Review App Service PHP runtime support

Use a supported PHP release, test app compatibility, and apply security updates.

Description

An end-of-support PHP runtime may no longer receive security fixes or technical support, increasing operational risk. Check App Service and PHP support, security updates, and application compatibility rather than choosing solely by the highest version number.

Potential impact

  • Unfixed runtime vulnerabilities can remain exposed.
  • Framework compatibility, dependencies, and operational support can be affected.

Remediation

Check App Service’s available runtimes and support periods, then choose a supported PHP release. For current Linux Web Apps, set site_config.application_stack.php_version. Test the app and its dependencies, and review runtime versions and support status regularly.

Examples

The first excerpt is a historical Windows PHP configuration, which is no longer supported. Current built-in App Service PHP runtimes run on Linux. Supply an actual Linux service plan ID and a supported PHP version to the second excerpt.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    php_version              = "7.3"
  }
}

After

hcl
resource "azurerm_linux_web_app" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  service_plan_id     = var.service_plan_id

  site_config {
    application_stack {
      php_version = var.php_version
    }
  }
}

The revision uses the current Linux Web App runtime field. Switching resources and operating systems is not merely a version-string change; migrate the app and deployment configuration as well.

References