Skip to content

Documentation: AWS projects and missing install steps in the Laravel guides - #2187

Merged
mnapoli merged 5 commits into
masterfrom
aws-projects
Sep 26, 2026
Merged

mnapoli merged 5 commits into
masterfrom
aws-projects

Conversation

@mnapoli

@mnapoli mnapoli commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

I redid the onboarding from scratch: a brand new AWS account, a fresh laravel new app with the recommended setup (queue, S3 storage, website assets), following the docs.

AWS projects

AWS now offers two ways to sign up. With "Sign up for AWS (new)", users log in with Google/GitHub/Apple/Amazon and AWS creates a "project": an AWS account in an organization managed by AWS, with AWS-managed guardrails (policies). Tested on such an account:

  • Bref Cloud cannot connect: a resource control policy that customers cannot edit (DenyAnyoneOutsideMyOrgAndAWS) denies sts:* to principals outside the project's organization, so Bref Cloud cannot assume its role. The only way out on the AWS side is to "activate advanced features", which cannot be undone.
  • One region per project, chosen by AWS based on the country (e.g. eu-north-1 in Europe). Deploying the examples of the docs (us-east-1) fails with ... with an explicit deny in a service control policy, which says nothing about the region.
  • Credentials come from aws login, in a named profile: without AWS_PROFILE, serverless deploy fails with AWS provider credentials not found. With it, osls reads these credentials fine.

With the right region and profile, everything else worked (HTTP, CloudFront + assets, S3 private and public files, SQS worker, bref:cli).

The docs now recommend against projects, for Bref Cloud and Serverless CLI users alike, in a new "AWS projects" section of the setup page (the Bref Cloud UI will link to /docs/setup#aws-projects). The main argument is not Bref Cloud: projects don't fit how companies run production on AWS (their own AWS Organization and policies, per-team permissions, cross-account integrations for monitoring/security/deployment tools, OIDC for CI/CD, any region), and AWS's own comparison says the same. For those who already have a project, the section explains what to change to deploy with the Serverless CLI, with the error messages so that the docs search finds them.

Laravel guides

Unrelated to AWS, two install steps were missing and broke the recommended setup:

  • The published serverless.yml enabled serverless-lift, but the getting started never installed it: the very first deploy failed. Comment out the Lift plugin in the serverless.yml stub laravel-bridge#212 comments the plugin out (like the constructs), and the guides that use constructs (queues, file storage, website assets) now tell to uncomment it. They also used serverless plugin install, which does not exist for Bref Cloud users (they don't install osls globally), so they now use npm install --save-dev serverless-lift.
  • Laravel's s3 disk requires league/flysystem-aws-s3-v3, which was never mentioned: any Storage:: call failed with Class "League\Flysystem\AwsS3V3\PortableVisibilityConverter" not found, including in queued jobs.

Also documented: QUEUE_FAILED_DRIVER: 'null' for applications without a database (otherwise storing a failed job fails too), and the Free plan closing AWS accounts after 6 months unless upgraded.

To release together with brefphp/laravel-bridge#212: with the current stub (plugin enabled), the getting started no longer installs Lift.

…guides

AWS accounts created with "Sign up for AWS (new)" are AWS projects: Bref Cloud cannot connect to them, they are limited to one region, and their credentials come from `aws login`.

The Laravel guides also missed two install steps: the Serverless Lift plugin (enabled in the published serverless.yml) and the Flysystem S3 adapter required by Laravel's s3 disk.
Explain why projects do not fit production applications (AWS-managed policies, no fine-grained permissions, no cross-account integrations, no OIDC for CI/CD, one region, spend limit stopping the application), instead of presenting them as an option that only Bref Cloud cannot use.
…less.yml

brefphp/laravel-bridge#212 comments out the plugin in the published serverless.yml, so the getting started no longer needs Lift. The guides that use constructs tell to uncomment it.
The docs recommend against AWS projects, the setup page covers what to change for those who use one anyway.
@mnapoli
mnapoli merged commit adf8abb into master Sep 26, 2026
8 checks passed
@mnapoli
mnapoli deleted the aws-projects branch September 26, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant