Most production incidents we are called in to fix are not code failures. They are an expired certificate, a full disk, a backup that had been running for six months and had never once been restored, or a server exposed with password authentication.
We install and operate complete Linux environments: nginx at the front, PM2 for Node applications, php-fpm for Laravel, PostgreSQL or MySQL, Redis, Let's Encrypt certificates renewed automatically. Deployment is scripted and zero-downtime, so shipping an update is not a risky event.
A backup does not exist until it has been restored. We set up encrypted off-site backups and we test the restore.