# Deployment strategy

**URL:** <https://discourse.cakephp.org/t/deployment-strategy/575>\
**Category:** Need Help\
**Created:** [June 19, 2016, 8:43am UTC](https://discourse.cakephp.org/t/deployment-strategy/575 "2016-06-19T08:43:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cakebey](https://avatars.discourse-cdn.com/v4/letter/c/91b2a8/32.png) [@cakebey](https://discourse.cakephp.org/u/cakebey)\
**Post date:** [June 19, 2016, 8:43am UTC](https://discourse.cakephp.org/t/deployment-strategy/575/1 "2016-06-19T08:43:50Z")

</div>

Hi all,

I’ve been using cakephp for a local information management project.

I’ve decided to use version 3 for my little e-commerce project but i have several questions regarding deployment to our hosting platform.

In version 2, it was easy to develop in local and deploy to live server.  
Right now with version 3 it’s a little complicated with composer activities and so on.  
What is the recommended way of working on cakephp for local development and deployment to live server ?  
I’ve read several articles about it, but i am interested in the security perspective and don’t do’s.

Is it safe to upload my local development copy to a live server ?  
I am continuously updating my dependacy libraries/plugins via composer, is it safe to upload composer modifications ?

Thanks.

---

<div class="post-metadata">

**Author:** ![raul338](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/raul338/32/69_2.png) [@raul338](https://discourse.cakephp.org/u/raul338)\
**Post date:** [June 19, 2016, 3:46pm UTC](https://discourse.cakephp.org/t/deployment-strategy/575/2 "2016-06-19T15:46:24Z")

</div>

You may try with [capcake](https://github.com/jadb/capcake) using capistrano  
What I do with simple pages (e.g. \< 10 controllers/tables) is set up a clone repo in the server, and install with composer using `composer install --no-dev -o` configure the app.php (set debug to false) and done!

---

<div class="post-metadata">

**Author:** ![rrd](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/rrd/32/113_2.png) [@rrd](https://discourse.cakephp.org/u/rrd)\
**Post date:** [June 20, 2016, 3:43pm UTC](https://discourse.cakephp.org/t/deployment-strategy/575/3 "2016-06-20T15:43:55Z")

</div>

Actually composer helps you in safe deploying. My strategy is the following.

1. I have my development enviroment where I regularly run composer update to get the latest versions of cake and libraries.
2. I use github for version control. So when I am working on a bugfix or on a new feature I push my changes there.
3. I added /vendor, /tmp, /logs to my .gitignore file as I do not want them in version control.
4. When I want to deploy I just pull my code from github and use the composer --nodev install command to get my code and all the used libraries to the production server.

---

<div class="post-metadata">

**Author:** ![cakebey](https://avatars.discourse-cdn.com/v4/letter/c/91b2a8/32.png) [@cakebey](https://discourse.cakephp.org/u/cakebey)\
**Post date:** [June 20, 2016, 5:32pm UTC](https://discourse.cakephp.org/t/deployment-strategy/575/4 "2016-06-20T17:32:34Z")

</div>

Thank you very much for the recommendations.  
I’ve used a svn method similiar to rrd several years ago.

I will try to use composer for my project too.  
What about security ? Can you protect your code within github from unwanted access from bug hunters ?

---

<div class="post-metadata">

**Author:** ![alysson\_azevedo](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/alysson_azevedo/32/194_2.png) [@alysson\_azevedo](https://discourse.cakephp.org/u/alysson_azevedo)\
**Post date:** [June 20, 2016, 5:35pm UTC](https://discourse.cakephp.org/t/deployment-strategy/575/5 "2016-06-20T17:35:07Z")

</div>

Since my projects are private, i use git to deploy my code.

> **[How To Set Up Automatic Deployment with Git with a VPS | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-set-up-automatic-deployment-with-git-with-a-vps)**
>
> This article will teach you how to use Git when you want to deploy your application. While there are many ways to use Git to deploy our application, we'll focus on the one that is most straightforward.

It works really nice.

---

<div class="post-metadata">

**Author:** ![rrd](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/rrd/32/113_2.png) [@rrd](https://discourse.cakephp.org/u/rrd)\
**Post date:** [June 21, 2016, 11:08am UTC](https://discourse.cakephp.org/t/deployment-strategy/575/6 "2016-06-21T11:08:18Z")

</div>

Bitbucket offers free private repos.

---

<div class="post-metadata">

**Author:** ![riteshpandey](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@riteshpandey](https://discourse.cakephp.org/u/riteshpandey)\
**Post date:** [September 8, 2016, 3:03pm UTC](https://discourse.cakephp.org/t/deployment-strategy/575/7 "2016-09-08T15:03:05Z")

</div>

CakePHP 2.x doesn’t create cache and logs folder in tmp when debug value is 0.

I use Apache environment variable for setting debug value  
Here is how I deploy

- Clone repository
- Create tmp folder. Set appropriate permissions as mentioned in [http://book.cakephp.org/2.0/en/installation.html#permissions](http://book.cakephp.org/2.0/en/installation.html#permissions)
- Change database.php configuration file

Now, there is a problem. CakePHP will throw error as it won’t generate cache and logs folder. These folders are generated when request hits Cake app with debug level != 0.

How do I solve that? I don’t want to change debug level to non-zero on my production machine.

@markstory @dereuromark Please suggest

---

<div class="post-metadata">

**Author:** ![dereuromark](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/dereuromark/32/37_2.png) [@dereuromark](https://discourse.cakephp.org/u/dereuromark)\
**Post date:** [September 13, 2016, 1:38pm UTC](https://discourse.cakephp.org/t/deployment-strategy/575/8 "2016-09-13T13:38:43Z")

</div>

You should have your own deploy scripts take care of that.  
It can be as simple as

```
mkdir -p ./tmp

```

etc added
