Recommended Server Stack and Hosting for Drupal 10 and 11

Drupal 11 raised the floor, and a good number of estates are now sitting below it. The upgrade is less a code change than a platform change, because Drupal 11 mandates newer versions of nearly every layer underneath it. Getting the stack right first is what makes the code upgrade routine rather than painful — and for a regulated firm, an unsupported CMS stack is a security and compliance exposure, not just a technical inconvenience.

What Drupal 11 actually requires

The baseline is specific and non-negotiable:

  • PHP 8.3 — older versions are unsupported, and future minor releases will raise this further as PHP itself moves on.
  • Database — MySQL 8.0, MariaDB 10.6, PostgreSQL 16, or SQLite 3.45, with InnoDB and the PDO extension.
  • Web server — Apache 2.4.7+ or Nginx 1.1+. Windows and IIS support in production has been removed.
  • Tooling — Composer 2.7+ and, if you use it, Drush 13. Under the hood, Symfony 7 and jQuery 4.

The deadline that matters: Drupal 10 receives support until roughly the end of 2026, after which the supported path is Drupal 11 (and then 12). Running a Drupal 10 site past that point puts you in the same unsupported position that Drupal 7 sites reached when their support ended in January 2025.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

A sensible target stack

For most regulated firms, the low-drama choice is a Linux host (a current Ubuntu LTS or RHEL family), Nginx or Apache, PHP 8.3 with OPcache and the standard extensions (PDO, XML, GD, OpenSSL, JSON, cURL, Mbstring, zlib), MariaDB 10.6+ or MySQL 8.0, and Composer-managed deployments. Add Redis or Memcache and a reverse-proxy or CDN cache if traffic warrants. The specifics matter less than the principle: pick versions that will remain vendor-supported for the life of the site, not the ones that merely work today.

The upgrade path, in order

The sequence is what trips teams up. Get to Drupal 10.3 or later first, because earlier update paths have been removed. Bring contributed modules to their latest versions, run an upgrade-status report, remediate custom code for PHP 8.3 and the deprecations, and only then move core to 11. Attempting the jump before the environment and the dependencies are ready is the reliable way to break a site mid-upgrade.

For a regulated firm, the honest prior question is whether Drupal remains the right platform for the estate at all — but if it does, upgrading onto a supported stack deliberately is far cheaper than being forced off an unsupported one later.

Who this is for

This reading is for:

  • Technical leads planning a Drupal 10 to 11 upgrade
  • Platform engineers specifying hosting for a regulated firm’s Drupal estate
  • CTOs deciding whether to upgrade, re-host, or re-platform
  • Teams whose Drupal site is drifting toward an unsupported stack

Sixteen Pillars advises regulated firms on whether Drupal remains the right platform for the estate, and on upgrading onto a supported stack deliberately. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Build and rescue work

Hands-on delivery of this kind is handled by Sixteen Pillars Studio.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Can you trust the architecture you have?

Architecture diagrams rarely show the reality of how systems actually operate. An independent review establishes what is really there.