Nitro

Going further

Building for production

In development, Nitro compiles a component on the first request after you change it. For production, run nitro:build to compile everything ahead of time, minify it and publish it, so the web server can send it without PHP.

On this page

To build your components for production, run:

Terminal
php artisan nitro:build

What a build does

  1. Compiles

    The build compiles every component, page and store, and minifies them with esbuild. It shows each step and how long it took, and -v lists the components. Chunks that haven't changed come from a cache.

  2. Publishes

    The build publishes the files to public/nitro. @nitroScripts links to them through asset(), so ASSET_URL and a CDN work as usual. Each file name contains a version, so browsers can cache the files for a year (Cache-Control: public, max-age=31536000, immutable).

  3. Obfuscates

    When nitro.build.obfuscate is on (the default), methods, properties, pages and components go by aliases derived from APP_KEY. The aliases are used in the bundle, in the page and in what the browser sends, and the server translates them back. Your PHP, views and tests keep using the real names.

The build is generated, so keep it out of git:

.gitignore
/public/nitro

Deploying

php artisan optimize doesn't build Nitro, so run nitro:build as a separate step when you deploy. If you change a component after a build, the /_nitro routes serve the current code until the next build. A tab still running the old bundle reloads once to pick up the new one.

Terminal
composer install --no-dev --optimize-autoloader
php artisan optimize
php artisan nitro:build

To remove the compiled files, run php artisan nitro:clear.

Writing names out in full

Nitro can only alias names that are written out in full. Write property and key names out, rather than building them from variables:

Blade
{{-- Aliased, because the name is written out in full. --}}
@if ($errors->has('form.email')) ... @endif

{{-- Not aliased, because the name is built from a variable. --}}
@if ($errors->has('form.'.$field)) ... @endif

Keys inside array properties, #[Url] query keys, mounted(), destroyed() and updated() always keep their names.

The bundle is public

The compiled files contain views and browser methods, never data. State, shared data and flash data travel with each response instead. Like any application's JavaScript, anyone can read the bundle, so keep secrets out of views and browser methods. Obfuscation shortens names, but it doesn't protect anything.

Next steps