What actually ends up inside a PHP image — and which parts you get to choose.
PHP extension
#
ext-, module, intl, gd, pdo_mysql, redis
A compiled add-on that gives PHP extra abilities, such as pdo_mysql for MySQL, intl for internationalisation or gd for images. Packages in your composer.json declare which ones they need as ext-… requirements. Some extensions are built into PHP itself; others have to be added separately.
At customcontainer
We read the required extensions from your composer.lock, and you can add or remove any of them with a click. Every extension you leave out is one less thing to patch.
See also:
Shared library, Attack surface, composer.lock
More on this →
PHP CLI
#
command line, php binary
PHP on the command line: php script.php, php artisan, bin/console, Composer, PHPUnit or a queue worker. A CLI container runs one command and ends when the command ends.
At customcontainer
Tick “CLI Package” and the image starts php by default — the right choice for workers, cron jobs and CI.
See also:
PHP-FPM, Container definition
PHP-FPM
#
FastCGI Process Manager, FPM, php-fpm
The process manager that runs PHP for web requests. A web server such as nginx, Caddy or Apache receives the HTTP request and hands it to PHP-FPM over the FastCGI protocol. In container setups the web server and PHP-FPM usually run in two separate containers.
At customcontainer
Tick “FPM Package” and the image starts php-fpm, listening on port 9000 for your web server.
See also:
PHP CLI, Port mapping
composer.lock
#
lock file, composer.json
The file in which Composer records the exact version of every installed package. It also lists which PHP extensions those packages require — which makes it the most reliable description of what your application needs to run.
At customcontainer
Paste it on the start page and we derive the extension list from it — no guessing, no forgotten ext- requirement.
See also:
PHP extension, Container definition
Distribution
#
distro, Linux distribution, Rocky Linux, Debian, Alpine
The Linux flavour the files in an image come from — Debian, Alpine, Rocky Linux and so on. It determines where the system libraries come from, how fast they receive security fixes and how long a release is supported.
At customcontainer
Our images are currently built on Rocky Linux 9, an enterprise distribution with long support cycles. They do not contain its package manager or tools — only the files PHP actually uses.
See also:
RPM package, Base image
RPM package
#
package, rpm, dnf
The package format of Red Hat–style distributions such as Rocky Linux. Every library and every PHP extension arrives as a package with a name, a version and a release number — which makes it possible to say exactly what is installed and when it changed.
At customcontainer
Every build records the exact package versions it contains. That is where your build history and the update feed get their data from.
See also:
Distribution, Update feed
Shared library
#
system library, .so file, libxml2, OpenSSL, ImageMagick
Code that several programs share instead of each bringing its own copy — OpenSSL for encryption, libxml2 for XML, ImageMagick for images. Many PHP extensions are thin wrappers around such a library, which means a security hole in the library is a security hole in your PHP application.
At customcontainer
An extension’s layer contains the libraries it links against. Leave out the extension and its libraries go with it.
See also:
PHP extension, CVE
Locale
#
glibc locale, setlocale, de_DE, language settings
Language and regional settings at system level: how dates, numbers and currencies are formatted, and how text is sorted. PHP functions such as setlocale() or strftime() only work for locales that are actually installed in the image.
At customcontainer
Every image includes C.utf8. Further locales, such as German or French, you add in the configurator.
See also:
Time zone data
Time zone data
#
tzdata, timezone, date.timezone
The database of the world’s time zones and their daylight-saving rules. Without it a container only knows UTC, and converting a timestamp to “Europe/Berlin” at system level goes wrong.
At customcontainer
Optional: tick “Include timezones” to add the tzdata layer.
See also:
Locale
Shell
#
sh, bash, BusyBox, docker exec
A command line inside the container — what you get with docker exec -it … sh. Handy for debugging, but in production it is also a handy tool for an attacker. Many minimal images therefore ship without one.
At customcontainer
Optional: tick “Include shell” to add BusyBox, a single small program that provides sh and the usual basic commands.
See also:
Attack surface, Container