AWS Resources
Resources are auto-detected by the compiler. Any Resource instance (DynamoDB, S3, SQS, KMS, SSMParameter) is automatically registered with "crud" permissions — deployless adds them to template.yaml, auto-generates IAM policies, and injects environment variables.
Detection rules
| Resource location | Detection | What you need to do |
|---|---|---|
Inside features/auth/ (any .py file) | Automatic | Nothing — detected by scanning the feature directory |
In app/shared/ | Only if imported | You must import the resource in your routes.py for the Lambda to get permissions |
app/shared/resources.py
import deployless as dpl
shared_table = dpl.DynamoDB("shared-table", pk="id")
app/features/auth/routes.py
from app.shared.resources import shared_table # ← triggers auto-detection
# Without this import, the auth Lambda will NOT have permissions for shared_table
Deduplication
If the same resource appears in multiple features, the CloudFormation definition is emitted only once in the template, but each feature gets its own IAM policies and environment variables.
Permission overrides
Use dpl.configure(resources={...}) only when you need to restrict the default "crud" permission:
dpl.configure(
resources={"kms_key": (kms_key, "decrypt")}, # restrict from crud to decrypt only
)
Detection summary
| Resource location | Detection | Default permission | configure(resources=...) needed? |
|---|---|---|---|
Inside features/X/ (any file) | Automatic via sys.modules scan | crud | Only to restrict permissions |
In shared/, imported in routes.py | Automatic via namespace scan | crud | Only to restrict permissions |
External (existing=True) | Automatic (same rules) | crud | Only to restrict permissions |
Available resource types
- DynamoDB — tables with GSI, TTL, streams, and provisioned capacity
- KMS — encryption keys with symmetric, asymmetric, and HMAC support
- SSM Parameter Store — create parameters or reference existing ones