Building a LAMP Stack on Ubuntu for Local Web Development

Web development on home hardware has become a quiet hobby across Australia, with meetups running from Sydney's CBD through to suburban libraries in Brisbane and shared co-working desks in Perth. Many of those developers rely on the same combination of tools that has powered the open web for two decades. A LAMP stack — Linux, Apache, MySQL or MariaDB, and PHP — gives you a complete environment for building, testing, and refining dynamic websites before they ever leave your desk.

Ubuntu is a sensible base for that environment. Long-term support releases ship with predictable package versions, security updates arrive on a clear schedule, and the same distribution runs comfortably on everything from a refurbished business laptop to a small home server. The four pieces of the stack work together cleanly on Ubuntu, and installing them takes only a few minutes once you know the right sequence.

This walkthrough covers a clean install on a current Ubuntu release, from the first system update through to a working local site with PHP processing and a database behind it. It assumes only that you can open a terminal and type commands. By the end you will have a self-contained development box you can extend with frameworks like Laravel, WordPress, or a custom PHP application of your own.

Preparing Ubuntu for the LAMP install

Before any web server package touches your system, take a few minutes to refresh what is already there. Open a terminal and run sudo apt update followed by sudo apt upgrade. The first command rebuilds the package index from Canonical's mirrors, and the second pulls in any pending security patches. On a fresh install, this step is quick, but on a machine that has been sitting for a while, it can take a while if you are pulling updates over a typical Australian NBN connection that caps out well below the gigabit speeds advertised on the higher plans.

Confirm you are on an LTS release with lsb_release -a. Versions such as 22.04 and 24.04 receive standard support until 2027 and 2029 respectively, which is a comfortable window for a development environment that you do not want to rebuild every nine months. If you started with a regular release instead, this is a good moment to consider reinstalling from an LTS image so the package names and PHP versions referenced in later steps remain consistent.

Create a non-root account for daily work if you have not already. Ubuntu's installer usually offers this, but a dedicated user with sudo rights keeps your web files and your system administration separated. It is also a habit that pays off later when you start deploying to a real server under a hosting provider registered with ASIC, where separating personal access from service accounts is a standard expectation.

Installing Apache web server on Ubuntu

Apache is the oldest of the four LAMP components and remains the most flexible for local development. Install it with sudo apt install apache2. The package pulls in the core server, the Multi-Processing Module, and a default site configuration that listens on port 80. Once the install finishes, check that the service started cleanly with sudo systemctl status apache2; you should see active (running) in green.

Point a browser at http://localhost and the default Ubuntu Apache page should appear. If you are testing from another machine on the same home network, replace localhost with the server's IP address, which you can find with ip addr. Many Australian households run a router in the 192.168.0.0/16 or 10.0.0.0/8 range, so the address will look familiar.

The document root on Ubuntu lives at /var/www/html. Anything you drop into that folder is served to anyone who can reach the server. For a single project, that is fine. For several sites, you will want virtual hosts, which the article covers further down. Apache's configuration split — main file in /etc/apache2/apache2.conf, site files in /etc/apache2/sites-available/ — makes that switch straightforward when you are ready.

Adding MySQL or MariaDB for data storage

The data layer of a LAMP stack used to mean MySQL without question. Today, most Ubuntu installations default to MariaDB, a community-maintained fork that remains wire-compatible with MySQL clients and applications. WordPress, Joomla, Drupal, and most PHP frameworks cannot tell the difference. If you have a hard requirement for Oracle's MySQL, you can still install it from Oracle's own APT repository, but for a learning environment, MariaDB is the path of least resistance.

Install the database server with sudo apt install mariadb-server. When the package finishes, run sudo mysql_secure_installation. This interactive script walks you through setting a root password, removing anonymous users, disabling remote root login, and dropping the test database. Even on a home box, these steps are worth completing, because the same muscle memory will protect a production database hosted with an Australian provider such as Digital Pacific, VentraIP, or Netregistry, where weak defaults attract automated attacks within hours of going live.

Log in with sudo mariadb to confirm the install. From the prompt, create a dedicated database and user for your first project rather than reusing root. Something like CREATE DATABASE workshop; followed by GRANT ALL ON workshop.* TO 'dev'@'localhost' IDENTIFIED BY 'a-strong-passphrase'; is a sensible pattern. Keep the credentials out of source control from day one; the Privacy Act 1988 and the Notifiable Data Breaches scheme mean that even accidental exposure of customer data carries reporting obligations, and good habits start on a local machine.

Setting up PHP and common extensions

PHP is the glue between Apache and the database, and the Ubuntu repositories ship a version that matches each release's support window. On a 24.04 install, the default is PHP 8.3. Pull in the language, the Apache module, and the database connector with sudo apt install php libapache2-mod-php php-mysql. Add other extensions as your projects need them: php-curl for API calls, php-xml for content frameworks, php-mbstring for Laravel, and php-gd or php-imagick for image work.

Confirm the install by creating a small test file. Run echo "<?php phpinfo(); ?>" | sudo tee /var/www/html/info.php and visit http://localhost/info.php in your browser. A long table of configuration values should appear, listing the loaded modules, the PHP version, and the server's environment. Delete the file once you are satisfied, because the same page that helps you debug is a gift to anyone scanning for vulnerable servers.

Most local development work is done in AEST or AEDT, and PHP inherits the system clock. Check that with date in the terminal. If you schedule cron jobs for backups, log rotation, or database exports, set the timezone explicitly in /etc/php/8.3/apache2/php.ini with date.timezone = Australia/Sydney (or Melbourne, Brisbane, Perth, or Adelaide as appropriate). It saves confusion when timestamps line up with the rest of your team.

Configuring virtual hosts and permissions

A single document root is limiting once you start juggling more than one site. Apache's virtual host system lets each project have its own folder, its own domain name on the local network, and its own configuration. Create a directory for the new site with sudo mkdir -p /var/www/example.test/public_html, then hand ownership to your regular user with sudo chown -R $USER:$USER /var/www/example.test. Working as a non-root user inside the site folder reduces the blast radius of a typo and keeps new files writable without sudo.

Copy the default site as a template: sudo cp /etc/apache2/sites-available/000-default.conf /etc/apache2/sites-available/example.test.conf. Open the new file and change the ServerName, DocumentRoot, and any ErrorLog or CustomLog lines so they point at the new directory. Enable the site with sudo a2ensite example.test.conf and disable the default with sudo a2dissite 000-default.conf, then reload Apache with sudo systemctl reload apache2.

Add an entry to your local hosts file so the name resolves without touching DNS. On the development machine, edit /etc/hosts and add 127.0.0.1 example.test on a new line. The site is now reachable at http://example.test from that machine. For a small team, sharing a development server on a home LAN is common, and each developer can map their own subdomain in their own hosts file while pointing at the same shared IP.

Securing the stack with firewall and HTTPS

A development server is still a server, and an unpatched Apache on a home NBN connection can attract attention from automated scanners within minutes of being online. Ubuntu ships with UFW, an uncomplicated firewall that defaults to blocking everything except outbound traffic. Allow SSH so you do not lock yourself out, then allow Apache: sudo ufw allow OpenSSH followed by sudo ufw allow in "Apache Full". Enable the firewall with sudo ufw enable and check the rules with sudo ufw status verbose.

For a public-facing test environment, layer in HTTPS. The Australian Cyber Security Centre's Essential Eight guidance recommends encryption in transit as a baseline, and the same principle applies on a small scale. Install Certbot from Snap with sudo snap install --classic certbot, then request a certificate for your local domain with sudo certbot --apache. Certbot renews certificates automatically through a systemd timer, so the only ongoing chore is keeping the snap package itself up to date.

The final hardening step is keeping everything current. Set up unattended upgrades with sudo dpkg-reconfigure --priority=low unattended-upgrades so security patches land during the night without manual intervention. In the morning, glance at /var/log/unattended-upgrades/ to confirm what was applied, and your stack will track Ubuntu's own security cadence with almost no effort.

Open a terminal right now and run sudo apt update to start the process; the rest of the stack will be ready before your coffee gets cold.