Install ONHOST CMS
Deploy ONHOST CMS on a supported PHP host, connect MySQL or MariaDB, and complete the browser installer.
## What you need
ONHOST CMS is a self-hosted PHP application for selling digital products and hosting services from one customer portal. Before installing, prepare a domain, a MySQL or MariaDB database, and a hosting account that can run PHP 8.2 or later.
- PHP 8.2 or later with `pdo`, `pdo_mysql`, `mbstring`, `openssl`, `curl`, `zip`, `json`, `fileinfo`, `intl` and `gd`.
- MySQL 8.0+ or MariaDB 10.6+.
- HTTPS for all customer, checkout, administration and API traffic.
- A writable `storage` directory for generated configuration, sessions, logs and private downloads.
- A document root that points to the package `public` directory.
## Upload the release
Upload the complete ONHOST CMS release outside the public web root when your host supports it. Point the domain to the `public` directory inside that release. Do not expose `app`, `config`, `database`, `resources` or `storage` directly to the web.
```
/home/account/onhost-cms/
├── app/
├── storage/
└── public/ ← domain document root
```
## Create the database
Create an empty database and a dedicated database user in your hosting panel. Use `utf8mb4` and keep the credentials ready for the installer. The installer writes its generated connection configuration to `storage/generated/app.php`; do not place production passwords in themes or frontend code.
## Run the installer
Open `https://your-domain.example/install`. The installer checks the PHP runtime, required extensions, writable directories, database connection and first administrator account before locking itself. Once complete, sign in at `/admin` and immediately review the production settings.
## After installation
- Turn on **Force HTTPS** once your TLS certificate is live.
- Configure SMTP before inviting users or accepting paid orders.
- Set company, VAT and invoice details before issuing invoices.
- Keep `storage/private/downloads` outside public access; ONHOST serves files through authenticated, signed endpoints.
> If the installer reports a database or permissions error, fix the host configuration first. Re-running the installer is safer than manually editing the generated runtime configuration.