Skip to main content

SSM Parameter Store

deployless provides two tools for SSM: dpl.SSMParameter to create a parameter as a CloudFormation resource, and dpl.SSMParam to reference an existing parameter as a dynamic reference in env vars.

dpl.SSMParameter — create a parameter​

dpl.SSMParameter(
name: str, # Parameter path, must start with "/"
value: str, # Parameter value
type: str = "String", # "String" | "StringList" | "SecureString"
description: str = None,
existing: bool = False, # True = do not create, only inject env var
)

Auto-generated environment variable​

Last segment of the path:

nameEnvironment variable
/myapp/db/hostHOST
/myapp/api/secret-keySECRET_KEY

Compile-time validations (E00)​

  • name must start with /
  • Alphanumeric only, ., -, _, /
  • type must be String, StringList, or SecureString
  • value cannot be empty (except for SecureString)

Example​

db_host = dpl.SSMParameter(
"/myapp/db/host",
value="db.example.com",
description="RDS endpoint",
)

# Auto-detected — SSMParameterReadPolicy is auto-generated
dpl.configure(description="My Service")
# → Variable: HOST = {"Ref": "MyappDbHostParameter"}

dpl.SSMParam — reference an existing parameter​

Does not generate a CloudFormation resource. Produces a dynamic reference directly in the env var value.

dpl.SSMParam(
name: str, # Path of the existing parameter
secure: bool = False, # True → "{{resolve:ssm-secure:/path}}" (SecureString)
version: int = None, # Optional — pin to a specific version
)

Usage in env vars​

dpl.configure(
env={
"DB_HOST": dpl.SSMParam("/prod/db/host"),
"API_KEY": dpl.SSMParam("/prod/api/key", secure=True),
"DB_PASS": dpl.SSMParam("/prod/db/password", secure=True, version=3),
}
)

This generates in the template:

Environment:
Variables:
DB_HOST: "{{resolve:ssm:/prod/db/host}}"
API_KEY: "{{resolve:ssm-secure:/prod/api/key}}"
DB_PASS: "{{resolve:ssm-secure:/prod/db/password:3}}"
note

{{resolve:ssm-secure:...}} only works with SecureString parameters and requires the Lambda to have ssm:GetParameter + kms:Decrypt permission on the parameter's KMS key.

Permission levels (SSMParameter only)​

LevelAuto-generated policy
"crud" / "read" (default)SSMParameterReadPolicy
"write"Inline ssm:PutParameter
dpl.configure(
resources={
"counter": (dpl.SSMParameter("/app/counter", value="0"), "write"),
},
)