Skip to main content

deployless.yaml Reference

Create this file at the project root (same level as requirements.txt). All fields are optional; default values are indicated.

# Project name
name: my-app

# Cloud provider — only "aws" is supported
provider: aws

# Deployment stage. Can be overridden with --stage in the CLI.
# Used for: API Gateway StageName, APP_STAGE env var in all Lambdas,
# and samconfig.toml stack prefix.
stage: dev

# Tags applied to all CloudFormation resources
tags:
Project: my-app
Environment: production

# Paths to the key directories of the project
paths:
features: app/features # Directory where features live
shared: app/shared # Shared code (copied into each Lambda)

# Global config for all Lambda functions
globals:
runtime: python3.13 # Lambda runtime
memory: 256 # MB (128–10240)
timeout: 30 # Seconds (1–900)
log_retention: 14 # Retention in CloudWatch (days)
# Valid: 1,3,5,7,14,30,60,90,120,
# 150,180,365,400,545,731,1096,1827,3653

# API Gateway configuration
api:
endpoint_type: REGIONAL # REGIONAL | EDGE | PRIVATE

# CORS — fallback when create_app() is not found in app/__init__.py.
# When create_app() exists, CORS is inherited automatically from it.
cors:
allow_origin: "*" # Or a list: ["https://my-app.com"]
allow_methods: [GET, POST, PUT, DELETE, OPTIONS]
allow_headers: [Content-Type, Authorization, X-API-Key]
max_age: 3600

# MIME types that API Gateway treats as binary (non-UTF-8)
binary_media_types:
- image/png
- image/jpeg
- application/octet-stream

# Compress responses larger than N bytes
minimum_compression_size: 1024

# Global environment variables injected into ALL functions
env:
APP_ENV: production
LOG_LEVEL: INFO

# .env file — environment variables and secrets
# Normal variables are injected as env vars in all Lambdas.
# Variables with the SECRET_ prefix are pushed to SSM Parameter Store.
env_file: .env.production

# KMS key to encrypt secrets in SSM (optional).
# Accepts alias ("my-app/secrets") or key ID / ARN.
secrets_kms: my-app/secrets

# Flask app initialization hooks (fallback only).
# Used when create_app() is not found in app/__init__.py.
# Each entry is a dotted "module.function" path.
init_app:
- app.shared.errors.register_error_handlers
- app.shared.middleware.register_middleware

API Gateway endpoint types​

TypeDescription
REGIONALStandard regional endpoint (default)
EDGECloudFront-optimized edge endpoint
PRIVATEAccessible only from within a VPC

CORS behavior​

When create_app() is present in app/__init__.py, CORS is inherited from your app factory. The cors: config in deployless.yaml is only used as a fallback when the app factory is unavailable.

The generated bootstrap injects CORS headers via @after_request with a guard — it only sets headers if Access-Control-Allow-Origin is not already present, so it coexists safely with flask-cors.