Linux, Web Server & Database
Fix Nginx Permission Error
Fix file and directory permission errors stopping Nginx (or PHP-FPM behind it) from serving your site correctly.
The Problem
Nginx returns a 403 Forbidden error, or PHP-FPM can't read or write files it needs, because ownership or permissions don't match what the Nginx or PHP-FPM process user requires.
About this problem
With Nginx, permission issues often involve two separate process users to check — Nginx itself for serving static files, and PHP-FPM (running as a potentially different user) for anything that needs to read or write via PHP, such as an uploads folder or cache directory. A mismatch between the two is a common, easy-to-miss cause of errors that only affect dynamic functionality, not static pages.
This typically shows up after a manual file upload as root, a migration, or a backup restore that didn't preserve the original ownership structure.
What's Included
- Identifying exactly which files/folders have incorrect ownership or permissions
- Checking both the Nginx and PHP-FPM process users for consistency
- Correcting ownership and setting appropriately restrictive permissions
- Testing that previously-failing functionality now works correctly
What's NOT Included
- Fixing an active security compromise caused by permissions left deliberately too open
- Ongoing permission management as new files are added
- Shared hosting environments where permission control is restricted by the host
How It Works
- Check Nginx's error log for the specific file or path triggering the permission denial.
- Confirm which user Nginx runs as, and separately which user the relevant PHP-FPM pool runs as.
- Correct ownership so both the web server and PHP-FPM can access what each specifically needs.
- Set permissions narrowly — read for static assets, write only where the application genuinely needs it (uploads, cache).
- Test the specific previously-failing functionality to confirm the fix without over-permissioning anything.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Why does my PHP upload fail even though the folder exists?
- Usually because PHP-FPM's process user doesn't have write permission to that specific folder, even if Nginx itself can read the rest of the site fine.
- Do Nginx and PHP-FPM run as the same user?
- Not always — they can be configured with different users, and a mismatch between what each one can access is a common source of permission errors that only affect dynamic (PHP) functionality.
- Why do I get a 403 error on static files but PHP pages work fine?
- That points specifically at Nginx's own file permissions for static assets, separate from whatever PHP-FPM can access for dynamic content.
- How do I check what user PHP-FPM runs as?
- The user and group directives in the relevant PHP-FPM pool configuration file (commonly under /etc/php/*/fpm/pool.d/) specify this.
- Is 755 or 777 the right permission for my web folder?
- 755 (owner read/write/execute, others read/execute) is the common safe default for most web content — 777 grants write access to everyone and should be avoided.
- Will a migration between servers break file permissions?
- Yes, commonly — ownership is often tied to user IDs that don't match between servers, so a migrated site frequently needs its permissions corrected on the new server.