# Server Hardening + Restart Guide (Single File)

Use this as a one-stop checklist for:
- securing `.env` and other sensitive files
- setting correct Laravel Apache vhost
- restarting services
- clearing Laravel + OPcache caches
- verifying protection

---

## 1) Apache Vhost (Production)

Create or update:

`/etc/apache2/sites-available/sudheerktonegramgold.conf`

```apache
<VirtualHost *:80>
    ServerName sudheerktonegramgold.com
    ServerAlias www.sudheerktonegramgold.com

    # IMPORTANT: Laravel must be served from /public only
    DocumentRoot /var/www/html/sudheerktonegramgold/live/public

    <Directory /var/www/html/sudheerktonegramgold/live/public>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>

    # Block hidden files/folders from URL access (except ACME challenge)
    <LocationMatch "^/(?!\.well-known/)\.">
        Require all denied
    </LocationMatch>

    # Block sensitive files explicitly
    <LocationMatch "^/(?:\.env|composer\.(?:json|lock)|package\.json|artisan|phpunit\.xml(?:\.dist)?|\.git)">
        Require all denied
    </LocationMatch>

    ErrorLog ${APACHE_LOG_DIR}/sudheerktonegramgold-error.log
    CustomLog ${APACHE_LOG_DIR}/sudheerktonegramgold-access.log combined
</VirtualHost>
```

If you use HTTPS (`:443`), apply the same `DocumentRoot` and `LocationMatch` rules there as well.

---

## 2) Enable Modules + Site + Config Test + Reload

```bash
sudo a2enmod rewrite headers
sudo a2ensite sudheerktonegramgold.conf
sudo apachectl -t
sudo systemctl reload apache2
```

---

## 3) Laravel Cache Clear + Rebuild

Run from project root:

```bash
cd /var/www/html/sudheerktonegramgold/live

# Clear all Laravel caches
php artisan optimize:clear

# Rebuild key caches
php artisan config:cache
php artisan route:cache
php artisan view:cache

# If queue workers are used
php artisan queue:restart
```

---

## 4) OPcache Clear / Service Restart

### If PHP-FPM is used

```bash
sudo systemctl restart php8.2-fpm
sudo systemctl reload apache2
```

### If mod_php is used (no php-fpm)

```bash
sudo systemctl restart apache2
```

---

## 5) Verify Security + App Health

```bash
curl -I https://sudheerktonegramgold.com/.env
curl -I https://sudheerktonegramgold.com/composer.json
curl -I https://sudheerktonegramgold.com/
```

Expected:
- `/.env` => `403` or `404`
- `/composer.json` => `403` or `404`
- `/` => `200`

---

## 6) Immediate Incident Remediation (If `.env` was exposed earlier)

Rotate secrets now:
- DB credentials
- mail credentials
- SMS/OTP API keys
- payment keys (Razorpay etc.)
- any third-party API keys/tokens

If `APP_KEY` was exposed, rotate it (sessions/cookies will be invalidated), then restart services and clear caches again.

---

## 7) Additional Note

Your repo now has a root-level `.htaccess` as extra protection, but **server-level vhost config is the real fix**.
