Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

This guide deploys Friendica 2026.05 on Ubuntu 24.04 LTS with Nginx, PHP-FPM, MariaDB, HTTPS, cron and outbound email. It assumes a fresh VPS or server, sudo access, a DNS name such as social.example.com, and comfort with SSH. Friendica’s May 21, 2026 release is the current stable release and is the last release compatible with PHP versions below 8.2, so verify the PHP requirement for the release you install. The project’s general installation document still lists a broader PHP 7.4+ baseline; the release-specific requirement takes precedence for a new 2026.05 deployment (release notes).

This is a self-managed installation, not a one-click service. You remain responsible for operating-system updates, firewalling, backups, storage, email deliverability, moderation, upgrades and federation troubleshooting.

What you will build

The finished node uses this layout:

DNS social.example.com → VPS
Nginx :80/:443 → PHP-FPM → Friendica
                              ↘ MariaDB
                              ↘ cron worker and SMTP

Use a top-level domain or subdomain, preferably https://social.example.com. Friendica documentation says path-based installs such as example.com/friendica are not thoroughly tested and are unsuitable for Diaspora communication (installation requirements).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before you begin

  • Ubuntu 24.04 LTS with root or sudo access. Ubuntu also lists 22.04 and 26.04 LTS; 24.04 is used here so package names and behavior are reproducible (Ubuntu release documentation).
  • An A record for the hostname and, if used, a working AAAA record.
  • Firewall access to TCP 22, 80 and 443, including IPv6 rules when applicable.
  • Outbound SMTP access. Some VPS providers restrict port 25, requiring authenticated SMTP on port 587 or 465.
  • A swap plan for a small VPS, accurate server time, and an off-server backup destination.
  • A database password stored in a password manager rather than shell history.

Check an AAAA record carefully: a broken IPv6 route can make an otherwise healthy site intermittently unreachable.

1. Update Ubuntu and install the stack

sudo apt update
sudo apt full-upgrade -y

sudo apt install -y 
  nginx mariadb-server git unzip curl ca-certificates imagemagick 
  certbot python3-certbot-nginx 
  php-fpm php-cli php-curl php-gd php-gmp php-intl php-mbstring 
  php-mysql php-xml php-zip

Ubuntu chooses the PHP package version for the release. Verify what was installed:

php -v
php -m
php --ini
nginx -v
mariadb --version
systemctl list-units --type=service 'php*-fpm.service'

Friendica identifies Curl, GD, GMP, PDO, mbstring, MySQLi, XML, ZIP, IntlChar, IDN, OpenSSL, POSIX and command-line PHP as relevant requirements. ImageMagick is optional but supports animated GIF and animated WebP handling (requirements).

Check the CLI PHP setting

php -i | grep register_argc_argv

The result should show register_argc_argv => On => On. If it is off, use php --ini to find the active CLI configuration, set:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
register_argc_argv = On

Then restart the exact FPM service shown by systemctl list-units, for example:

sudo systemctl restart php8.3-fpm

2. Create and secure MariaDB

sudo mariadb-secure-installation
sudo mariadb

At the MariaDB prompt, create a database-specific account:

CREATE DATABASE friendica
  CHARACTER SET utf8mb4
  COLLATE utf8mb4_general_ci;

CREATE USER 'friendica'@'localhost'
  IDENTIFIED BY 'REPLACE_WITH_A_LONG_RANDOM_PASSWORD';

GRANT ALL PRIVILEGES ON friendica.* TO 'friendica'@'localhost';
FLUSH PRIVILEGES;
EXIT;

Friendica recommends MariaDB and requires a MySQL-compatible engine with InnoDB and Barracuda support; MySQL and Percona Server may also work. The application account should not have global privileges (database guidance).

3. Download Friendica and matching addons

Git installation

The stable branch is the normal choice for a production node:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo mkdir -p /var/www
sudo git clone https://github.com/friendica/friendica.git 
  -b stable /var/www/friendica

cd /var/www/friendica
sudo -u www-data bin/composer.phar run install:prod

sudo git clone https://github.com/friendica/friendica-addons.git 
  -b stable addon

Check both branches:

cd /var/www/friendica && git branch --show-current
cd /var/www/friendica/addon && git branch --show-current

Keep core and addons on the same release line. Do not mix stable with develop, or a 2026.05 core archive with older addons.

Release archive alternative

The release page publishes matching friendica-full-2026.05 and addons archives with SHA-256 checksums. The full archive includes dependencies and is suitable when you want a fixed, reproducible deployment. Verify the checksum and preserve configuration files during later replacements. Git is more convenient for operators who stage repository updates and Composer changes.

4. Set ownership and writable paths

sudo chown -R root:www-data /var/www/friendica
sudo find /var/www/friendica -type d -exec chmod 0755 {} ;
sudo find /var/www/friendica -type f -exec chmod 0644 {} ;

sudo mkdir -p /var/www/friendica/view/smarty3
sudo chown -R www-data:www-data /var/www/friendica/view/smarty3
sudo chmod 0775 /var/www/friendica/view/smarty3

The Smarty directory must exist and be writable by the web-server user (installation notes). If the installer cannot create its configuration, prepare only that file:

sudo touch /var/www/friendica/config/local.config.php
sudo chown www-data:www-data /var/www/friendica/config/local.config.php
sudo chmod 0660 /var/www/friendica/config/local.config.php

Do not make the whole application tree writable by www-data.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Configure Nginx and PHP-FPM

Nginx does not process .htaccess; its server block must provide Friendica’s front-controller routing. Create /etc/nginx/sites-available/friendica:

server {
    listen 80;
    listen [::]:80;
    server_name social.example.com;

    root /var/www/friendica;
    index index.php;
    client_max_body_size 50M;

    location / {
        try_files $uri $uri/ /index.php?$args;
    }

    location ~ .php$ {
        try_files $uri =404;
        include snippets/fastcgi-php.conf;
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        fastcgi_pass unix:/run/php/php8.3-fpm.sock;
    }

    location ~ /.(?!well-known).* {
        deny all;
    }
}

Replace php8.3-fpm.sock with the socket actually installed on your server:

ls -l /run/php/

The Friendica project’s sample Nginx configuration is a useful reference, but it is an example that must be adapted to your Ubuntu and PHP versions (sample configuration). Test and enable the site:

sudo ln -s /etc/nginx/sites-available/friendica /etc/nginx/sites-enabled/friendica
sudo rm -f /etc/nginx/sites-enabled/default
sudo nginx -t
sudo systemctl reload nginx

Never reload after a failed nginx -t. A missing socket, incorrect root or malformed try_files rule commonly causes 502, 404 or blank-page errors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Point DNS and test HTTP

getent hosts social.example.com
curl -I http://social.example.com

The request should reach this virtual host rather than the default Nginx page. Watch logs while diagnosing:

sudo tail -f /var/log/nginx/access.log /var/log/nginx/error.log
sudo journalctl -u nginx -f
sudo journalctl -u php8.3-fpm -f

Use the installed FPM service name in place of php8.3-fpm.

7. Enable HTTPS with Certbot

Let’s Encrypt certificates are free, browser-trusted and valid for 90 days. HTTP-01 issuance requires DNS to resolve to this server and port 80 to be reachable (Ubuntu TLS documentation).

sudo snap install --classic certbot
sudo certbot --nginx -d social.example.com
sudo certbot renew --dry-run
systemctl status snap.certbot.renew.timer

Certbot’s Nginx plugin adds TLS directives and can configure HTTP-to-HTTPS redirection. Renewal still depends on a working timer, DNS, firewall and Nginx configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

8. Run the Friendica installer

Open https://social.example.com and enter:

  • Database type: MySQL/MariaDB
  • Database host: localhost
  • Database name: friendica
  • Database user: friendica
  • The password created in MariaDB
  • An administrator email address
  • Site URL: https://social.example.com

Use the final HTTPS URL from the beginning. If the installer reports a missing extension, permission, database, PHP setting, email or configuration-file problem, fix that prerequisite instead of bypassing the check.

9. Schedule workers with cron

Friendica needs scheduled jobs for federation, notifications and other asynchronous work. A real scheduler is preferable to visitor-triggered execution. Create a cron entry for the web user:

sudo crontab -u www-data -e
*/5 * * * * cd /var/www/friendica && /usr/bin/php bin/worker.php

The five-minute interval is a practical example; confirm the current release’s worker guidance when tuning it. Test manually:

sudo -u www-data php /var/www/friendica/bin/worker.php
sudo journalctl -u cron --since "15 minutes ago"

Check for a wrong CLI PHP binary, an incomplete PATH, database access errors, unreadable files or duplicate cron/systemd schedules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

10. Configure reliable email

Email is required for account confirmation, password resets, notifications and administration. Use local Postfix or another MTA, or configure authenticated remote SMTP. Friendica also documents the PHPMailer addon for remote SMTP when local delivery is unavailable (mail requirements).

  • Use a sender address on your domain.
  • Publish SPF and configure DKIM through the SMTP provider.
  • Publish DMARC.
  • Test Gmail, Outlook and another mailbox, including spam folders and bounces.
  • Do not rely on unauthenticated residential-IP mail.

11. Verify federation and administration

  • sudo nginx -t succeeds; Nginx and MariaDB are active.
  • HTTPS loads without warnings and HTTP redirects.
  • Registration, login and image upload work.
  • Password-reset mail arrives.
  • A remote Fediverse profile can be searched or followed.
  • The worker runs and admin diagnostics show no critical errors.
  • sudo certbot renew --dry-run succeeds.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

12. Backups, updates and recovery

Back up the complete service

Back up the MariaDB database, config/local.config.php, config/addon.config.php when present, uploaded media, custom themes/addons, Nginx configuration and relevant TLS recovery information. Store encrypted copies outside the VPS and test a restoration; an untested dump is not a dependable backup.

Update a Git installation

cd /var/www/friendica
git pull
bin/composer.phar run install:prod

cd addon
git pull

Back up first and keep core and addons aligned. Friendica normally applies database updates automatically. If an upgrade leaves one stuck, run the documented recovery command from the installation directory:

cd /var/www/friendica
bin/console dbstructure update

Choose between Nginx and Apache

Choice Advantages Trade-offs
Nginx Efficient static files, common VPS architecture, clear PHP-FPM separation No .htaccess; you maintain routing and socket settings yourself
Apache Friendica’s primary documentation path and native .htaccess behavior Less suitable if your existing stack is standardized on Nginx

Choose Apache when you want the project’s primary documented path or have little Nginx experience.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshooting by symptom

502 Bad Gateway

Check ls -l /run/php/, confirm the socket in fastcgi_pass, and verify the matching FPM service is active.

Nginx default page

Confirm the symlink in /etc/nginx/sites-enabled, remove the default site, verify DNS and reload only after nginx -t succeeds.

Profile URLs return 404

Ensure location / contains try_files $uri $uri/ /index.php?$args; and that the server root is the Friendica directory.

Installer cannot write configuration

Check ownership of config/local.config.php and the parent config/ directory; do not grant write access to the entire tree.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Database authentication fails

Test the exact database name, user, host and password, and verify that the account is limited to localhost as created.

Emails or federation are delayed

Run the worker manually as www-data, inspect cron logs, verify SMTP credentials and check whether outbound port 25 is blocked.

Certificate issuance fails

Verify public DNS, TCP 80 reachability, the correct Nginx server name and absence of a broken IPv6 route.

Is a VPS the right choice?

A low-cost VPS can suit a personal or small node, but there is no universal minimum size. Memory, CPU, storage and bandwidth depend on local accounts, followed remote accounts, media volume, indexing and worker load. DigitalOcean advertises Droplets from $4 per month with per-second billing and a monthly cap, but it is unmanaged infrastructure: patching, backups, email and Friendica maintenance remain yours (Droplet pricing). Ubuntu Pro is generally optional for a small personal node; on public clouds it is metered through the provider and adds security and compliance features (Ubuntu Pro pricing). Budget separately for a domain, SMTP and off-site backups.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

For a maintainable Nginx deployment, use Ubuntu 24.04, PHP 8.2 or newer for Friendica 2026.05, matching core and addon releases, least-privilege MariaDB credentials, a tested PHP-FPM socket, front-controller routing, HTTPS, real cron workers, reliable SMTP and verified off-server backups.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.