Skip to main content

AWS Resources

Resources are auto-detected by the compiler. Any Resource instance (DynamoDB, S3, SQS, KMS, SSMParameter) is automatically registered with "crud" permissions — deployless adds them to template.yaml, auto-generates IAM policies, and injects environment variables.

Detection rules​

Resource locationDetectionWhat you need to do
Inside features/auth/ (any .py file)AutomaticNothing — detected by scanning the feature directory
In app/shared/Only if importedYou must import the resource in your routes.py for the Lambda to get permissions
app/shared/resources.py
import deployless as dpl
shared_table = dpl.DynamoDB("shared-table", pk="id")
app/features/auth/routes.py
from app.shared.resources import shared_table  # ← triggers auto-detection
# Without this import, the auth Lambda will NOT have permissions for shared_table

Deduplication​

If the same resource appears in multiple features, the CloudFormation definition is emitted only once in the template, but each feature gets its own IAM policies and environment variables.

Permission overrides​

Use dpl.configure(resources={...}) only when you need to restrict the default "crud" permission:

dpl.configure(
resources={"kms_key": (kms_key, "decrypt")}, # restrict from crud to decrypt only
)

Detection summary​

Resource locationDetectionDefault permissionconfigure(resources=...) needed?
Inside features/X/ (any file)Automatic via sys.modules scancrudOnly to restrict permissions
In shared/, imported in routes.pyAutomatic via namespace scancrudOnly to restrict permissions
External (existing=True)Automatic (same rules)crudOnly to restrict permissions

Available resource types​

  • DynamoDB — tables with GSI, TTL, streams, and provisioned capacity
  • KMS — encryption keys with symmetric, asymmetric, and HMAC support
  • SSM Parameter Store — create parameters or reference existing ones