NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #994 most downloaded on PyPI
AWS SAM Translator is a library that transform SAM templates into AWS CloudFormation templates
Last release 24 days ago
24 Aug 2026
Ships fairly regularly
a new release about every 6 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
121 releases · first in 2018
Release 1.54.0 (to develop) by @aws-sam-cli-bot in https://github.com/aws/serverless-application-model/pull/2587
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.54.0...v1.55.0
chore: fix custom domain integration tests for feature toggle by @hnnasit in https://github.com/aws/serverless-application-model/pull/2517
DependsOn to connector by its generated logical IDs by @hoffa in https://github.com/aws/serverless-application-model/pull/2537sam sync instead of sam deploy by @hoffa in https://github.com/aws/serverless-application-model/pull/2569Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.53.0...v1.54.0
One column per quarter.
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.52.0...v1.53.0
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.52.0...v1.53.0
fix: Update Slack Invite link by @jfuss in https://github.com/aws/serverless-application-model/pull/2490
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.51.0...v1.52.0
chore: Add missing import and add partition into base test for integration test by @qingchm in https://github.com/aws/serverless-application-model/pul
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.50.0...v1.51.0
chore: Skip self managed kafka tests by @qingchm in https://github.com/aws/serverless-application-model/pull/2461
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.49.0...v1.50.0
Fix EventSource Schedule passes Enabled to State by @lightpriest in https://github.com/aws/serverless-application-model/pull/1666
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.48.0...v1.49.0
chore: [Foss] Sync public: Update region service exclusion list by @mingkun2020 in https://github.com/aws/serverless-application-model/pull/2427
FailOnWarnings property on AWS::Serverless::Api by @nialdaly in https://github.com/aws/serverless-application-model/pull/2417Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.47.0...v1.48.0
test: Add logging for relevant Amazon headers useful for debugging by @mildaniel in https://github.com/aws/serverless-application-model/pull/2390
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.46.0...v1.47.0
Validation for API property Model by @jonife in https://github.com/aws/serverless-application-model/pull/2340
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.45.0...v1.46.0
Feat FURL by @jonife @valerena in https://github.com/aws/serverless-application-model/pull/2370
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.44.0...v1.45.0
Feat /tmp config by @slowpokesnail in https://github.com/aws/serverless-application-model/pull/2362
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.43.0...v1.44.0
Fix no allowed origin by @c2tarun in https://github.com/aws/serverless-application-model/pull/2180
Full Changelog: https://github.com/aws/serverless-application-model/compare/v1.42.0...v1.43.0
feat: adding OwnershipVerificationCertificateArn and DisableExecuteApiEndpoint to APIs.
Self Managed Kafka as event source support
feat: Add ValidateBody/ValidateParameters attribute to API models
feat: Percentage-based Enablement for Feature Toggle
fix: Increase PageSize of ListPolicies Paginator
Optimize shared API usage plan handling
@theBaffo for https://github.com/aws/serverless-application-model/commit/d08d77bba296ff852ba146513ff83c37c79d1d12 @chrisoverzero for https://github.co
@theBaffo for https://github.com/aws/serverless-application-model/commit/d08d77bba296ff852ba146513ff83c37c79d1d12 @chrisoverzero for https://github.com/aws/serverless-application-model/commit/9ac8282793a1fc58d309747692b87ae57fc396ff @forzagreen for https://github.com/aws/serverless-application-model/commit/848c39c7de959a48ac41594c68420255e115e31b
@ejafarli for https://github.com/aws/serverless-application-model/commit/16fa8522d596a153965d6801943249276b8d974b @vinayaksood for https://github.com/
@ejafarli for https://github.com/aws/serverless-application-model/commit/16fa8522d596a153965d6801943249276b8d974b @vinayaksood for https://github.com/aws/serverless-application-model/commit/a34ae261b3371ec0fb7448f545185852cc9e7d5b
SAM Translator now supports TumblingWindowInSeconds property in event source mappings.
SAM Translator now supports TumblingWindowInSeconds property in event source mappings.
SAM now supports Lambda Container Images
SAM now supports Lambda Container Images
Lambda Code Signing support have been added by supporting for CodeSigningConfigArn property for AWS::Serverless::Function resource.
Lambda Code Signing support have been added by supporting for CodeSigningConfigArn property for AWS::Serverless::Function resource.
For more information please check Configuring code signing for AWS SAM applications.
@javulticat for https://github.com/aws/serverless-application-model/commit/863964567a59e4f2042fe9fbffb1890633b55f81
@javulticat for https://github.com/aws/serverless-application-model/commit/863964567a59e4f2042fe9fbffb1890633b55f81
Changing boto version to boto3~=1.5
@wong-a & Vaib Suri for https://github.com/aws/serverless-application-model/commit/4590f327fce98fff5d5677c3000f1003b8665cd7 @gruebel for https://githu
@wong-a & Vaib Suri for https://github.com/aws/serverless-application-model/commit/4590f327fce98fff5d5677c3000f1003b8665cd7 @gruebel for https://github.com/aws/serverless-application-model/commit/b34a39a03324a08fb7a304f6b2a6cb27dfaf26cc
Several bug-fixes including XRay issue with CN and GOV regions have been fixed.
Adding supporting for using AmazonMQ as as event source in AWS::Serverless::Function resource
@kaidih : Contributes on 1769
Adding supporting for using AmazonMQ as as event source in AWS::Serverless::Function resource
Domain configuration of AWS::Serverless::Api and AWS::Serverless::HttpApi now support MTLS configuration. Also AWS::Serverless::HttpApi has new property DisableExecuteApiEndpoint.
@Tolledo : Contributes on #1733
@Tolledo : Contributes on #1733
On Sept 9th, API Gateway launched support for customers to secure Amazon API Gateway HTTP APIs using Lambda authorizers. SAM v1.28 adds support for Lambda Authorizers to the AWS Serverless Application Model.
Adding the Tracing property to the Step Functions State Machine resource to pass X-Ray tracing configuration to the TracingConfiguration property for
@patrickgreenwell
Adding the Tracing property to the Step Functions State Machine resource to pass X-Ray tracing configuration to the TracingConfiguration property for State Machine CloudFormation resource.
Add support for dynamic references in property "ResourcePolicyStatement". New properties are added to pass in dynamic references: IntrinsicVpcBlacklist/IntrinsicVpceBlacklist/IntrinsicVpcWhitelist/IntrinsicVpceWhitelist Example:
ResourcePolicy:
IntrinsicVpcBlacklist:
# Note: The dynamic reference should be defined before usage.
- '{{resolve:ssm:SomeVPCReference:1}}'
Issue #809 is fixed. Allow passing in reference objects to CompatibleRuntimes.
Add support for MSK (Managed Streaming Kafka) as event source for AWS SAM Serverless Functions.
@scbrown
AWS::Serverless::FunctionAdd support for MSK (Managed Streaming Kafka) as event source for AWS SAM Serverless Functions.
AWS SAM now supports VPCEndpointIds in EndpointConfiguration as a pass-through parameter to Cloud Formation configuration.
AWS SAM now supports adding FileSystemConfigs to your AWS::Serverless::Function resources, so that you can integrate your AWS Lambda functions with Am
AWS SAM now supports adding FileSystemConfigs to your AWS::Serverless::Function resources, so that you can integrate your AWS Lambda functions with Amazon Elastic File System.
Customers can now use AWS Lambda to build data-intensive applications, load larger libraries and models, process larger amounts of data in a highly distributed manner, and share data across functions, containers and instances. AWS Lambda will automatically mount the file system and provide a local path to read and write data at low latency.
AWS SAM now supports AWS Step Functions, enabling you to integrate workflow orchestration into your serverless applications quickly and easily. Throug
AWS SAM now supports AWS Step Functions, enabling you to integrate workflow orchestration into your serverless applications quickly and easily. Through direct support in the AWS Serverless Application Model AWS SAM, an open-source framework for building serverless applications, you can now deliver your serverless applications faster by defining your Step Functions state machine workflows alongside your application architecture and code.
AWS Step Functions allows you to build resilient serverless workflows and set up state machines using AWS services such as AWS Lambda, Amazon SNS, Amazon DynamoDB, and more—all supported by AWS SAM. Now with Step Functions support in AWS SAM, you can define state machines in a SAM template or in a separate file, create state machine execution roles through SAM policy templates, inline policies, or managed policies, and easily trigger state machine executions with API Gateway, EventBridge events, or on a schedule within a SAM template.
Using AWS SAM, your state machine definitions can be stored locally or packaged and stored in S3, and your state machine execution roles can easily be created through SAM policy templates, inline policies, or managed policies which can be directly defined within your state machine resource. To get started with Step Functions using AWS SAM, install the SAM CLI and then run the ‘sam init’ command.
## SAM v1.23 Release: Bug fixes ### Change Log: 2. #1537 fix: ref for autopublish code sha
@cakepietoast, @dalumiller, @jmnarloch, @nmoutschen, @tyldavis
@cakepietoast, @dalumiller, @jmnarloch, @nmoutschen, @tyldavis
SAM supports adding tags to AWS::Serverless::HttpApi. When a stack is created, SAM will automatically add httpapi:createdBy: SAM tag. SAM also propagates tags from AWS::Serverless::HttpApi to AWS::ApiGatewayV2::DomainName and AWS::ApiGatewayV2::Stage resources. For more information on how to define tags, see the AWS CloudFormation Documentation. (#1459) (#1492)
Api:
Type: AWS::Serverless::HttpApi
Properties:
Tags:
Tag1: value1
Tag2: value2
SAM supports PayloadFormatVersion and TimeoutInMillis for Http API events. SAM defaults to "2.0" for PayloadFormatVersion if the version is not specified. The default value of TimeoutInMillis is 5000 milli seconds for Http APIs. For more information on these properties see AWS CloudFormation documentation. (#1450) #1517
HttpApiFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: ./
Handler: index.handler
Runtime: nodejs12.x
Events:
Basic:
Type: HttpApi
Properties:
Path: /basic
Method: post
TimeoutInMillis: 10000
PayloadFormatVersion: "2.0"
SAM supports FailOnWarnings for AWS::Serverless::HttpApi resource. Specifies whether to rollback the API creation (true) or not (false) when a warning is encountered. For more information on FailOnWarnings see AWS CloudFormation Documentation (#1509)
MyApi:
Type: AWS::Serverless::HttpApi
Properties:
FailOnWarnings: True
SAM supports enabling CORS for Http APIs. SAM adds x-amazon-apigateway-cors header in open api definition for your Http API when CorsConfiguration property is defined. Specify true for adding Cors with domain '*' to your Http APIs or specify a dictionary with additional CorsConfiguration object. For more information see AWS CloudFormation documentation. (#1381)
MyApi:
Type: AWS::Serverless::HttpApi
Properties:
CorsConfiguration:
AllowOrigins:
- "https://example.com"
AllowHeaders:
- x-apigateway-header
AllowMethods:
- GET
This release adds support for configuring custom domains on AWS::Serverless::HttpApi. For more information about this feature see AWS CloudFormation documentation. (#1472)
MyApi:
Type: AWS::Serverless::HttpApi
Properties:
Domain:
DomainName: !Ref DomainName
CertificateArn: !Ref ACMCertificateArn
BasePath:
- /fetch
Route53:
HostedZoneId: ZQ1UAL4EFZVME
IpV6: true
SAM supports DefaulRouteSettings and RouteSettings for Http API. For more information see AWS CloudFormation documentation. (#1461) (#1490)
RouteSettings example snippet:
Resources:
HttpApiFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: s3://sam-demo-bucket/todo_list.zip
Handler: index.restapi
Runtime: nodejs12.x
Events:
SimpleCase:
Type: HttpApi
Properties:
ApiId: !Ref MyApi
RouteSettings:
ThrottlingBurstLimit: 300
LoggingLevel: INFO
MyApi:
Type: AWS::Serverless::HttpApi
Properties:
StageName: Prod
RouteSettings:
"$default":
ThrottlingBurstLimit: 200
ThrottlingRateLimit: 0.7
DefaultRouteSettings example snippet:
MyApi:
Type: AWS::Serverless::HttpApi
Properties:
DefinitionUri: s3://bucket/key
StageName: !Join ["", ["Stage", "Name"]]
DefaultRouteSettings:
ThrottlingBurstLimit: 50
@aketcham0691, @allanchua101 , @brettstack, @doug-skinner, @jmnarloch, @mark-hirayama, @mbarneyjr, @nikp, @patrickgreenwell, @timoschilling, @tom139
@aketcham0691, @allanchua101 , @brettstack, @doug-skinner, @jmnarloch, @mark-hirayama, @mbarneyjr, @nikp, @patrickgreenwell, @timoschilling, @tom139
SAM now supports configuring Usage Plans on AWS::Serverless::Api resources! For more information on how to configure and use usage plans, see the AWS SAM Documentation.
Api:
Type: AWS::Serverless::Api
Properties:
Auth:
UsagePlan:
CreateUsagePlan: PER_API
Description: My test usage plan
Quota:
Limit: 500
Period: MONTH
Throttle:
BurstLimit: 100
RateLimit: 50
This release supports a new way of forcing updates to Lambda Versions: AutoPublishCodeSha256.
This property addresses a problem that occurs when an AWS SAM template has the following characteristics: the DeploymentPreference object is configured for gradual deployments (as described in Deploying Serverless Applications Gradually), the AutoPublishAlias property is set and doesn't change between deployments, and the CodeUri property is set and doesn't change between deployments.
This scenario might occur when the deployment package stored in an Amazon S3 location is replaced by a new deployment package that contains updated Lambda function code, but the CodeUri property remains unchanged (as opposed to the new deployment package being uploaded to a new Amazon S3 location and the CodeUri being changed to the new location). An example of this is if code was always uploaded to the same s3://bucket/code.zip S3 location.
In this scenario, you must provide a unique value for AutoPublishCodeSha256 to trigger the gradual deployment successfully.
Patch fix to correct PyPi upload
Patch fix to correct PyPi upload
#1393
@53ningen, @alexfrosa, @brettstack, @cakepietoast, @chrisoverzero, @dballance, @ebaizel, @eddiecho, @eugeniosu, @gliptak, @hui-yang, @klmz, @koenaad,
@53ningen, @alexfrosa, @brettstack, @cakepietoast, @chrisoverzero, @dballance, @ebaizel, @eddiecho, @eugeniosu, @gliptak, @hui-yang, @klmz, @koenaad, @kvasukib, @limitusus, @MattMasters, @me2resh, @merzwilliam, @michaeljfazio, @nheijmans, @nikp, @pfeilbr, @tde908, @timoschilling, @yan12125, @zmaleki
This release adds support for configuring custom domains on AWS::Serverless::Api. For more information about this feature see CloudFormation documentation. (#1144) (#1165)
Resources:
MyApi:
Type: AWS::Serverless::Api
Properties:
OpenApiVersion: 3.0.1
StageName: Prod
Domain:
DomainName: !Ref DomainName
CertificateArn: !Ref ACMCertificateArn
EndpointConfiguration: EDGE
BasePath:
- /fetch
Route53:
HostedZoneId: ZQ1UAL4EFZVME
IpV6: true
DistributionDomainName: !GetAtt Distribution.DomainName
DeploymentPreferenceThis release adds support for adding Trigger Configurations on DeploymentPreference of a serverless function. For more information on Trigger Configurations see CloudFormation documentation. A big thank you to @cakepietoast for contributing this feature! (#1195)
Resources:
MinimalFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: .
Handler: hello.handler
Runtime: python3.7
AutoPublishAlias: live
DeploymentPreference:
Enabled: true
Type: Linear10PercentEvery1Minute
TriggerConfigurations:
- TriggerEvents:
- DeploymentSuccess
- DeploymentFailure
TriggerName: TestTrigger
TriggerTargetArn: !Ref MySNSTopic
This release supports AuthorizationScopes for Authorizers in AWS::Serverless::Api. The scopes are used with a COGNITO_USER_POOLS authorizer to authorize the method invocation. For more information on scopes see AWS blog post. A big thank you to @klmz for contributing this feature! (#917)
Resources:
MyFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: .
Handler: index.handler
Runtime: python3.7
Events:
CognitoDefaultScopesWithOverwritten:
Type: Api
Properties:
RestApiId: !Ref MyApiWithCognitoAuth
Method: get
Path: /hello
Auth:
Authorizer: MyDefaultCognitoAuth
AuthorizationScopes:
- read
- write
SqsSubscription property of the SNS event type now supports adding an existing SQS queue. When this property is set, uses an existing SQS queue or creates a SQS queue and subscribes to the SNS topic, and the Lambda function is subscribed to the SQS queue. For more information about SNS and SQS, see the developer documentation. A big thank you to @53ningen for contributing this feature! (#1231)
Resources:
MyLambdaFunction:
Type: AWS::Serverless::Function
Properties:
Handler: index.handler
Runtime: nodejs10.x
CodeUri: .
MemorySize: 128
Events:
SQSSubscriptionEvent:
Type: SNS
Properties:
Topic: !Ref MySnsTopic
SqsSubscription:
QueueUrl: !Ref MyQueue
QueueArn: !GetAtt MyQueue.Arn
QueuePolicyLogicalId: NotificationA
BatchSize: 8
Enabled: true
FilterPolicy:
store:
- example_corp
price_usd:
- numeric:
- ">="
- 100
This release adds support to propogate Serverless function tags to IAM roles generated for the function. You can configure tags on IAM Role by updating the Tags property of Serverless function. A big thank you to @cakepietoast for contributing this feature! (#1194)
Resources:
MyFunctionWithTags:
Type: AWS::Serverless::Function
Properties:
CodeUri: .
Handler: index.handler
Runtime: nodejs10.x
Tags:
TagKey1: TagValue1
cloudwatch:describeAlarmHistory policy, (#1259) Allow kinesis:DescribeStreamSummary for KinesisCrudPolicy and KinesisStreamReadPolicy, (#1137) Add AthenaQueryPolicy template, (#1192) Add KMSEncryptPolicy policy templatesourcearnThis is a patch release to fix the implementation of HTTP API authorizers. Authorizers are now correctly nested under components.securitySchemes in th
This is a patch release to fix the implementation of HTTP API authorizers. Authorizers are now correctly nested under components.securitySchemes in the OpenApi document that SAM generates. #1301
HTTP APIs enable you to create RESTful APIs with lower latency and lower cost than REST APIs. In SAM, we aim to make creating and configuring these AP
HTTP APIs enable you to create RESTful APIs with lower latency and lower cost than REST APIs. In SAM, we aim to make creating and configuring these APIs easier and safer by providing the ability to construct an authenticated API backed by Lambda functions. We did this by creating a new resource type, AWS::Serverless::HttpApi, and a new Function event type to go with it, HttpApi.
To learn more about the differences and benefits of using a HTTP API, see the Amazon API Gateway documentation.
We followed the same pattern that we had for our current AWS::Serverless::Api resource, with a few notable changes.
We are making it even easier to configure a Lambda-backed API. We are introducing a new simple case, where one Lambda function can map to all endpoints of an API and is simple and easy to use. This is done via several improvements:
Always Deploy API There is now an option to automatically deploy any changes made to an API. SAM will no longer have to try to hash any changes to the API in an effort to deploy for any change; it should instead always work.
Default Stage
There is a new $default stage that is used if no StageName is given. This stage maps to the base of the API url.
Default Path
There is a new $default path option that SAM uses if no Method and Path are given in an HttpApi event. All unmapped paths and methods will be routed to this endpoint.
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description: AWS SAM template with a simple API definition backed by a single Lambda function.
Resources:
ApiFunction:
Type: AWS::Serverless::Function
Properties:
Events:
ApiEvent: # uses new default path
Type: HttpApi
Handler: index.handler
CodeUri: ./src
Runtime: python3.7
AWS::Serverless::HttpApi at launch only supports JWT authorizers, and these can be added and used in much the same way that authorizers work on the AWS::Serverless::Api resource.
For more information about authorization on AWS::Serverless::HttpApi resources, see the SAM Documentation.
SAM will now attempt to merge Lambda integrations with existing OpenApi documents. This allows advanced users to bring a pre-existing OpenApi document with all paths and methods specified and let SAM add the API Gateway integrations for Serverless functions via HttpApi events on these functions. If the template author defines their own OpenApi, SAM requires the openapi version to be set and at least an empty paths dictionary to be created.
This release adds support to configure the number of concurrent executions to be reserved for the lambda function on AWS::Lambda::Alias resource. Sett
This release adds support to configure the number of concurrent executions to be reserved for the lambda function on AWS::Lambda::Alias resource. Setting the AutoPublishAlas property is required to use this feature on an AWS::Serverless::Function.
Resources:
MinimalFunction:
Type: 'AWS::Serverless::Function'
Properties:
CodeUri: ./src/
Handler: index.handler
Runtime: nodejs8.10
AutoPublishAlias: live
ProvisionedConcurrencyConfig:
ProvisionedConcurrentExecutions: 10
This release adds support for specifying an EventBusName for the CloudWatchEvent function event type. For more information about this property see the
@zbintliff
This release adds support for specifying an EventBusName for the CloudWatchEvent function event type. For more information about this property see the CloudFormation documentation. Thank you @zbintliff for contributing this feature. (#1185)
Resources:
TriggeredFunction:
Type: 'AWS::Serverless::Function'
Properties:
CodeUri: .
Handler: index.handler
Runtime: python3.7
Events:
OnTerminate:
Type: CloudWatchEvent
Properties:
EventBusName: ExternalEventBridge
Pattern:
detail:
state:
- terminated
This release adds support for ParallelizationFactor, MaximumRetryAttempts, BisectBatchOnFunctionError, MaximumRecordAgeInSeconds, and DestinationConfi
This release adds support for ParallelizationFactor, MaximumRetryAttempts, BisectBatchOnFunctionError, MaximumRecordAgeInSeconds, and DestinationConfig properties for Kinesis and DynamoDB event types.
ParallelizationFactor property can be set to increase concurrent Lambda invocations for each shard, which by default is 1. This allows for faster stream processing without the need to over-scale the number of shards, while still guaranteeing order of records processed.
Lambda functions can skip retrying a batch of records when it has reached the value set in the MaximumRetryAttempts property, which can be configured from 0 to 10,000.
Lambda functions can skip processing a data record when it has reached the value set in MaximumRecordAgeInSeconds property, which can be configured from 60 seconds to 7 days.
Lambda functions can continue processing a shard even when it returns an error. When a data record reaches the Maximum Retry Attempts or Maximum Record Age, you can send its metadata like shard ID and stream ARN to an SQS queue or SNS topic by setting that configuration in DestinationConfig
BisectBatchOnFunctionError allows a customer to have retried invocations contain a smaller number of records. With Bisect on Function Error enabled, Lambda splits the impacted batch of records into two when a function returns an error, and retries them separately. This allows you to easily separate the malformed data record from the rest of the batch, and process the rest of data records successfully.
Resources:
StreamProcessor:
Type: AWS::Serverless::Function
Properties:
Handler: index.handler
Runtime: nodejs10.x
CodeUri: .
Events:
Stream:
Type: Kinesis
Properties:
Stream: !GetAtt Stream.Arn
ParallelizationFactor: 8
MaximumRetryAttempts: 100
BisectBatchOnFunctionError: true
MaximumRecordAgeInSeconds: 604800
DestinationConfig:
OnFailure:
Destination: !GetAtt MySqsQueue.Arn
This patch release fixes two bugs introduced in Release 1.15.0 -
This patch release fixes two bugs introduced in Release 1.15.0 -
ResourcePolicy created incorrect resource paths, this was fixed in #1181CustomStatements property of ResourcePolicy, which resulted in multiple copies of custom statements being created. This caused some users to run into policy size limits. It was fixed in #1183@53ningen, @adanilev, @ArendAMZN, @beck3905, @chrisoverzero, @dalumiller, @Jacco, @kennyk, @khamaileon, @MattTunny, @sambattalio, @singledigit, @TDagl
@53ningen, @adanilev, @ArendAMZN, @beck3905, @chrisoverzero, @dalumiller, @Jacco, @kennyk, @khamaileon, @MattTunny, @sambattalio, @singledigit, @TDaglis, @tim-pugh, @yuimam
SAM 1.14.0 release added support for adding Amazon API Gateway resource policies, allowing you to specify custom resource policy statements. This release adds a simplified syntax for creating API Gateway resource policies for the common use cases of whitelisting and blacklisting based on AWS Account, IP address range, and source VPC. For more information about Amazon API Gateway resource policies, see the Amazon API Gateway developer guide. (#1077)
Globals:
Api:
OpenApiVersion: "3.0.1"
Auth:
ResourcePolicy:
AwsAccountWhitelist: ['account-id']
AwsAccountBlacklist: ['account-id']
SourceVpcWhitelist: ['vpc-1234']
SourceVpcBlacklist: ['vpce-1234']
IpRangeWhitelist: ['1.2.3.4/24']
IpRangeBlacklist: ['1.2.3.4']
Resources:
MyLambdaFunction:
Type: AWS::Serverless::Function
Properties:
Handler: index.handler
Runtime: nodejs8.10
CodeUri: .
MemorySize: 128
Events:
Api:
Type: Api
Properties:
Path: /apione
Method: any
This release adds support for Cognito as a Lambda function event type. This allows you to easily add Lambda functions for customizing Cognito user pool workflows. For more information on Cognito user pool workflows with Lambda triggers, see the Cognito developer guide. A big thank you to @Jacco for contributing this feature! (#1066)
Resources:
PreSignupLambdaFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: .
Handler: index.handler
MemorySize: 128
Runtime: nodejs8.10
Events:
CognitoUserPoolPreSignup:
Type: Cognito
Properties:
UserPool: !Ref MyUserPool
Trigger: PreSignUp
MyUserPool:
Type: AWS::Cognito::UserPool
The SNS event type now supports a SqsSubscription property. When set to true, rather than connecting the Lambda function directly to the provided SNS topic, an SQS queue is created and subscribed to the SNS topic, and the Lambda function is subscribed to the SQS queue. This feature eliminates the CloudFormation boilerplate required to setup this common pattern. For more information about SNS and SQS, see the developer documentation. A big thank you to @53ningen for contributing this feature! (#1065)
Resources:
MyLambdaFunction:
Type: AWS::Serverless::Function
Properties:
Handler: index.handler
Runtime: nodejs8.10
CodeUri: .
MemorySize: 128
Events:
SNSEvent:
Type: SNS
Properties:
Topic:
Ref: MySnsTopic
SqsSubscription: true
MySnsTopic:
Type: AWS::SNS::Topic
MaximumBatchingWindowInSeconds support for stream event sourcesThis feature adds support for MaximumBatchingWindowInSeconds property for Kinesis and DynamoDb event types. For more information about this property, see the AWS CloudFormation user guide. (#1120)
Resources:
MyFunction:
Type: 'AWS::Serverless::Function'
Properties:
CodeUri: .
Handler: index.handler
Runtime: nodejs8.10
AutoPublishAlias: Live
Events:
KinesisStream:
Type: Kinesis
Properties:
Stream:
Fn::GetAtt: [MyStream, Arn]
BatchSize: 100
MaximumBatchingWindowInSeconds: 20
StartingPosition: TRIM_HORIZON
MyStream:
Type: AWS::Kinesis::Stream
Properties:
ShardCount: 1
This feature allows you to specify API request parameter customizations directly on AWS::Serverless::Function Api events. Previously, you had to manage your own OpenApi document in order to use this feature of Amazon API Gateway. For more information on Request Parameters, see the Amazon API Gateway developer documentation. A big thank you to @beck3905 for contributing this feature! (#953)
Globals:
Api:
CacheClusterEnabled: true
CacheClusterSize: '0.5'
Resources:
MyLambdaFunction:
Type: AWS::Serverless::Function
Properties:
Handler: index.handler
Runtime: nodejs8.10
CodeUri: .
Events:
PostApi:
Type: Api
Properties:
Path: /post
Method: POST
RequestParameters:
- method.request.header.Authorization:
Required: true
Caching: true
- method.request.querystring.type
Before this change, SAM was generating 2 Lambda permissions per Api event. Now, SAM will generate a single Lambda permission per Api event. This change reduces the number of permissions created for Api events by half, reducing the chances of users hitting Lambda policy size limits. (#1119)
S3FullAccess PolicyRequestParameters Support@53ningen, @cfbarbero, @easydonny, @eduardovra, @falnyr, @Gaurav2Github, @kdnakt, @lo1tuma, @parimaldeshmukh, @sambattalio, @yan12125
@53ningen, @cfbarbero, @easydonny, @eduardovra, @falnyr, @Gaurav2Github, @kdnakt, @lo1tuma, @parimaldeshmukh, @sambattalio, @yan12125
This is the first step in supporting ApiGateway API Keys and Usage Plans in SAM. You can now require API Keys on API endpoints by specifying ApiKeyRequired: true in the Auth property of a Serverless::Api or in a Serverless::Function event configuration. In upcoming releases we will provide support for usage plans. For more information about setting up and using API Keys, see the developer documentation. A big thank you to @cfbarbero for contributing this feature! (#943)
Resources:
MyApi:
Type: AWS::Serverless::Api
Properties:
StageName: Prod
Auth:
ApiKeyRequired: true # sets for all resource methods
MyFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: .
Handler: index.handler
Runtime: nodejs8.10
Events:
ApiKey:
Type: Api
Properties:
RestApiId: !Ref MyApi
Path: /
Method: get
Auth:
ApiKeyRequired: true # sets for single resource method
This is the first of two proposed changes to add support for ApiGateway resource policies; the second change will come in a future release. This change adds support for the CustomStatements field of the ResourcePolicy field inside the Auth property of a Serverless::Api. This property allows template authors to set one or multiple resource policies that will be added to the ApiGateway RestApi. Resource policies are also necessary for using PRIVATE API Gateway APIs. For more information about creating and using resource policies for APIs, see this blog post. (#1045)
Globals:
Api:
Auth:
ResourcePolicy:
CustomStatements:
- Effect: "Allow"
Principal: "*"
Action: "execute-api:Invoke"
Resource: "execute-api:*/*/*"
Resources:
MyFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: .
Handler: index.handler
Runtime: nodejs8.10
Events:
Api:
Type: Api
Properties:
Method: put
Path: /
Enabled, Name, Description fields to CloudWatch Schedule EventsName and Type exist as properties of PrimaryKey for Serverless::SimpleTableApplicationId property of Location on Serverless::Application is not nullThis patch release fixes a bug where the API GW would not redeploy if you added OpenApiVersion in certain cases. The fix takes into account the OpenAp
This patch release fixes a bug where the API GW would not redeploy if you added OpenApiVersion in certain cases. The fix takes into account the OpenApiVersion flag when calculating the hash to determine if the API has changed and needs to be redeployed.
Changelog (#1056)(#1061) Redeploy api if OpenApiVersion changes.
This patch release fixes a bug with Binary Media Types introduced in 1.13.0 and reported in issue #1036. SAM wasn't converting the encoding of the Bin
This patch release fixes a bug with Binary Media Types introduced in 1.13.0 and reported in issue #1036. SAM wasn't converting the encoding of the Binary Media Types from *~1* to */* before adding them to the swagger document, which resulted in the corruption of some APIs that use Binary Media Types in SAM. This was fixed in #1043
(#1043) Fix Binary Media Types regression
We have now added support for OpenApi 3.0 in SAM. This is an opt-in feature that can be enabled by using the OpenApiVersion property for an AWS::Serve
We have now added support for OpenApi 3.0 in SAM. This is an opt-in feature that can be enabled by using the OpenApiVersion property for an AWS::Serverless::Api. This property is supported at both the resource and global levels of the template.
Globals:
Api:
OpenApiVersion: '3.0.1'
Resources:
ImplicitApiFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: s3://sam-demo-bucket/member_portal.zip
Handler: index.gethtml
Runtime: nodejs8.10
Events:
GetHtml:
Type: Api
Properties:
Path: /
Method: get
If you opt into this flag, SAM also fixes the issue where a stage named "stage" was created by default. #191
This feature adds support for listing Models in the Api resource and defining a model to be used in the Api event source. Previously, the only way to do this was to manually write the swagger file. This now makes it much simpler to define the models, and special callout to community member @beck3905 for adding this feature.
Resources:
MyApi:
Type: AWS::Serverless::Api
Properties:
StageName: prod
Models:
User:
type: object
required:
- grant_type
- username
- password
properties:
grant_type:
type: string
username:
type: string
password:
type: string
MyLambdaFunction:
Type: AWS::Serverless::Function
Properties:
Handler: index.handler
Runtime: nodejs6.10
CodeUri: src/
Events:
GetApi:
Type: Api
Properties:
Path: /post
Method: POST
RestApiId:
Ref: MyApi
RequestModel:
Model: User
Required: true
Previously in SAM, you could configure CodeDeploy to enable gradual code deployments for your AWS Lambda functions. Now, you can reference existing cu
Previously in SAM, you could configure CodeDeploy to enable gradual code deployments for your AWS Lambda functions. Now, you can reference existing custom CodeDeploy configurations in the DeploymentPreference property of an AWS::Serverless::Function. Thank you @Buffer0x7cd for contributing this feature! (#848)
To learn more about implementing gradual Lambda deployments using CodeDeploy, see this blog post. To learn more about how to create a custom Lambda CodeDeploy configuration, see the AWS Documentation.
# Example using a custom CodeDeploy configuration
Resources:
MyFunction:
Type: 'AWS::Serverless::Function'
Properties:
CodeUri: s3://sam-demo-bucket/demo.zip
Handler: index.handler
Runtime: python3.6
AutoPublishAlias: live
DeploymentPreference:
Type: MyCustomDeploymentConfiguration # Name of CodeDeploy configuration
(#904) Add StepFunctionsExecutionPolicy (#908 #913) Bug fixes by @jadhavmanoj (#918 #966) Additional bug fixes (#888) Run cfn-lint on test outputs (#605 #883 #886 #887) Example app updates (#899 #902 #905 #909 #919) Documentation updates
AWS SAM previously let you control who can access your Amazon API Gateway APIs with an Amazon Cognito user pool or an API Gateway Lambda Authorizer. N
AWS SAM previously let you control who can access your Amazon API Gateway APIs with an Amazon Cognito user pool or an API Gateway Lambda Authorizer. Now, you can control access to an API defined in SAM with IAM Permissions. To learn more, see controlling access to APIs using IAM permissions and an example application that uses this feature. Shout out to @horike37 for this contribution! (#827)
With this release, you can also define Gateway Responses in your AWS::Serverless::API resources. Amazon API Gateway lets you customize the content of error responses, and you can now define these in SAM. To learn more, see Set up Gateway Responses to Customize Error Responses and an example application that uses this feature. Shout out to @chrisoverzero for this contribution! (#841)
This release also adds support for using FindInMap to specify the ApplicationId and SemanticVersion properties of a Serverless::Application. To learn more, see the docs for FindInMap and Nested Applications. (#856)
# Example application using !FindInMap
ApplicationFindInMap:
Type: 'AWS::Serverless::Application'
Properties:
Location:
ApplicationId: !FindInMap
- ApplicationLocations
- !Ref 'AWS::Region'
- ApplicationId
SemanticVersion: !FindInMap
- ApplicationLocations
- !Ref 'AWS::Region'
- Version
(#808) Add ReservedConcurrentExecutions to globals
(#858) Fix ElasticsearchHttpPostPolicy resource reference
(#855) Support using AWS::Region in Ref and Sub
(#831 #814 #879) Documentation and examples updates
(#835) Add VersionDescription property to Serverless::Function
(#847) Update ServerlessRepoReadWriteAccessPolicy
(#873 #860 #846 #845) Add additional template validation
You can now define conditions on AWS::Serverless resources. Conditions are statements that let you define the circumstances under which resources get
You can now define conditions on AWS::Serverless resources. Conditions are statements that let you define the circumstances under which resources get created or configured. With this release, you can conditionally create AWS::Serverless resources. For example, if you deploy your serverless application to multiple environments such as test and prod, you can choose to only deploy specific AWS::Serverless::Functions to your test environment. Conditions on AWS::Serverless resources are also applied to other generated resources (#755), and the swagger definitions generated by SAM on AWS::Serverless::Api resources (#804). Shout out to @Jacco for contributing to this feature! (#653 #707)
(#620 #686) Add GSIs to DynamoDBReadPolicy and DynamoDBCrudPolicy (#615) Add DynamoDBReconfigurePolicy (#426) Add CostExplorerReadOnlyPolicy and OrganizationsListAccountsPolicy (#556) Add EKSDescribePolicy (#715) Add SESBulkTemplatedCrudPolicy (#729) Add FilterLogEventsPolicy (#625) Add SSMParameterReadPolicy (#723) Add SESEmailTemplateCrudPolicy (#769) Add s3:PutObjectAcl to S3CrudPolicy
(#464) Add allow_credentials CORS option (#643) Add support for AccessLogSetting and CanarySetting Serverless::Api properties (#657) Add support for X-Ray in Serverless::Api (#786) Add support for MinimumCompressionSize in Serverless::Api (#682) Add Auth to Serverless::Api globals (#763) Remove trailing slashes from APIGW permissions (#648) Add SNS FilterPolicy and an example application (#690) Add Enabled property to Serverless::Function event sources (#782) Add support for PermissionsBoundary in Serverless::Function (#697) Fix boto3 client initialization (#700) Add PublicAccessBlockConfiguration property to S3 bucket resource (#705) Make PAY_PER_REQUEST default mode for Serverless::SimpleTable (#709) Add limited support for resolving intrinsics in Serverless::LayerVersion (#720) SAM now uses Flake8 (#737) Add example application for S3 Events written in Go (#604 #632 #644 #741) Updated several example applications
Nothing published for this version
You can now assemble and deploy new serverless architectures using nested applications supported by AWS SAM and the AWS Serverless Application Reposit
You can now assemble and deploy new serverless architectures using nested applications supported by AWS SAM and the AWS Serverless Application Repository.
Nested applications enable you to rapidly build highly sophisticated serverless architectures by reusing and composing authored and maintained services using SAM and the Serverless Application Repository. You can deploy serverless architectures as a set of serverless applications and easily share those architectures privately across teams and organizations or publicly with developers in the open-source community. Using nested applications, you can build more powerful applications, easily manage serverless artifacts, avoid duplicated work, and help ensure consistency and best practices across your teams and organizations.
The new AWS::Serverless::Application transforms into a AWS::CloudFormation::Stack (also known as a nested stack) resource by resolving the Location property to an S3 template URL. SAM users can either provide direct links to a nested template or provide an ApplicationId and SemanticVersion pair from the Serverless Application Repository and SAM will retrieve the template and all its resources for you. This allows developers re-use common application building blocks as well as share and consume them via the Serverless Application Repository.
Learn more in the SAM developer documentation or in the AWS::Serverless::Application specification. We have also included a sample application that uses this feature.
Lambda functions in a serverless application typically share common dependencies such as SDKs, frameworks, and runtimes. Lambda Layers are a new type of artifact that can contain arbitrary code and data, and may be referenced by multiple functions at the same time. With layers, you can centrally manage common components across multiple functions enabling better code reuse. You can now use AWS SAM and AWS SAM CLI to locally test, deploy and manage serverless applications that leverage Layers. An AWS::Serverless::LayerVersion transforms into an AWS::Lambda::LayerVersion.
Since an AWS::Lambda::LayerVersion resource is immutable, CloudFormation currently automatically creates a new version and deletes the old version of the Lambda Layer after each update. By default, SAM prevents CloudFormation from deleting old versions by appending a 10-digit SHA (based on all resource parameters) to the logical id of the LayerVersion resource and adding a DeletionPolicy: Retain attribute. This means that any update to the Lambda Layer will result in the creation of a new version, and the old version will still be available for use.
Learn more about Lambda Layers in the Lambda Layers documentation, and in the SAM developer documentation.
#670 Added AWS WorkMail hello world lambda function example #639 Added link to the new AWS SAM Developer documentation There were also a few documentation fixes and updates.
To get started, check out the specification updates for using the new Authorizer (Auth) parameter within an AWS::Serverless::Api resource or within an
#546 You can use AWS SAM to easily control who can access your API Gateway APIs with an Amazon Cognito user pool or an API Gateway Lambda Authorizer. An authorizer can be a Lambda authorizer, which is a Lambda function that you provide to control access to your API methods, or it can be an Amazon Cognito user pool, which is a user directory in Amazon Cognito. In SAM, you can define these authorizers as a property of an API, or as a new resource which can be used across multiple APIs.
To get started, check out the specification updates for using the new Authorizer (Auth) parameter within an AWS::Serverless::Api resource or within an API event for an AWS::Serverless::Function. See more examples of how to use Cognito authorizers, Lambda request authorizers, and Lambda token authorizers.
#511 Add dynamodb:DescribeTable to DynamoDBCrudPolicy #589 Added RekognitionFacesManagementPolicy
Help shape future SAM development! Add your opinions on proposed features and try tackling good first issues. Join the #samdev Slack channel where a growing community of Serverless developers hangs out.
This release also contains many documentation updates and fixes. We would like to give a shoutout and a thank you to all of the contributors that have
#541 You can now define explicit AWS::Serverless::API resources without needing to specify a DefinitionBody or DefinitionUri. If you do not specify one of these properties, SAM will generate Swagger for you based on the configuration of your SAM template. This means you can now configure things such as StageName, Cors, and soon Auth without having to manually define the Swagger of your API.
#453 Added s3:DeleteObject to S3CrudPolicy #539 Added AWSSecretsManagerGetSecretValuePolicy #548 Fixed resource scoping in CodePipelineLambdaExecutionPolicy #571 Added RekognitionDetectOnlyPolicy
#508 Allow string values in the DependsOn property of S3 buckets (previously only accepted a list of strings) #574 Expose skill ID for event source validation with Alexa skills #554 #560 Fixed the sample apps to properly use Policy Templates and re-published these examples to the Serverless Application Repository #484 Removed JSON schema validation warning
This release also contains many documentation updates and fixes. We would like to give a shoutout and a thank you to all of the contributors that have helped us with examples, documentation, and giving us feedback about how we can further improve the SAM experience!
As always, we welcome your feedback and ideas of what we can do with SAM as well as your contributions! Join us and a growing community of Serverless developers on our #samdev Slack Channel and continue to engage with SAM through submitting and helping out on issues and pull requests. Check out our Development Guide for more information about how to get started!
NOTE: Although v1.7.0 has since been released, we're posting these release notes retroactively for awareness of v1.6.1 features.
NOTE: Although v1.7.0 has since been released, we're posting these release notes retroactively for awareness of v1.6.1 features.
#451 You can now define an SQS Queue as an event source in your SAM template, and trigger lambda functions by sending messages to an Amazon SQS queue. Check out more information in the documentation as well as in an example application that uses this new feature.
#447 You can now (optionally) write your lambda function code inside of your SAM yaml template. An example of this is included below:
AWSTemplateFormatVersion: '2010-09-09'
Transform: 'AWS::Serverless-2016-10-31'
Description: A hello world lambda function with inline code.
Resources:
helloworld:
Type: 'AWS::Serverless::Function'
Properties:
Handler: index.handler
Runtime: nodejs8.10
MemorySize: 128
Timeout: 3
InlineCode: |
exports.handler = async () => ‘Hello World!'
Thanks to @tylersouthwick, one of our community contributors, for this new feature!
#408 Add MobileAnalyticsWriteOnlyAccessPolicy and PinpointEndpointAccessPolicy to Policy Templates #449 Fix ANY method ARN generation to use a wildcard (*) #477 Fix references to AWSLambdaSQSQueueExecutionRole Commit Add SSE to SimpleTable #397 Add FirehoseWritePolicy and FirehoseCrudPolicy to Policy Templates #490 #491 Add support for Python3 (AWS internal transform still uses Python2.7 for backwards compatibility) Also, updates to the documentation and example applications.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →