Skip to main content

Laravel Vapor on GitHub: CI/CD Pipelines and Serverless Infrastructure

NR Tech Studio Team
NR Tech Studio Team NR Tech Studio
11 min read

Laravel Vapor GitHub integration connects Laravel Vapor, the dedicated serverless deployment platform for AWS, with GitHub repositories and GitHub Actions to automate cloud infrastructure provisioning, container builds, asset distribution, and zero-downtime serverless deployments directly on AWS Lambda.

Modern engineering teams rely heavily on GitHub as the central hub for code versioning, continuous integration, and declarative cloud infrastructure pipelines. Deploying serverless PHP at scale requires bridging the stateless container execution model of AWS Lambda with the managed deployment primitives provided by Laravel Vapor. When paired with GitHub, teams can transition away from brittle, local deployments executed from developer machines toward deterministic, auditable CI/CD pipelines.

Implementing this workflow involves configuring the Vapor command-line interface inside GitHub Actions runners, securing deployment credentials, orchestrating asset builds, synchronizing database migrations across isolated staging environments, and managing infrastructure state across multi-region AWS environments.

Understanding Laravel Vapor and GitHub Repositories

Laravel Vapor coordinates AWS cloud primitives specifically designed for serverless execution, abstracting API Gateway, AWS Lambda, Simple Queue Service (SQS), Simple Storage Service (S3), and CloudFront CDN routing. Within a standard developer workflow, the vapor-cli binary issues calls to Vapor API endpoints, which synthesize AWS CloudFormation templates and orchestrate cloud resource lifecycles.

Integrating this deployment loop with a GitHub repository moves pipeline management from individual developer laptops into a centralized, deterministic environment. When code merges to main or release branches, GitHub Actions acts as the execution runner, while Vapor acts as the control plane that updates AWS infrastructure.

  • State Decoupling: Infrastructure state and environment variables remain encrypted within Vapor while deployment orchestration remains in GitHub.
  • Immutable Builds: Each commit triggers a repeatable build artifact, eliminating discrepancies caused by local operating system runtimes or varied PHP extensions.
  • Auditability: Every deployment, roll-forward, and rollback traces back to a signed Git commit hash.

Architectural Overview of GitHub Actions and AWS Lambda

To build a resilient deployment architecture, engineers must understand how GitHub Actions interacts with both the Laravel Vapor control plane and the underlying Amazon Web Services infrastructure. The CI/CD worker does not directly configure AWS resources. Instead, it interacts with Vapor API endpoints, which execute the AWS SDK commands under your configured IAM roles.

During a run, the GitHub runner checks out application code, compiles front-end assets, optimizes Composer autoloader maps, and invokes vapor deploy [environment]. Vapor compiles this application bundle into an immutable deployment package, provisions temporary S3 upload URLs, and pushes the package to Amazon S3. AWS Lambda functions update asynchronously across routing groups.

The execution topology requires coordination across multiple distinct components:

Component Hosted On Functional Role in Pipeline
GitHub Actions Runner GitHub Infrastructure Compiles static assets, installs PHP dependencies, executes linting, calls Vapor CLI.
Laravel Vapor Control Plane Managed SaaS Translates high-level vapor.yml into AWS primitives; coordinates rolling deployments.
AWS S3 Application Bucket Amazon Web Services Stores versioned Lambda zip bundles or container images and asset manifests.
AWS CloudFront & S3 Amazon Web Services Serves static assets bypassing serverless PHP workers.
AWS Lambda Runtime Amazon Web Services Executes incoming HTTP requests, queue jobs, and scheduled tasks via custom PHP runtimes.

Essential Repository Setup and the vapor.yml Configuration

The foundation of deploying Laravel to AWS via GitHub is the vapor.yml configuration manifest located at the repository root. This declarative file specifies cloud resource sizing, runtimes, queue workers, database attachments, and domain routing for isolated environments like staging and production.

A production-ready vapor.yml configuration enforces memory boundaries, concurrency reservations, and environment variable references. Below is an example of an infrastructure configuration designed for high-throughput environments:

id: 48921
name: enterprise-app
environments:
 production:
 memory: 1024
 cli-memory: 512
 runtime: 'php-8.3:al2'
 database: enterprise-mysql-cluster
 redis: enterprise-cache-redis
 domain: api.example.com
 build:
 - 'composer install --no-dev --optimize-autoloader'
 - 'php artisan event:cache'
 - 'php artisan route:cache'
 - 'php artisan view:cache'
 deploy:
 - 'php artisan migrate --force'

 staging:
 memory: 512
 cli-memory: 256
 runtime: 'php-8.3:al2'
 database: staging-mysql-instance
 domain: staging-api.example.com
 build:
 - 'composer install --optimize-autoloader'
 deploy:
 - 'php artisan migrate --force'

Keep this manifest version-controlled inside GitHub. When branches branch off or merge, any changes to memory limits or build hooks automatically reconcile upon deployment.

Authenticating GitHub with Laravel Vapor Securely

Running deployments headlessly requires authenticating the CI runner with Laravel Vapor without exposing long-lived credentials to arbitrary code executions. The primary mechanism for authentication is the VAPOR_API_TOKEN.

To generate this token, navigate to the Laravel Vapor dashboard, access your Team or Account settings, and create a deployment API token with permissions scoped to the target application. Once generated, add this secret directly to your GitHub repository or organization secrets:

  • Navigate to Settings > Secrets and variables > Actions in your GitHub repository.
  • Create a new repository secret named VAPOR_API_TOKEN.
  • Ensure branch protection rules are applied to prevent pull requests from fork repositories from accessing sensitive environment secrets.

Never commit raw API keys or AWS credentials to GitHub source files. Vapor handles AWS authentication internally using cross-account IAM roles established during your initial account onboarding.

Constructing an Automated GitHub Actions Deployment Workflow

Constructing a continuous delivery pipeline demands a structured GitHub Actions workflow that executes validation, tests, dependency installation, and infrastructure rollout. The workflow must run within a containerized or virtualized Ubuntu environment equipped with the matching PHP runtime and Node.js toolchains.

Here is an end-to-end GitHub Actions workflow configuration (.github/workflows/deploy.yml) engineered for high reliability and zero downtime:

name: Deploy Application to Laravel Vapor

on:
 push:
 branches:
 - main
 - staging

jobs:
 deploy:
 runs-on: ubuntu-22.04
 concurrency:
 group: vapor-deploy-${{ github.ref }}
 cancel-in-progress: false

 steps:
 - name: Checkout Code
 uses: actions/checkout@v4

 - name: Setup PHP Environment
 uses: shivammathur/setup-php@v2
 with:
 php-version: '8.3'
 extensions: mbstring, bcmath, pdo_mysql, zip, curl
 coverage: none

 - name: Setup Node.js Toolchain
 uses: actions/setup-node@v4
 with:
 node-version: 20
 cache: 'npm'

 - name: Install Composer Dependencies
 run: |
 composer install --no-interaction --prefer-dist --optimize-autoloader --no-dev

 - name: Install NPM Dependencies & Build Assets
 run: |
 npm ci
 npm run build

 - name: Install Laravel Vapor CLI
 run: composer global require laravel/vapor-cli --no-interaction

 - name: Deploy to Staging Environment
 if: github.ref == 'refs/heads/staging'
 run: ~/.composer/vendor/bin/vapor deploy staging --commit="${{ github.sha }}"
 env:
 VAPOR_API_TOKEN: ${{ secrets.VAPOR_API_TOKEN }}

 - name: Deploy to Production Environment
 if: github.ref == 'refs/heads/main'
 run: ~/.composer/vendor/bin/vapor deploy production --commit="${{ github.sha }}"
 env:
 VAPOR_API_TOKEN: ${{ secrets.VAPOR_API_TOKEN }}

Using the --commit flag passes the exact Git commit SHA to Laravel Vapor, ensuring that deployment traces in the management console match your GitHub commit logs perfectly.

Managing Environment Variables and Secrets in GitHub and Vapor

A frequent design challenge in serverless pipelines is managing the division between build-time configuration variables and runtime application secrets. GitHub Actions variables handle build assets, while Vapor encrypts runtime configuration within AWS Parameter Store or AWS Secrets Manager.

Understanding this boundary prevents sensitive tokens from leaking into static frontend assets:

  • Build-Time Secrets: Variables like VITE_API_URL or NPM_TOKEN belong in GitHub Secrets. They are embedded into JavaScript and CSS bundles during the npm run build step inside the runner.
  • Runtime Secrets: Secrets like DB_PASSWORD, STRIPE_SECRET, or application encryption keys belong in Vapor. Inject these via the CLI using vapor secret:set [environment] KEY=VALUE or via the dashboard.
  • Storage Architecture: For workflows handling object persistence at scale, such as managing assets outside the deployment bundle, review architecting S3 storage in Laravel to decouple runtime state from ephemeral compute.

Database Migrations and Isolation in Serverless Pipelines

Executing relational database migrations against cloud databases like AWS Aurora Serverless or RDS MySQL requires careful handling in serverless workflows. Traditional applications run migrations on a single worker node before launching traffic. In serverless systems, migrations must run within isolated, short-lived containers.

Laravel Vapor executes the deploy hooks defined in vapor.yml inside an isolated, temporary AWS Lambda function directly within your Virtual Private Cloud (VPC). This guarantees network connectivity to RDS clusters without exposing database endpoints to the public internet or requiring the GitHub Actions runner to establish a direct VPC connection.

# Inside vapor.yml
deploy:
 - 'php artisan down --render="maintenance" --secret="bypass-token"'
 - 'php artisan migrate --force'
 - 'php artisan config:cache'
 - 'php artisan up'

If your application couples relational tables with document data stores, see our architectural review of Laravel MongoDB integration for strategies on handling schema migration boundaries in mixed storage setups.

Optimizing CI/CD Build Times and Artifact Caching

Serverless applications require compiling both static assets and PHP binaries. Without intelligent caching, build times on GitHub Actions can exceed 10 minutes per commit. This delay increases feedback loops and slows emergency patches.

By leveraging GitHub Actions caching primitives, teams can accelerate build cycles down to under two minutes. Caching Composer packages and npm artifacts prevents redundant network transfers:

- name: Cache Composer Dependencies
 uses: actions/cache@v4
 with:
 path: ~/.composer/cache/files
 key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
 restore-keys: |
 ${{ runner.os }}-composer-

- name: Cache NPM Dependencies
 uses: actions/cache@v4
 with:
 path: ~/.npm
 key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
 restore-keys: |
 ${{ runner.os }}-node-

Asset offloading is handled during deployment: Vapor extracts static files from the build and transfers them directly to an S3 bucket fronted by CloudFront. Lambda zip bundles remain compact and load faster during cold starts.

Preview Deployments with Pull Requests and Vapor

A major advantage of integrating Laravel Vapor with GitHub is the ability to provision ephemeral preview environments for open pull requests. This setup allows engineering teams to validate feature branches against production-grade serverless cloud infrastructure before merging to the main branch.

To support ephemeral preview deployments, create a separate GitHub Actions workflow that responds to pull request lifecycle events:

name: Pull Request Preview Environment

on:
 pull_request:
 types: [opened, synchronize, closed]

jobs:
 preview:
 runs-on: ubuntu-22.04
 steps:
 - name: Checkout Code
 uses: actions/checkout@v4

 - name: Setup PHP
 uses: shivammathur/setup-php@v2
 with:
 php-version: '8.3'

 - name: Teardown Environment on Close
 if: github.event.action == 'closed'
 run: |
 composer global require laravel/vapor-cli
 ~/.composer/vendor/bin/vapor env:delete "pr-${{ github.event.pull_request.number }}" --force
 env:
 VAPOR_API_TOKEN: ${{ secrets.VAPOR_API_TOKEN }}

 - name: Deploy Environment on Open or Sync
 if: github.event.action!= 'closed'
 run: |
 composer install --no-dev --optimize-autoloader
 composer global require laravel/vapor-cli
 ~/.composer/vendor/bin/vapor deploy "pr-${{ github.event.pull_request.number }}"
 env:
 VAPOR_API_TOKEN: ${{ secrets.VAPOR_API_TOKEN }}

Using pull-request-scoped naming conventions (pr-123) lets teams run automated end-to-end browser tests in an isolated AWS environment, reducing regression risks before production integration.

Monitoring, Rollbacks, and Failure Recovery

Even thoroughly tested pipelines can fail due to upstream cloud API limits, database deadlocks, or syntax issues. A comprehensive GitHub workflow should include automated notifications and rollback commands.

Vapor maintains an immutable log of prior deployments. When a health check fails or errors spike post-deployment, engineers can execute a fast rollback to the previous version using the CLI: vapor rollback [environment].

For deep visibility into serverless Lambda metrics, memory saturation, cold starts, and queue backpressure, consult our guide to Laravel application monitoring and observability. Connecting GitHub commit webhooks to your monitoring platform lets teams correlate latency anomalies directly with new releases.

Security Hardening and Least Privilege IAM Policies

Securing the pipeline between GitHub and Laravel Vapor requires adhering strictly to the principle of least privilege across identity providers, access keys, and cloud permissions. Compromised CI environments are a primary vector for supply chain attacks.

Enforce these operational safeguards within your GitHub repository settings:

  • Branch Protections: Require pull request reviews, linear Git histories, and passing status checks on your main branch before code can merge.
  • Restrict Deployment Environments: Use GitHub’s Environments feature to restrict which branches can access the production VAPOR_API_TOKEN. Set manual approval requirements for deployments to production.
  • Rotate Access Tokens: Rotate Vapor API tokens periodically, and immediately revoke credentials assigned to departed engineers.
  • Avoid Root Cloud Credentials: Never add AWS root access keys or broad administrator access keys to GitHub Secrets. Rely solely on Vapor cross-account IAM delegations.

Common Troubleshooting Patterns in Vapor GitHub Deployments

When deploying via headless GitHub runners, engineers frequently encounter edge cases that do not occur on local development machines. Understanding these common scenarios simplifies log analysis and speeds up troubleshooting.

Address these common failure modes directly:

  1. Vapor CLI Memory Limit: If Composer runs out of memory during CLI installation on GitHub, add COMPOSER_MEMORY_LIMIT=-1 to the runner step environment variables.
  2. Asset Manifest Mismatches: Ensure that the public/build or public/mix-manifest.json artifact is generated before running vapor deploy. If assets compile after the deploy command runs, Lambda serves stale HTML references to missing CloudFront resources.
  3. Database Subnet Timeout: If deployment hooks hang on migrations, verify in the AWS console that your Lambda execution subnets have active NAT Gateways or VPC Endpoints configured for S3 and Parameter Store.

Explore the Fundamentals

Building resilient, automated serverless architectures requires mastering core application patterns alongside infrastructure delivery pipelines. Explore the complete foundational documentation to deepen your understanding of framework internals and infrastructure design.

[Explore our complete Laravel, Basics directory for more guides.](/topics/topics-laravel-basics/)

Integrating Laravel Vapor with GitHub through automated CI/CD pipelines moves serverless engineering away from fragile local deployments toward deterministic cloud infrastructure operations. By using declarative vapor.yml manifests, containerized GitHub runners, and least-privilege deployment credentials, engineering teams can safely deploy to AWS Lambda while maintaining high deployment velocity.

Adopting automated artifact caching, pull request preview environments, and decoupled configuration boundaries delivers the full operational benefits of serverless PHP: elastic scalability, minimal server maintenance overhead, and reproducible software lifecycles across all cloud environments.

References & Further Reading