Skip to main content

.env File and Secrets

deployless reads a .env file to inject environment variables and manage secrets automatically.

Configuration​

deployless.yaml
env_file: .env.production       # Path to the .env file

# Optional — KMS key to encrypt secrets in SSM
secrets_kms: my-app/secrets # Alias, key ID, or ARN

.env file format​

.env.production
# Normal variables — injected directly as env vars in all Lambdas
APP_ENV=production
LOG_FORMAT=json

# Secrets — SECRET_ prefix indicates they are pushed to SSM Parameter Store
SECRET_DB_PASSWORD=mysecretpassword
SECRET_API_KEY=sk_live_xxxx

Behavior​

TypeExampleDestinationValue in Lambda
NormalAPP_ENV=productionDirect env varproduction
SecretSECRET_DB_PASSWORD=xxxSSM Parameter Store{{resolve:ssm:/my-app/SECRET_DB_PASSWORD}}

How SECRET_ variables work​

  1. The name is kept in full with the prefix: SECRET_DB_PASSWORD → /my-app/SECRET_DB_PASSWORD
  2. The value is stored as String in SSM Parameter Store under /{app_name}/{VAR_NAME}
  3. The Lambda receives a dynamic reference {{resolve:ssm:...}} that CloudFormation resolves at deploy time
  4. The env var in the Lambda keeps the full name: SECRET_DB_PASSWORD
note

String (not SecureString) is used because CloudFormation does not support {{resolve:ssm-secure:...}} in Lambda environment variables. The value is still protected by IAM — only roles with ssm:GetParameter permission can read it.

Validations​

CodeRule
E27The specified env_file does not exist
E28SECRET_ variable with empty value
E29Invalid secrets_kms format (alias can only contain alphanumeric, -, _, /)