AWS::Lambda::Function Code - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

AWS::Lambda::Function Code

The deployment package for a Lambda function. To deploy a function defined as a container image, you specify the location of a container image in the Amazon ECR registry. For a .zip file deployment package, you can specify the location of an object in Amazon S3. For Node.js and Python functions, you can specify the function code inline in the template.


When you specify source code inline for a Node.js function, the index file that Amazon CloudFormation creates uses the extension .js. This means that Lambda treats the file as a CommonJS module. ES modules aren't supported for inline functions.

Changes to a deployment package in Amazon S3 or a container image in ECR are not detected automatically during stack updates. To update the function code, change the object key or version in the template.


To declare this entity in your Amazon CloudFormation template, use the following syntax:


{ "ImageUri" : String, "S3Bucket" : String, "S3Key" : String, "S3ObjectVersion" : String, "SourceKMSKeyArn" : String, "ZipFile" : String }


ImageUri: String S3Bucket: String S3Key: String S3ObjectVersion: String SourceKMSKeyArn: String ZipFile: String



URI of a container image in the Amazon ECR registry.

Required: No

Type: String

Update requires: No interruption


An Amazon S3 bucket in the same Amazon Web Services Region as your function. The bucket can be in a different Amazon Web Services account.

Required: Conditional

Type: String

Pattern: ^[0-9A-Za-z\.\-_]*(?<!\.)$

Minimum: 3

Maximum: 63

Update requires: No interruption


The Amazon S3 key of the deployment package.

Required: Conditional

Type: String

Minimum: 1

Maximum: 1024

Update requires: No interruption


For versioned objects, the version of the deployment package object to use.

Required: Conditional

Type: String

Minimum: 1

Maximum: 1024

Update requires: No interruption


The ARN of the Amazon Key Management Service (Amazon KMS) customer managed key that's used to encrypt your function's .zip deployment package. If you don't provide a customer managed key, Lambda uses an Amazon owned key.

Required: No

Type: String

Pattern: ^(arn:(aws[a-zA-Z-]*)?:[a-z0-9-.]+:.*)|()$

Update requires: No interruption


(Node.js and Python) The source code of your Lambda function. If you include your function source inline with this parameter, Amazon CloudFormation places it in a file named index and zips it to create a deployment package. This zip file cannot exceed 4MB. For the Handler property, the first part of the handler identifier must be index. For example, index.handler.


When you specify source code inline for a Node.js function, the index file that Amazon CloudFormation creates uses the extension .js. This means that Lambda treats the file as a CommonJS module. ES modules aren't supported for inline functions.

For JSON, you must escape quotes and special characters such as newline (\n) with a backslash.

If you specify a function that interacts with an Amazon CloudFormation custom resource, you don't have to write your own functions to send responses to the custom resource that invoked the function. Amazon CloudFormation provides a response module (cfn-response) that simplifies sending responses. See Using Amazon Lambda with Amazon CloudFormation for details.

Required: Conditional

Type: String

Update requires: No interruption


Inline Function

Inline Node.js function that lists Amazon S3 buckets in us-east-1 . This example uses the Amazon SDK for JavaScript v3, which is available in the nodejs18.x runtime. Before using this example, make sure that your function's execution role has Amazon S3 read permissions.


Code: ZipFile: | const { S3Client, ListBucketsCommand } = require("@aws-sdk/client-s3"); const s3 = new S3Client({ region: "us-east-1" }); // replace "us-east-1" with your Amazon Web Services Region exports.handler = async function(event) { const command = new ListBucketsCommand({}); const response = await s3.send(command); return response.Buckets; };