Skip to main content

Auto-detection of Resources

deployless automatically detects Resource instances (DynamoDB, S3, SQS, KMS, SSMParameter) without requiring explicit declaration in dpl.configure(resources={...}).

1. Feature-local resources​

Any Resource created inside a feature's directory (in any .py file, not just routes.py) is auto-detected for that feature's Lambda with "crud" permissions.

app/features/auth/services.py
import deployless as dpl

auth_table = dpl.DynamoDB("auth-table", pk="PK", sk="SK")
# Auto-detected for the auth Lambda — no need to import in routes.py

2. Shared resources (imported from shared/)​

Resources defined in app/shared/ are only injected into features that explicitly import them in routes.py (least privilege).

app/shared/services/dynamo.py
import deployless as dpl

ums_table = dpl.DynamoDB("ums-table", pk="PK", sk="SK")
app/features/auth/routes.py
from app.shared.services.dynamo import ums_table  # import = auto-detect with "crud"

dpl.configure(description="Auth Service")
# ums_table is auto-detected because it was imported
app/features/tenant/routes.py
# Does NOT import ums_table → does NOT get permissions for it
dpl.configure(description="Tenant Service")

Permission overrides​

Use dpl.configure(resources={...}) only when you need to restrict the default "crud" permission:

app/features/auth/routes.py
from app.shared.services.kms_service import kms_key

dpl.configure(
resources={"kms_key": (kms_key, "decrypt")}, # restrict to decrypt only
)

Detection summary​

Resource locationDetectionDefault permissionconfigure(resources=...) needed?
Inside features/X/ (any file)Automatic via sys.modules scancrudOnly to restrict
In shared/, imported in routes.pyAutomatic via namespace scancrudOnly to restrict
External (existing=True)Automatic (same rules)crudOnly to restrict

Deduplication​

If the same resource appears in multiple features, the CloudFormation definition is emitted only once in the template, but each feature gets its own IAM policies and environment variables.