Scheduled jobs

Four jobs. One of them is the difference between a working installation and a silent one.

Each job is a PHP file you run on a schedule. In cPanel the screen is called Cron Jobs; on a server you manage yourself it is crontab.

JobHow oftenWhat it does
cron/process_email_queue.phpEvery 5 minutesSends queued mail using the saved batch size, inter-send delay and rolling-hour attempt cap, and checks whether an audit year is due for archiving. Defaults: 25 messages, one second between attempts and 100 attempts per hour.
cron/process_webhook_queue.phpEvery minuteSends signed API-client webhook events, up to 25 per run, and retries non-2xx or unavailable receivers with bounded backoff.
cron/cleanup_exports.phpHourlyDeletes generated export files older than EXPORT_FILE_LIFETIME_HOURS.
cron/cleanup_certificate_documents.phpDailyDeletes PDF files not accessed for six months. Keeps approved business values and render history; the next authorised access regenerates with current template appearance and verification, if the background assets are retained.
cron/archive_audit_logs.phpMonthly, or not at allForces an audit archive run. The email-queue job already does this on its own schedule, so run it by hand only when you need a year archived immediately.

Without process_email_queue.php nothing is ever delivered. Certificates are issued, notifications are queued, and the queue grows. This is the first thing to check when a buyer reports that email does not work.

cPanel

Add one cron job per line below. Replace the path with your own, and use the PHP binary your host recommends: it is often /usr/local/bin/php rather than php.

*/5 * * * *  /usr/local/bin/php /home/account/public_html/cron/process_email_queue.php
0 * * * *    /usr/local/bin/php /home/account/public_html/cron/cleanup_exports.php
30 3 * * *   /usr/local/bin/php /home/account/public_html/cron/cleanup_certificate_documents.php

Leave the fourth job unscheduled unless you need it. Audit archiving already happens inside the email job on its own interval.

crontab

*/5 * * * * cd /var/www/certiflow && php cron/process_email_queue.php >> storage/logs/cron.log 2>&1
0 * * * *   cd /var/www/certiflow && php cron/cleanup_exports.php >> storage/logs/cron.log 2>&1
30 3 * * *  cd /var/www/certiflow && php cron/cleanup_certificate_documents.php >> storage/logs/cron.log 2>&1

Run them as the same user the web server runs as. A job running as root leaves files the web server cannot then read.

Checking that a job works

Every job prints one line of output, which is what a cron mail or a log file will show.

JobOutput
process_email_queue.phpsent=3 failed=0 deferred=2 throttled=2 audit_archive=recently_checked
cleanup_exports.phpdeleted=2
cleanup_certificate_documents.phppurged=0 skipped=0 cutoff=...

Run one by hand from the control panel first, and read the line it prints. A PHP error instead of that line usually means the wrong PHP binary or the wrong path. The deferred value includes retry backoff and hourly-cap deferrals; throttled counts messages postponed by the saved rolling-hour cap. See send limits before changing provider traffic. The audit_archive value reports the archiving check that rides along with the email job: recently_checked means it ran inside its interval and had nothing to do, completed means a year was archived, disabled means AUDIT_ARCHIVE_ENABLED is off, and locked means another run holds the lock.

If your host allows no scheduled jobs at all, the product still issues and verifies certificates: only email delivery and the two cleanups need the schedule. An external service that requests a URL on a timer is not a substitute, because these are command-line scripts and are deliberately not reachable over the web.