deployless.yaml Reference
Create this file at the project root (same level as requirements.txt). All fields are optional; default values are indicated.
# Project name
name: my-app
# Cloud provider — only "aws" is supported
provider: aws
# Deployment stage. Can be overridden with --stage in the CLI.
# Used for: API Gateway StageName, APP_STAGE env var in all Lambdas,
# and samconfig.toml stack prefix.
stage: dev
# Tags applied to all CloudFormation resources
tags:
Project: my-app
Environment: production
# Paths to the key directories of the project
paths:
features: app/features # Directory where features live
shared: app/shared # Shared code (copied into each Lambda)
# Global config for all Lambda functions
globals:
runtime: python3.13 # Lambda runtime
memory: 256 # MB (128–10240)
timeout: 30 # Seconds (1–900)
log_retention: 14 # Retention in CloudWatch (days)
# Valid: 1,3,5,7,14,30,60,90,120,
# 150,180,365,400,545,731,1096,1827,3653
# API Gateway configuration
api:
endpoint_type: REGIONAL # REGIONAL | EDGE | PRIVATE
# CORS — fallback when create_app() is not found in app/__init__.py.
# When create_app() exists, CORS is inherited automatically from it.
cors:
allow_origin: "*" # Or a list: ["https://my-app.com"]
allow_methods: [GET, POST, PUT, DELETE, OPTIONS]
allow_headers: [Content-Type, Authorization, X-API-Key]
max_age: 3600
# MIME types that API Gateway treats as binary (non-UTF-8)
binary_media_types:
- image/png
- image/jpeg
- application/octet-stream
# Compress responses larger than N bytes
minimum_compression_size: 1024
# Global environment variables injected into ALL functions
env:
APP_ENV: production
LOG_LEVEL: INFO
# .env file — environment variables and secrets
# Normal variables are injected as env vars in all Lambdas.
# Variables with the SECRET_ prefix are pushed to SSM Parameter Store.
env_file: .env.production
# KMS key to encrypt secrets in SSM (optional).
# Accepts alias ("my-app/secrets") or key ID / ARN.
secrets_kms: my-app/secrets
# Flask app initialization hooks (fallback only).
# Used when create_app() is not found in app/__init__.py.
# Each entry is a dotted "module.function" path.
init_app:
- app.shared.errors.register_error_handlers
- app.shared.middleware.register_middleware
API Gateway endpoint types
| Type | Description |
|---|---|
REGIONAL | Standard regional endpoint (default) |
EDGE | CloudFront-optimized edge endpoint |
PRIVATE | Accessible only from within a VPC |
CORS behavior
When create_app() is present in app/__init__.py, CORS is inherited from your app factory. The cors: config in deployless.yaml is only used as a fallback when the app factory is unavailable.
The generated bootstrap injects CORS headers via @after_request with a guard — it only sets headers if Access-Control-Allow-Origin is not already present, so it coexists safely with flask-cors.