A fresh Ubuntu server can't serve a single web page until you give it a web server, a database and a language that ties them together. This guide shows how to install LAMP stack on Ubuntu 26.04 or 24.04 in one sitting, with every command checked against the current Ubuntu packages.
Quick Answer: To install a LAMP stack on Ubuntu, run
sudo apt update, thensudo apt install apache2 mysql-server php libapache2-mod-php php-mysql, allow "Apache Full" in UFW, runsudo mysql_secure_installation, and load a phpinfo() test page. As of September 2026, Ubuntu 26.04 LTS installs Apache 2.4.65, MySQL 8.4 and PHP 8.5, while Ubuntu 24.04 LTS installs MySQL 8.0 and PHP 8.3.
Last verified: September 2026: Ubuntu 26.04 LTS (Apache 2.4.65, MySQL 8.4.8, PHP 8.5, MariaDB 11.8) and Ubuntu 24.04 LTS (MySQL 8.0, PHP 8.3, MariaDB 10.11)
Our engineers resolve 20-30 client server issues every day, and a steady share of them trace back to a LAMP build that skipped one quiet step. This walkthrough comes straight from that work. Follow it once and you'll have a stack you can also fix yourself when something slips.
What a LAMP Stack Is and Which Ubuntu Version to Use
LAMP is four open-source layers on one server. Linux runs the machine, Apache answers browser requests on ports 80 and 443, MySQL stores your data, and PHP builds each page on the fly. As of September 2026, that combination is still the default base for self-hosted WordPress, Drupal and Laravel sites, and every piece ships in Ubuntu's own repositories.
That last point matters more than it sounds. Every Apache MySQL PHP Ubuntu install in this guide uses only the default repositories, so security patches arrive through normal apt upgrade runs with no third-party sources to babysit.
Your Ubuntu release decides which versions you get:
| Component | Ubuntu 26.04 LTS | Ubuntu 24.04 LTS | |---|---|---| | Apache | 2.4.65 | 2.4.x | | MySQL | 8.4 LTS | 8.0 | | MariaDB (alternative) | 11.8 | 10.11 | | PHP | 8.5 | 8.3 | | Free security updates until | April 2031 | April 2029 |
Our take: choose 26.04 for any new server. It gets the longest support window and the newest PHP. Stay on 24.04 only if an app you rely on hasn't certified PHP 8.5 yet. The full package list is in the Ubuntu 26.04 LTS release notes, and Apache's own HTTP Server 2.4 documentation explains every directive used below.
Before you start, you need a server with a sudo user, at least 1 GB of RAM and about 10 GB of free disk. If the box is brand new, run through our Linux VPS security baseline for Ubuntu first. It takes around 30 minutes and closes the obvious doors.
How to Install LAMP Stack on Ubuntu, Step by Step
The whole install is four apt commands plus a firewall rule, and on a typical VPS it finishes in about 15 minutes. Run each step in order and check its result before moving on, because a problem caught at step 2 takes seconds to fix, while one caught at step 4 can take an hour to trace.
Step 1: Update the package index
bashsudo apt update && sudo apt upgrade -y
If the upgrade pulls in a new kernel, reboot now rather than halfway through the build.
Step 2: Install Apache and open the firewall
bashsudo apt install apache2 -y sudo systemctl enable --now apache2 sudo ufw allow OpenSSH sudo ufw allow "Apache Full" sudo ufw enable
The "Apache Full" profile opens port 80 (HTTP) and port 443 (HTTPS). Now visit http://your_server_ip in a browser. If you see the Apache2 Ubuntu Default Page, layer one works.
Pro Tip: Always allow OpenSSH before running
ufw enable. We've handled plenty of "my server vanished" tickets that were really a firewall switched on over an SSH session with no SSH rule. Our UFW firewall guide for Ubuntu covers the safe order in detail.
Step 3: Install MySQL
bashsudo apt install mysql-server -y sudo systemctl status mysql
Look for active (running) in the output. Prefer MariaDB? Use sudo apt install mariadb-server instead. On Ubuntu the two servers are mutually exclusive, so pick one and stick with it.
Step 4: Install PHP and the modules most apps expect
bashsudo apt install php libapache2-mod-php php-mysql php-cli php-curl php-gd php-mbstring php-xml php-zip -y php -v sudo systemctl restart apache2
php -v should report PHP 8.5.x on 26.04 or 8.3.x on 24.04. The extra modules cover what WordPress and most frameworks check for on first run, and the official PHP manual documents each extension if you need more.
Pro Tip: Apache and the command line read different config files. Settings for your website go in
/etc/php/8.5/apache2/php.ini(use8.3on 24.04), not in theclifolder. The defaults are tight, too:memory_limitis 128 MB andupload_max_filesizeis only 2 MB, which is why so many first WordPress uploads fail.
Secure MySQL Without Locking Yourself Out
Run the secure MySQL installation script next. It removes anonymous users, blocks remote root logins and drops the test database in under 2 minutes:
bashsudo mysql_secure_installation
Answer Y to removing anonymous users, disallowing remote root login, removing the test database and reloading the privilege tables. The VALIDATE PASSWORD component is optional; switch it on if other people will create database users on this server.
On Ubuntu, MySQL's root account uses the auth_socket plugin, so it logs in through sudo mysql with no password at all. According to Hostaccent's support queue in 2026, where our engineers handle 20-30 client issues every day, the endless "SET PASSWORD has no significance" loop in this script is one of the most repeated LAMP questions. It isn't a broken install. The script simply can't set a password on a socket-authenticated user, so stop it with Ctrl+C (or kill it from a second SSH session) and carry on. Current packages usually skip that prompt entirely.
Should I switch MySQL root to a password?
No, and this is exactly where older guides go wrong. Many tell you to run ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password. On MySQL 8.4, the default on Ubuntu 26.04, that plugin is deprecated and accounts using it are locked out by default. Keep root on the socket and give each application its own user:
bashsudo mysql
sqlCREATE DATABASE appdb; CREATE USER 'appuser'@'localhost' IDENTIFIED BY 'Use-A-Long-Unique-Password'; GRANT ALL PRIVILEGES ON appdb.* TO 'appuser'@'localhost'; EXIT;
New users get caching_sha2_password by default, and PHP's mysqli and PDO drivers handle it natively, so there's nothing else to configure. Want a browser-based database tool later? Our phpMyAdmin setup guide adds one with a separate admin account, so root never needs a password.
Still working through this server issue?
Send the symptoms, error output, and what you have already tried. We can work with Hostaccent services or infrastructure hosted with another provider.
Set Up a Virtual Host and Test Your Stack
A virtual host tells Apache which folder belongs to which domain. Setting one up now, even for a single site, takes about 5 minutes and saves you from the classic "I uploaded my site but still see the Apache default page" problem later.
bashsudo mkdir -p /var/www/example.com sudo chown -R $USER:www-data /var/www/example.com sudo nano /etc/apache2/sites-available/example.com.conf
Paste this, swapping in your domain:
apache<VirtualHost *:80> ServerName example.com ServerAlias www.example.com DocumentRoot /var/www/example.com <Directory /var/www/example.com> AllowOverride All Require all granted </Directory> ErrorLog ${APACHE_LOG_DIR}/example.com_error.log CustomLog ${APACHE_LOG_DIR}/example.com_access.log combined </VirtualHost>
bashsudo a2ensite example.com.conf sudo a2dissite 000-default.conf sudo a2enmod rewrite sudo apache2ctl configtest sudo systemctl reload apache2
Use a test PHP info page
bashecho "<?php phpinfo();" | sudo tee /var/www/example.com/info.php
Open http://example.com/info.php (or your server IP if DNS isn't pointed yet). You should see the PHP information table with Server API reading "Apache 2.0 Handler". Delete the file once you've checked it, because it publishes your full server configuration to anyone who finds it: sudo rm /var/www/example.com/info.php.
Prove PHP can reach MySQL
Save this as /var/www/example.com/db-test.php, load it in your browser, then delete it:
php<?php try { $db = new mysqli('localhost', 'appuser', 'Use-A-Long-Unique-Password', 'appdb'); echo 'Connected to MySQL ' . $db->server_info; } catch (mysqli_sql_exception $e) { echo 'Failed: ' . $e->getMessage(); }
The try/catch matters because mysqli throws exceptions by default since PHP 8.1, so an old-style error check never runs.
The Four-Light Check
Our team runs the same four checks on every fresh build before calling it done. All four lights must be green:
- Apache light: your site (or the default page) loads over HTTP.
- PHP light: info.php shows your PHP version and "Apache 2.0 Handler".
- Database light: db-test.php prints "Connected to MySQL".
- Reboot light: after
sudo reboot, lights 1 to 3 still pass without you touching anything.
Across the 4,000+ sites Hostaccent has migrated since 2016, we found the reboot light is the one people skip most, and it's the one that bites at 3 a.m. when a host restarts. The systemctl enable commands above are what make it pass.
Common LAMP Mistakes and What to Do Next
Most broken LAMP builds fail in one of four predictable ways, and each has a fix you can apply in under 5 minutes. Check this list before reinstalling anything, since a reinstall rarely fixes a config mistake and often adds a second one.
- The browser downloads the .php file instead of running it.
libapache2-mod-phpis missing or Apache wasn't restarted after PHP went in. - You still see the Apache default page.
000-default.confis still enabled, or your domain's A record points somewhere else. - 403 Forbidden on your own site. The
<Directory>block lacksRequire all granted, orwww-datacan't read the folder. - "Access denied for user 'root'@'localhost'". You tried
mysql -u root -pagainst a socket-authenticated root. Usesudo mysqlinstead.
Harden and extend it
Your stack works, but it isn't finished. Add HTTPS with a free Let's Encrypt certificate:
bashsudo apt install certbot python3-certbot-apache -y sudo certbot --apache -d example.com -d www.example.com
Certificates last 90 days, and Certbot's timer renews them automatically. After that, set up automated rsync and cron backups and server monitoring that alerts you first.
Insider Insight: The default mod_php setup is fine for one or two sites, and we'd use it on a first build without hesitation. Once you host several sites or see memory spikes under traffic, move to PHP-FPM with Apache's event MPM. Our Nginx + PHP-FPM performance tuning guide covers the pool settings that make the real difference.
What to remember from this build:
- Use Ubuntu 26.04 for new servers: PHP 8.5, MySQL 8.4 and updates until April 2031.
- Leave MySQL root on auth_socket and create one database user per app.
- Delete info.php and db-test.php the moment they've done their job.
- Don't call it done until the Four-Light Check passes after a reboot.
Your Next Step: A Server Ready for This Build
Now that you've seen how to install LAMP stack on Ubuntu, and why that root password loop is auth_socket doing its job rather than a broken MySQL, the rest is under an hour of careful typing. You can run it on a spare machine this weekend, or on a VPS where real engineers are one ticket away if a step goes sideways. Hostaccent has been hosting since 2016 (UK-incorporated 2018), and the Basic plan at $7.99/mo (renews at $7.99/mo) gives you full root access, free 30 Gbps DDoS protection and 24/7 support from our in-house engineers, with a 30-day money-back guarantee. One honest caveat: no control panel is bundled, so a cPanel licence costs extra. When you're ready, start on the Basic plan and run this guide on it tonight.
Frequently Asked Questions
What do I need before learning how to install LAMP stack on Ubuntu?
You need an Ubuntu 26.04 or 24.04 server, a user with sudo rights, and SSH access from your computer. A VPS with 1 GB of RAM handles a small site, though 2 GB gives MySQL more breathing room. Basic terminal comfort helps: pasting commands, editing a file in nano and reading an error message. You don't need a domain to start, since every test in this guide works on the server's IP address.
Should I use MariaDB instead of MySQL?
Either works for a LAMP stack, and most PHP apps, including WordPress, support both. On Ubuntu 26.04, MariaDB 11.8 now has full support in the main repository, so it's a first-class choice rather than a workaround. Pick MySQL 8.4 if your app's documentation names it, or MariaDB if you prefer its community release model. Just don't install both, because the two servers conflict on Ubuntu and apt will remove one.
Why does my browser download PHP files instead of showing the page?
This happens when Apache doesn't know how to hand .php files to PHP, so it serves them as plain downloads. The usual cause is a missing libapache2-mod-php package, or an Apache service that wasn't restarted after PHP was installed. Run sudo apt install libapache2-mod-php, then sudo systemctl restart apache2, and clear your browser cache before testing again, because browsers often remember the old download response.
Can I use these commands for a LAMP stack 22.04 setup?
Yes. A LAMP stack 22.04 setup uses the same apt commands, but you'll get PHP 8.1 and MySQL 8.0 instead of the newer versions. PHP 8.1 is past its upstream support, so for anything long-lived we'd recommend moving the server to 24.04 or 26.04 rather than stacking third-party PHP repositories on an older base. Standard free security updates for Ubuntu 22.04 end in April 2027, which is close enough to plan around now.
Is mod_php or PHP-FPM better for Apache?
For a first server with one or two sites, mod_php is simpler and performs fine. PHP-FPM wins once you host several sites, because each site gets its own process pool, and Apache can switch to the event MPM, which uses noticeably less memory under load. You can start with mod_php today and migrate later using a2dismod, a2enmod proxy_fcgi and a2enconf for the PHP-FPM config, plus the MPM swap, without rebuilding anything.











Discussion
Have a question or tip about this topic? Share it below — your comment will appear after review.