Description
An end-of-support PHP runtime may no longer receive security fixes or technical support, increasing operational risk. Check App Service and PHP support, security updates, and application compatibility rather than choosing solely by the highest version number.
Potential impact
- Unfixed runtime vulnerabilities can remain exposed.
- Framework compatibility, dependencies, and operational support can be affected.
Remediation
Check App Service’s available runtimes and support periods, then choose a supported PHP release. For current Linux Web Apps, set site_config.application_stack.php_version. Test the app and its dependencies, and review runtime versions and support status regularly.
Examples
The first excerpt is a historical Windows PHP configuration, which is no longer supported. Current built-in App Service PHP runtimes run on Linux. Supply an actual Linux service plan ID and a supported PHP version to the second excerpt.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
php_version = "7.3"
}
}
After
resource "azurerm_linux_web_app" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
service_plan_id = var.service_plan_id
site_config {
application_stack {
php_version = var.php_version
}
}
}
The revision uses the current Linux Web App runtime field. Switching resources and operating systems is not merely a version-string change; migrate the app and deployment configuration as well.