: it archives files and database together, and its companion Kickstart script restores an archive onto an empty server. Store archives off the server - a backup on the same disk as the site disappears with it. Backups that actually restore explains why the restore test matters more than the backup.

Caching, sessions and scheduled tasks#

Joomla has two separate caching layers, both off by default:

  • Conservative or Progressive caching, under Global Configuration, then System, caches module and component output. Conservative is the safe choice; Progressive caches per visitor and can use a lot of disk.
  • The System - Page Cache plugin caches whole pages for guests. Large gain for anonymous traffic, but exclude pages with forms or anything personalised, and leave it off on shops.

The Cache Handler and Session Handler settings list only the backends your PHP installation supports. File and database are always there. Redis appears when the phpredis extension is loaded, and works with Valkey unchanged because Valkey speaks the same protocol. Moving sessions and cache to a Valkey server takes write load off the database on busy sites; on small sites the database handler is fine. If the Redis option is missing from the list, the extension is not installed, and no setting will add it.

Joomla's Task Scheduler, under System, then Scheduled Tasks, runs jobs such as session cleanup, sending queued emails, update notifications and site checks. It is triggered one of three ways: the Lazy Scheduler, which runs due tasks during normal page visits (the default, fine for small sites); a web cron URL with a secret key that an external scheduler requests; or the CLI with php cli/joomla.php scheduler:run where you have a shell. If nothing triggers it, tasks silently never run. Scheduled tasks worth having is a broader list.

Updates#

Joomla 5.4 and 6.0 introduced automatic core updates. On a fresh Joomla 6 install the feature is enabled by default; on a site updated from Joomla 5 it starts disabled and must be switched on in the Joomla Update component. It applies bug-fix and security releases (6.0.0 to 6.0.1, for example) and emails Super Users the result. It relies on Joomla's update service being able to reach your site, so it does not work on local development copies.

For major and minor updates, and for every extension update, the routine should be:

  1. Take a full backup, and confirm it completed.
  2. Read the release notes, especially for extensions that change database structure.
  3. Run the Pre-Update Check for major versions; every extension should report compatible.
  4. Update core first, then extensions, under System, then Update.
  5. Clear the cache and check the front end, a login and any form.
  6. Look at System, then Manage, then Database. If it reports structure problems, the Fix button repairs schema differences left by an interrupted update.

Troubleshooting#

"Error connecting to the database" during install. Wrong host or credentials. Test them in phpMyAdmin; if they work there, the host field is usually the difference - localhost where a hostname was needed, or a missing port.

"JFolder::create: Could not create folder" or extension installs fail. tmp_path points to a directory that does not exist or is not writable, usually after a migration.

404 on every page except the home page. URL rewriting is on without the server rule.

Locked out after enabling Force HTTPS. Set force_ssl back to 0 in configuration.php, fix the certificate, then turn it on again.

"The most recent request was denied because it had an invalid security token". An expired session; refresh and sign in again. If it happens constantly, raise lifetime or check that the session handler's storage is working.

White page. A PHP fatal error with display off. Set error_reporting to maximum briefly, reproduce, read the message, set it back.

FAQ#

Is Joomla still maintained?

Yes. Joomla 6.0 was released in October 2025 with automatic core updates, and the project publishes regular minor and security releases. It has a smaller extension ecosystem than WordPress, and a capable built-in feature set - multilingual content, access levels and custom fields in core.

How much hosting does Joomla need?

A small site runs on 1 GB of memory and half a CPU core. A site with a page builder, a shop extension or many logged-in members wants 2 GB. PHP's memory_limit should be 256 MB, as the Joomla manual recommends.

Can I move a Joomla site to new hosting?

Yes. Copy the files and export the database, import it on the new server, then update the database credentials, tmp_path and log_path in configuration.php. A backup extension with a restore script does the same in fewer steps. The phpMyAdmin import and export guide covers the database half.

Should I use the Redis cache handler with Valkey?

On a busy site, yes - it takes cache and session writes off the database. It needs the phpredis extension. On a small site the file cache and database sessions are simpler and perfectly adequate.

Which is better, Joomla or WordPress?

It depends on the site. Joomla's core does multilingual sites and fine-grained access levels without extensions; WordPress has a far larger ecosystem of themes and plugins. WordPress, Drupal and Joomla compared goes through which suits what.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000