.env File and Secrets
deployless reads a .env file to inject environment variables and manage secrets automatically.
Configuration
deployless.yaml
env_file: .env.production # Path to the .env file
# Optional — KMS key to encrypt secrets in SSM
secrets_kms: my-app/secrets # Alias, key ID, or ARN
.env file format
.env.production
# Normal variables — injected directly as env vars in all Lambdas
APP_ENV=production
LOG_FORMAT=json
# Secrets — SECRET_ prefix indicates they are pushed to SSM Parameter Store
SECRET_DB_PASSWORD=mysecretpassword
SECRET_API_KEY=sk_live_xxxx
Behavior
| Type | Example | Destination | Value in Lambda |
|---|---|---|---|
| Normal | APP_ENV=production | Direct env var | production |
| Secret | SECRET_DB_PASSWORD=xxx | SSM Parameter Store | {{resolve:ssm:/my-app/SECRET_DB_PASSWORD}} |
How SECRET_ variables work
- The name is kept in full with the prefix:
SECRET_DB_PASSWORD→/my-app/SECRET_DB_PASSWORD - The value is stored as
Stringin SSM Parameter Store under/{app_name}/{VAR_NAME} - The Lambda receives a dynamic reference
{{resolve:ssm:...}}that CloudFormation resolves at deploy time - The env var in the Lambda keeps the full name:
SECRET_DB_PASSWORD
note
String (not SecureString) is used because CloudFormation does not support {{resolve:ssm-secure:...}} in Lambda environment variables. The value is still protected by IAM — only roles with ssm:GetParameter permission can read it.
Validations
| Code | Rule |
|---|---|
| E27 | The specified env_file does not exist |
| E28 | SECRET_ variable with empty value |
| E29 | Invalid secrets_kms format (alias can only contain alphanumeric, -, _, /) |