Timberdocs

Getting started

Deploying anywhere

Timber is a folder of files. Deployment is putting that folder where a PHP web server can see it.

What to deploy#

PathDeploy?Notes
index.php, router.php, .htaccess, .user.iniYesFront controller and server rules
inc/, padmin/, templates/YesCore
themes/, assets/YesThemes and static files
docs/OptionalThis documentation. Delete it if you don't want it public
_dev/, _prd/, README.mdOptionalBlocked from the web anyway
data/*.jsonNoYour content and your accounts' password hashes. Created on the server; git-ignored
uploads/NoYour media. Sync separately; never overwrite blindly

Apache, LiteSpeed, cPanel#

Upload everything and make sure the dotfiles arrived — FTP clients often hide them:

.htaccess in the root and in data/, inc/, templates/, themes/, _dev/ and uploads/.

Folders 755, files 644; data/ and uploads/ must be writable by the PHP user. Then open the site and install.

nginx#

nginx ignores .htaccess. Use the ready-made config:

  • Plain nginx + PHP-FPM: _dev/nginx.conf.example
  • CloudPanel: _dev/nginx-cloudpanel.conf — paste it into the site's Vhost and replace example.com.

Git-based deploys#

Commit the project, push, pull on the server — and keep data/ and uploads/ persistent between releases. See Installation → Commit and deploy.

A simple zero-downtime layout, if you use symlinked releases:

/var/www/site/
  releases/2026-10-09/     # a checkout of your repo
  shared/data              # persistent
  shared/uploads           # persistent
  current -> releases/2026-10-09
# in each release:  ln -s ../../shared/data data  &&  ln -s ../../shared/uploads uploads

Subfolders#

Timber auto-detects its folder, so example.com/site/ just works. Override with the TIMBER_BASE_PATH environment variable if you must.

Behind a cache, proxy or CDN#

  • Admin pages, version previews, redirects and any page rendered for a logged-in admin send no-store / private, so a cache never serves them to visitors.
  • Public pages are safe to cache. Purge after a deploy or after you publish.
  • Static files carry ?v=filemtime in their URLs, so browsers and CDNs refetch changed files automatically.

Updating Timber#

Copy the new inc/, padmin/, templates/, assets/vendor, assets/themes/_base, router.php and .htaccess over the old ones. Don't touch data/, uploads/, or any theme you've edited. Click through a few admin screens afterwards — one-time migrations run on your first admin visit.

Pre-flight checklist#

  • ☐ PHP 8.1+ and writable data/ + uploads/
  • ☐ Dotfiles uploaded (or nginx rules added)
  • ☐ HTTPS on
  • ☐ Installed immediately after upload
  • ☐ Site URL set in SEO & Metrics
  • ☐ Email sends a test message
  • ☐ A backup exported
Timber is open source. Built by indies, for indies. © 2026