EasySAM
EasySAM is an opinionated YAML-to-SAM generator for modular AWS serverless applications.
It helps you define Lambda functions, API Gateway routes, DynamoDB tables, S3 buckets, SQS queues, Kinesis streams, OpenSearch Serverless collections, and IoT Core authorizers in a compact resources.yaml model, then generate and deploy the resulting SAM stack.
Why EasySAM
- Simple YAML-first resource definitions
- Recursive import system (
import+ localeasysam.yaml) - Modular app structure with shared
common/code support - Built-in validation (
inspect schema,inspect cloud) - Native support for:
- Environment variable expansion and
.envloading - DynamoDB stream triggers from table definitions
- DynamoDB TTL
- Lambda Function URLs
- Prismarine model-driven tables
- OpenSearch Serverless search collections
- MQTT/IoT Core custom authorizers
- Local Lambda execution (no Docker required)
- Environment variable expansion and
Prerequisites
- Python 3.12+ (Your local/CI environment version should match the
python:option inresources.yamlto ensure dependency compatibility) - AWS credentials configured (named profile recommended)
- AWS SAM CLI 1.138.0+
pip25.1.1+ (used in deployment checks)- One of:
uv(recommended for project-local workflows)pipx(recommended for global CLI install)pip
Installation
Choose one installation method.
Option A: project-local with uv
uv add --dev easysam
Use as:
uv run easysam --help
Option B: global with pipx
pipx install easysam
Use as:
easysam --help
Option C: global/local with pip
pip install easysam
Quick start (5 minutes)
- Create a Python project and initialize EasySAM:
mkdir my-easysam-app
cd my-easysam-app
uv init
uv add --dev easysam
uv run easysam init
For a Prismarine scaffold:
uv run easysam init --prismarine
- Validate your resources:
uv run easysam --environment dev inspect schema .
- Generate templates:
uv run easysam --environment dev generate .
- Deploy to AWS:
uv run easysam --environment dev --aws-profile my-profile deploy . --tag project=easysam-demo
- Delete stack when done:
uv run easysam --environment dev --aws-profile my-profile delete --await
For all options:
uv run easysam --help
Local execution
Run your Lambda handlers locally without deploying — no Docker required. EasySAM starts a local HTTP server that mocks API Gateway routing while using real cloud resources (DynamoDB, S3, etc.).
# Start local server (default: http://127.0.0.1:3000)
uv run easysam --environment dev local .
# Custom port and REST API v1 event format (default)
uv run easysam --environment dev local . --port 8080
# Use HTTP API v2 event format
uv run easysam --environment dev local . --event-format v2
# Inject authorization context (simulates authenticated user)
uv run easysam --environment dev local . --auth-context '{"principalId": "dev-user"}'
# Or from a file
uv run easysam --environment dev local . --auth-context auth-context.json
Then call your endpoints:
curl http://127.0.0.1:3000/items
Invoke a single function
For non-HTTP triggers (SQS, Kinesis, DynamoDB streams), invoke a function directly:
# With an event file
uv run easysam --environment dev local . invoke myfunction --event event.json
# With inline JSON
uv run easysam --environment dev local . invoke myfunction --event '{"Records": [...]}'
# With empty event (default)
uv run easysam --environment dev local . invoke myfunction
Minimal resources.yaml
prefix: MyApp
import:
- backend
EasySAM recursively finds easysam.yaml files under backend/ and merges them.
Local import file format (easysam.yaml)
lambda:
name: myfunction
resources:
tables:
- MyItem
integration:
path: /items
open: true
greedy: false
You can also define tables locally:
tables:
MyItem:
attributes:
- name: ItemID
hash: true
Key concepts
Environment Variables and .env files
EasySAM automatically loads .env files if present in the target directory. It evaluates environment variables using the standard ${MY_VAR} syntax in both global (resources.yaml) and local (easysam.yaml) files immediately after they are loaded.
Global CLI options can also be set via environment variables:
| CLI option | Environment variable |
|---|---|
--environment |
EASYSAM_ENVIRONMENT |
--aws-profile |
EASYSAM_AWS_PROFILE |
--target-region |
EASYSAM_TARGET_REGION |
Explicit CLI flags always take precedence over environment variables.
You can also pass environment variables to your functions directly using the envvars property.
functions:
myfunc:
uri: "src/"
envvars:
API_URL: "${API_URL}"
LOG_LEVEL: "DEBUG"
DynamoDB table triggers
Trigger a Lambda directly from table changes:
tables:
SearchableItem:
attributes:
- name: ItemID
hash: true
trigger: indexfunc
Advanced trigger configuration:
tables:
SearchableItem:
attributes:
- name: ItemID
hash: true
trigger:
function: indexfunc
viewtype: new-and-old
batchsize: 10
batchwindow: 5
startingposition: latest
Conditional resources
Conditional keys are resolved against deploy context (environment, target_region):
buckets:
? !Conditional
key: my-bucket
environment: prod
region: eu-west-2
:
public: true
extaccesspolicy: ProdPolicy
Negation is supported using ~ (example: environment: ~prod).
Deployment context overrides
Use a context file for CI/environment-specific patches:
overrides:
buckets/my-bucket/public: true
Then pass it with:
uv run easysam --environment dev --context-file deploy-context.yaml deploy .
Prismarine integration
prismarine:
default-base: common
access-module: common.dynamo_access
modelling: typed-dict
tables:
- package: myobject
Set modelling: pydantic for Pydantic-based generated clients.
MQTT / IoT Core custom authorizer
mqtt:
authorizer:
function: mqtt-auth
topics:
- channels/*
If a function publishes to IoT topics, add mqtt in function services.
Documentation
Examples
All examples live under example/ and include focused scenarios such as:
- minimal app bootstrap
- conditionals and deploy context overrides
- custom Lambda layers
- global and local env vars (with
.envfile support) and plugins - DynamoDB TTL (plain + Prismarine)
- Prismarine TypedDict and Pydantic modelling
- OpenSearch Serverless + DynamoDB streams
- Kinesis with multiple S3 destinations
See the full index: example/README.md.
Development
git clone https://github.com/adsight-app/easysam.git
cd easysam
uv sync
source .venv/bin/activate
Changelog
See CHANGELOG.md.
Support
If you hit an issue:
- Search existing issues
- Open a new issue with a reproducible example
License
MIT. See LICENSE.
Metadata
Release files for easysam 1.13.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| easysam-1.13.0.tar.gz | 222.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| easysam-1.13.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 269.0 kB
Release files / easysam-1.13.0.tar.gz
| Download URL | easysam-1.13.0.tar.gz |
|---|---|
| Size | 222.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1497d00525387a144f4961f05c1eeadbb91bf7a1a9756aa340f06e8d50e3b83a
|
|
BLAKE2b-256 checksum How to use checksums |
ef54229ed10192c7be4383f70ecd523285afdadd6342306d8fef4d710dd3fc59
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.
Transparency logRelease files / easysam-1.13.0-py3-none-any.whl
| Download URL | easysam-1.13.0-py3-none-any.whl |
|---|---|
| Size | 46.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d1eb658d2b63dfee4dd6f842a73720abfc8e283bd3fc5b6d1ee1973c45aca124
|
|
BLAKE2b-256 checksum How to use checksums |
4f19d2c9067a49500fd0db63d716923149e867a01eacac9a5e5111909bae59ff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.
Transparency log