Magento and Adobe Commerce support: performance, security and deploys - init.d
IT

Magento and Adobe Commerce support: performance, security and deploys

Magento is demanding: you need a sysadmin who really knows it.

Magento (now Adobe Commerce) is one of the most full-featured e-commerce platforms around, and also one of the most demanding: multi-level caching, a dedicated search engine, queues, indexers and structured deploys. Without a sysadmin who really knows it, it turns slow and fragile. We handle the side that makes it work - infrastructure, performance, security and deploys - so the store runs the way it should.

Need custom development instead - plugins, modules, integrations? See e-commerce development.

Overview

A Magento left on defaults is heavy by definition: the platform was built for large catalogues and serious traffic, and it only performs at its best once Varnish, Redis and Elasticsearch/OpenSearch are in the right place. When a store slows down, the theme or the modules are rarely to blame - it’s almost always the underlying stack, set up once and never revisited since. Indexers, cron and queues complicate things further: if one of these gears jams, prices stop updating, orders sit unprocessed, and nobody notices until a customer calls.

Our method is straightforward: first we take a real snapshot of the system, then we remove the bottlenecks one by one and secure the rest. We’re a systems consultancy, not a hosting provider: no black boxes, a single technical contact who knows your store, and documented configurations that stay your property.

Typical problems we solve

  • High TTFB even on catalogue pages → we configure Varnish as a real full-page cache, with hole punching for private blocks.
  • Internal search is slow or returns wrong results → we tune Elasticsearch/OpenSearch with resources and mapping sized for your catalogue.
  • Reindexing locks up the site during peak hours → we move indexers to scheduled mode and fix cron and queues.
  • Every deploy is a leap into the unknown → we build a repeatable pipeline with setup:upgrade, di:compile and static content deploy, rollback included.
  • Security patches behind schedule and an exposed admin → we apply patches on staging and lock down the admin area with 2FA, a WAF and access restrictions.
  • Sales traffic brings the server to its knees → we size the stack to real load and, where needed, add web nodes behind a load balancer.
  • Magento cron jobs overlap or die silently → we monitor executions and queues, with alerts when something stops running.

What’s included

  • Performance tuning: Varnish for full-page cache, Redis for object cache and sessions, Elasticsearch/OpenSearch for search, tuning of PHP-FPM, OPcache and the database.
  • Environment management: dev, staging and production kept aligned, with consistent data and configuration so every change is tested before release.
  • Deploys and releases: a repeatable pipeline with setup:upgrade, di:compile and static content deploy, the site set to production mode and a rollback always ready.
  • Indexing and queues: scheduled indexers, reliable cron and message queues (RabbitMQ included) kept under control, with alerts on anomalies.
  • Security: official patches applied methodically, admin area protection, 2FA, WAF, HTTPS and hardening of filesystem and database permissions.
  • Scalability: resource sizing based on measured traffic and, when needed, multiple web nodes behind a load balancer for sales and campaigns.
  • Monitoring: metrics on response times, queues and indexers, so problems surface before your customers see them.

Stack and technologies

Nginx sits in front of PHP-FPM with OPcache, on the version supported by your Magento release, and MariaDB/MySQL (or Percona) tuned to the real workload. Varnish handles full-page cache, Redis object cache and sessions, Elasticsearch or OpenSearch catalogue search; Composer manages dependencies, cron and message queues run background processing, Cloudflare acts as CDN and first line of defence at the edge. For the operating system we use Debian and Ubuntu, with AlmaLinux, Rocky Linux and other distributions available on request. On the cloud side we work mainly on Google Cloud, with AWS and DigitalOcean as proven alternatives - but a dedicated server or VPS you already have works just as well. Every component is configured around your store: a Magento catalogue of twenty thousand SKUs isn’t handled the same way as one with two hundred.

A real-world example

A B2B company with a Magento catalogue of over twenty thousand items came to us because category pages took several seconds to load and overnight reindexing was spilling into business hours. Varnish was installed but effectively inactive: almost every request was reaching PHP because a module had set the headers wrong. We fixed the cache rules, moved sessions and object cache onto Redis, switched indexers to scheduled mode, and gave Elasticsearch resources sized to the catalogue. To finish, we set up a deploy pipeline with rollback, retiring FTP updates for good. The result: category pages served from cache, reindexing that finishes overnight, and releases that no longer need a maintenance window.

Who it’s for

  • Magento and Adobe Commerce stores with large catalogues or growing traffic that have started to slow down.
  • Businesses that have invested in the platform and want solid infrastructure without having to oversee it themselves.
  • Agencies and software houses that build themes and modules and are looking for a systems partner for servers, performance and deploys.
  • Anyone inheriting an improvised stack who needs clean environments, repeatable releases and security put back in order.

How we work

We start with a check of the store and server: Magento version, the state of Varnish, Redis and Elasticsearch/OpenSearch, the health of indexers, cron and queues, response times and weak points on the security side. From there we set out a plan with clear priorities and an indicative price, discussed before we start, agreeing every maintenance window with you. Changes go through staging before touching production, and at the end of the work you get a readable report: what we changed, why, and how it’s configured. Standard coverage is Mon-Fri 10:00-18:00 with priority triage - details are on the response times page - and for ongoing management there are hour packages that never expire. No lock-in: the store stays yours, verifiable line by line.

Frequently asked questions

Why is my Magento so slow?

Almost always missing or misconfigured caching, heavy indexing and unoptimised queries. With Varnish, Redis and Elasticsearch/OpenSearch set up correctly, TTFB drops sharply: before switching servers, it’s worth fixing the stack.

Do you handle Magento deploys or just the server?

Both. We set up a repeatable deploy pipeline with setup:upgrade, di:compile and static content deploy: every release becomes predictable, with a rollback ready if something doesn’t add up.

Does Adobe Commerce need a dedicated server?

It depends on traffic and catalogue size. We size the stack on measured load, not estimates: in many cases one well-configured machine is enough, and when it isn’t, we set up multiple web nodes behind a load balancer to handle spikes.

Do you also handle updates and security patches?

Yes. We apply patches on staging first, test checkout and integrations, then promote to production with backups and rollback ready. No patch is ever applied blindly on the live store.

How much does Magento systems support cost?

On a pay-as-you-go basis, we bill at a flat €75/hour. For ongoing support, hour packages are the better fit and never expire: 5 hours at €350, 10 at €660, 20 at €1,200. Quotes are free, with a reply within one business day.

What response time do you guarantee if the store goes down?

We triage every request on a P1-P4 scale: a store that’s down is a P1, and we pick it up within one business hour. Standard coverage is Mon-Fri 10:00-18:00; night and weekend emergencies require a monthly on-call retainer, while work planned at least 20 days ahead does not.

Do you also work at night or on weekends?

Guaranteed only for clients with an active on-call plan, and only for real P1 emergencies: production down, data loss, active security incident. On-call is a monthly retainer with limited seats, available on systems we manage and, after a case-by-case assessment, on others too: prices and rules are on the On-call page. Without a plan, coverage is Mon-Fri 10:00-18:00 and out-of-hours work is best effort: it may happen, but it is neither guaranteed nor something you can demand. Night or holiday work planned at least 20 days ahead remains available to everyone, at the surcharged rate.

Need a hand with your infrastructure?

Tell us the problem: we reply with a clear plan and a quote.

Get in touch →