Lesson 378 · AWS Learning Path

AWS 378: AWS SAM templates, local testing, packaging, deployment, and policies

· Published · 4 min read

Labelled process diagram for AWS 378: Versioned intent to Automated validation to Controlled AWS change to Observed result and retained evidence, with decision, proof and rejection evidence.

Why this lesson matters

AWS SAM extends CloudFormation with serverless resources and a separate CLI for build, local emulation, packaging, synchronization, and deployment. Production readiness requires understanding the transform, generated resources, IAM policy expansion, artifact identity, local-test limits, change sets, aliases, and cleanup.

Template and transformation model

A SAM template includes the AWS::Serverless-2016-10-31 transform and may contain both SAM and ordinary CloudFormation resources. During transformation, concise resources generate Lambda functions, roles, APIs, permissions, deployments, log integrations, state machines, or event mappings. Review the processed CloudFormation, not only the shorthand.

SAM construct/controlPurposeReview focus
AWS::Serverless::FunctionFunction, code/image, eventsRuntime, architecture, timeout, concurrency, logging
GlobalsShared supported propertiesHidden broad defaults and merge behavior
EventsTrigger integrationPermission, retry, filtering, ordering, DLQ/destination
AutoPublishAliasVersion/alias publicationImmutable deployment and traffic configuration
Policy templateParameterized common permissionsExpanded actions/resources, least privilege
ConnectorPermission between resourcesGenerated policy and supported boundary

Policy templates and connectors are conveniences, not proof of least privilege. Transform/synthesize and inspect the generated IAM role/policy. Prefer explicit resource-scoped policies when templates grant more than required. Separate deployment identity from function execution roles and never embed secrets in template, samconfig.toml, events, or environment files.

Build and local testing

Pin SAM CLI, container image/runtime, language dependencies, and architecture. sam build creates .aws-sam output, installs dependencies, prepares code/images, and rewrites artifact paths. Never edit generated build output as source. Use --use-container when reproducibility and native dependencies require the Lambda-like build image; still scan and record it.

sam local invoke, start-api, generated events, debugger, and Docker accelerate feedback. They emulate selected Lambda/API behavior, not IAM evaluation, service quotas, VPC networking, KMS, managed retries, concurrency, event-source polling, API edge behavior, CloudWatch, or distributed failure. Pair unit/local tests with cloud integration, security, load, retry/idempotency, and rollback tests in an approved sandbox.

Keep sanitized event fixtures for API, S3, EventBridge, SQS/SNS, and stream schemas. Test valid, malformed, oversized/boundary, duplicate, out-of-order, partial-batch failure, timeout, and dependency failure. Do not use real customer events locally.

Package and deployment

For ZIP resources, packaging/uploads place immutable artifacts in S3 and produce references; image functions use ECR. Record commit, source hash, dependency lock, build environment, artifact SHA-256 or image digest, transformed template hash, and execution/change-set ID. Do not deploy mutable image tags as release evidence.

sam deploy --guided helps create configuration, but production should use reviewed noninteractive settings. Review capabilities, parameter overrides, KMS/S3/ECR ownership, tags, failure behavior, change set, IAM changes, resource replacements/deletions, alias preference, alarms, and rollback. sam sync favors development speed and can bypass a normal reviewed deployment path; restrict it to approved development environments.

Safe deletion requires data classification. sam delete/stack deletion can leave retained resources, versions, logs, buckets, ECR images, APIs/domains, event sources, and KMS keys. Inventory before and after, and never empty/delete unowned data.

Local workshop

Build a function behind an API that writes idempotently to DynamoDB and sends failed asynchronous work to a queue. Define explicit runtime, architecture, memory, timeout, tracing/log retention, reserved concurrency, environment references, alias, deployment preference/alarms, API authorization, table encryption/PITR, and narrow policies.

sam --version
sam validate --lint --template-file template.yaml
sam build --use-container
sam local invoke FunctionLogicalId --event events/valid.json
sam local start-api
sam package --s3-bucket ARTIFACT_BUCKET --output-template-file packaged.yaml
aws cloudformation validate-template --template-body file://packaged.yaml

The package command requires approved AWS access and is optional; otherwise use supplied output. Inspect .aws-sam, transformed template, IAM, artifact hashes, and local logs. Produce a reviewed change set without executing it.

Failure game day and acceptance

Diagnose 18 failures: CLI/runtime mismatch, Docker missing, native dependency architecture, stale build output, secret in fixture, event-schema mismatch, local/cloud difference, broad policy template, transform permission, artifact KMS denial, wrong Region bucket, mutable image, CloudFormation capability omitted, alias traffic alarm, event-source duplicate, partial-batch error, retained data orphan, and rollback after external write.

Price Lambda requests/duration/concurrency, API, DynamoDB, queues/topics, logs/traces, artifact S3/ECR/KMS, build compute, data transfer, and retained versions. Submit source plus processed template, generated-resource/IAM inventory, build manifest, test matrix, artifact lineage, change-set review, deployment/rollback plan, eighteen failures, cost, and two-pass cleanup. Pass requires explicit generated controls, no secret leakage, immutable artifacts, honest local-test boundaries, least privilege, and state-safe recovery.

Official sources

Advertisement