Environment Variables
There are multiple ways to configure environment variables:
- an environment file from your project, copied into the containers as their
.env; - individual variables set in
sst.config.ts; - SST secrets linked to the service;
RemoteEnvVault, which stores the file in AWS Secrets Manager.
On top of these, SST Laravel adds variables for linked resources and a few Laravel settings.
Which one to use
- An environment file is the simplest and costs nothing, but only a machine that has the file can deploy. It suits one person, or trying SST Laravel out.
RemoteEnvVaultkeeps the file in your AWS account (about $0.40/month per stage), so teammates and CI deploy with the same values without passing a file around. It suits teams, CI, and production.- SST secrets keep the most sensitive values out of any file. SST Laravel writes them into the
.envthat the environment file orRemoteEnvVaultprovides, so use them with one of the two. - Variables in the config are committed with the code, so use them only for values that aren't secret.
Environment file
If you want SST Laravel to copy an environment file, configure the config.environment.file entry. The configuration below copies a file named .env.$STAGE (e.g. .env.production) into the deployment containers as your .env file.
const app = new LaravelService('MyLaravelApp', {
// ...
config: {
environment: {
file: `.env.${$app.stage}`,
}
}
});
You can also configure it to use simply .env.
const app = new LaravelService('MyLaravelApp', {
// ...
config: {
environment: {
file: `.env`,
}
}
});
Keep the file out of Git, and don't put AWS access keys in it. See Troubleshooting.
Variables in the config
To set individual variables in sst.config.ts, use config.environment.vars:
const app = new LaravelService('MyLaravelApp', {
// ...
config: {
environment: {
vars: {
SESSION_DRIVER: 'redis',
QUEUE_CONNECTION: 'redis',
}
}
}
});
SST secrets
You can also use SST Secrets to store your environment variables. This is a more secure way to store your environment variables.
const APP_KEY = new sst.Secret("APP_KEY");
const DB_PASSWORD = new sst.Secret("DB_PASSWORD");
const app = new LaravelService('MyLaravelApp', {
link: [APP_KEY, DB_PASSWORD],
});
This will automatically inject the environment variables into the .env file of your Laravel application. Read more about SST Secrets.
AWS Secrets Manager (RemoteEnvVault)
For a more robust environment variable management solution similar to Laravel Vapor, you can use the RemoteEnvVault component. This stores your environment variables in AWS Secrets Manager and provides CLI commands to push and pull secrets.
const { RemoteEnvVault, LaravelService } = await import("@kirschbaum-development/sst-laravel");
const env = new RemoteEnvVault("Env");
const app = new LaravelService('MyLaravelApp', {
// ...
config: {
environment: {
secrets: env,
}
}
});
The secrets are stored in AWS Secrets Manager at the path /{app-name}/{stage}/env. You can also use a custom path:
const env = new RemoteEnvVault("Env", {
path: `/custom/${$app.stage}/env`
});
env:push and env:pull read the path from sst.config.ts, filling in $app.name and $app.stage. When the path is built some other way, pass it with --path.
Pushing secrets
To push your local .env file to AWS Secrets Manager:
# Push .env.production to the production stage
npx sst-laravel env:push --stage production --input .env.production
# Push .env to staging (interactive)
npx sst-laravel env:push --stage staging
Pulling secrets
To pull secrets from AWS Secrets Manager to a local file:
# Pull from production to .env.production (default)
npx sst-laravel env:pull --stage production
# Pull from staging to a custom file
npx sst-laravel env:pull --stage staging --output .env.local
Deploying with secrets
When using RemoteEnvVault, deploy using the sst-laravel deploy command, which automatically fetches secrets before building:
npx sst-laravel deploy --stage production
Workflow example
# 1. Initial setup - push your environment file
npx sst-laravel env:push --stage production --input .env.production
# 2. Deploy (secrets are automatically fetched)
npx sst-laravel deploy --stage production
# 3. Update secrets later
npx sst-laravel env:pull --stage production # Creates .env.production
# Edit .env.production
npx sst-laravel env:push --stage production --input .env.production
npx sst-laravel deploy --stage production
Large environment files
Large environment files that exceed AWS Secrets Manager's 64KB limit are automatically handled. The CLI will:
- Split large
.envfiles into multiple chunks when pushing - Automatically merge all chunks when pulling or deploying
This is completely transparent. You don't need to do anything special.
Variables SST Laravel adds
SST Laravel fills in some variables for you, with both environment files and RemoteEnvVault:
- Linked resources. Linking a database, Redis, or a bucket injects its
DB_*,REDIS_*, orAWS_*variables. See Linking Resources. LOG_CHANNEL. To send logs to AWS CloudWatch,LOG_CHANNELmust bestderr. If your environment doesn't set it, SST Laravel addsLOG_CHANNEL=stderr.APP_URL. If your environment doesn't set it, SST Laravel adds it with the value of theweb.domainproperty.- Reverb. With
reverb.domainset, SST Laravel adds theREVERB_*variables. See Reverb.
SST Laravel adds them after your variables. Laravel reads the last value of a variable, so the values of linked resources win over the same variables in your environment, such as DB_CONNECTION=sqlite copied from .env.example. LOG_CHANNEL and APP_URL are only added when your environment doesn't set them.
To stop SST Laravel from injecting variables for linked resources, set config.environment.autoInject to false. See Disabling the auto-inject of environment variables.