The summary.
DISABLE DEBUG MODE IN PRODUCTION
It exposes paths, versions and sometimes credentials. And log errors rather than displaying them.
DEPLOY IN THE SAME ORDER EVERY TIME, AUTOMATED
Back up, deploy, install dependencies, migrate, rebuild caches, restart, verify.
Rebuild caches as part of every deployment — cached configuration does not re-read its source, which is why changes appear not to take effect.
NEVER EDIT FILES DIRECTLY ON THE SERVER
They are lost at the next deployment and exist nowhere else.
VERIFY AFTERWARDS, AND WATCH ERROR RATES FOR AN HOUR
Problems appear under real traffic, not during verification.
MONITOR FROM OUTSIDE, AND MONITOR BUSINESS OUTCOMES
A site can serve an error page while appearing healthy, and a broken form produces no errors at all while stopping every enquiry.
Send alerts somewhere independent of the site.
WHAT GETS NEGLECTED
Updates, until something is exploited. Backups, until one is needed. And content dates, which suggest a dormant business.