Apache's configuration denied the request before it reached your app: Directory permissions/Require rules, filesystem permissions, or missing DirectoryIndex. The error log names the satisfied/failed condition — it is the whole diagnosis.
Apache 2.4's Require directives: Require all denied in the wrong scope, a leftover Order/Deny (2.2 syntax) that silently does nothing in 2.4, or Require ip blocks excluding your client. The AH01630 log line identifies the failing rule.
The apache user must have read (and +x on directories) access to every path component. After migrations or as different users create files, a single 700 directory anywhere in the path yields 403 even with correct Apache config.
DirectoryIndex not finding index.html/index.php + Options -Indexes = 403 on directory paths while direct file paths serve fine. The distinguishing signature: files work, directories don't.
tail -5 /var/log/apache2/error.log # AH01630 names the path and module
<Directory /var/www/app>\n Require all granted\n</Directory> # then: apachectl configtest && systemctl reload apache2
namei -l /var/www/app/index.html # shows every path component's permissions at once
# DirectoryIndex index.php index.html + Options +Indexes only where listing is intended
2.2→2.4 migrations break here constantly: Order allow,deny / Allow from all silently fail on 2.4 (wrong module), converting a working vhost into blanket 403s. The migration path is Require all granted. namei -l is the one-command permission audit: it walks every directory in the path so a single root-owned 700 hop can't hide.
Scoped Require rules: a Require ip allowlist in a Location/Directory block denies everyone else. The error log's path + the vhost's rule order tell you which block matched — restrictive blocks override later permissive ones.
A parent directory denies traversal: every component from / down needs +x for the apache user. namei -l /path/to/file reveals the hop that's missing it — usually a home dir or a 750 created by a deployment user.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.