SSM Parameter Store
deployless provides two tools for SSM: dpl.SSMParameter to create a parameter as a CloudFormation resource, and dpl.SSMParam to reference an existing parameter as a dynamic reference in env vars.
dpl.SSMParameter — create a parameter
dpl.SSMParameter(
name: str, # Parameter path, must start with "/"
value: str, # Parameter value
type: str = "String", # "String" | "StringList" | "SecureString"
description: str = None,
existing: bool = False, # True = do not create, only inject env var
)
Auto-generated environment variable
Last segment of the path:
name | Environment variable |
|---|---|
/myapp/db/host | HOST |
/myapp/api/secret-key | SECRET_KEY |
Compile-time validations (E00)
namemust start with/- Alphanumeric only,
.,-,_,/ typemust beString,StringList, orSecureStringvaluecannot be empty (except forSecureString)
Example
db_host = dpl.SSMParameter(
"/myapp/db/host",
value="db.example.com",
description="RDS endpoint",
)
# Auto-detected — SSMParameterReadPolicy is auto-generated
dpl.configure(description="My Service")
# → Variable: HOST = {"Ref": "MyappDbHostParameter"}
dpl.SSMParam — reference an existing parameter
Does not generate a CloudFormation resource. Produces a dynamic reference directly in the env var value.
dpl.SSMParam(
name: str, # Path of the existing parameter
secure: bool = False, # True → "{{resolve:ssm-secure:/path}}" (SecureString)
version: int = None, # Optional — pin to a specific version
)
Usage in env vars
dpl.configure(
env={
"DB_HOST": dpl.SSMParam("/prod/db/host"),
"API_KEY": dpl.SSMParam("/prod/api/key", secure=True),
"DB_PASS": dpl.SSMParam("/prod/db/password", secure=True, version=3),
}
)
This generates in the template:
Environment:
Variables:
DB_HOST: "{{resolve:ssm:/prod/db/host}}"
API_KEY: "{{resolve:ssm-secure:/prod/api/key}}"
DB_PASS: "{{resolve:ssm-secure:/prod/db/password:3}}"
note
{{resolve:ssm-secure:...}} only works with SecureString parameters and requires the Lambda to have ssm:GetParameter + kms:Decrypt permission on the parameter's KMS key.
Permission levels (SSMParameter only)
| Level | Auto-generated policy |
|---|---|
"crud" / "read" (default) | SSMParameterReadPolicy |
"write" | Inline ssm:PutParameter |
dpl.configure(
resources={
"counter": (dpl.SSMParameter("/app/counter", value="0"), "write"),
},
)