Make sure it's running as its own user and group.
Same for PHP, depending on how you run it (i.e. FPM).
And of course directory permissions, disabling what you don't need, proper limits, outgoing connections etc, listening to the right host headers only ... blablabla
Make sure it's running as its own user and group.
Same for PHP, depending on how you run it (i.e. FPM).
And of course directory permissions, disabling what you don't need, proper limits, outgoing connections etc, listening to the right host headers only ... blablabla