[ aws . lambda-web ]

deploy

Description

Deploys a local HTTP server to an AWS Lambda Web Function. The command creates a Web Function or deploys a new revision to an existing Web Function, applies the requested endpoint configuration, and returns the endpoint URL.

The deploy command coordinates API operations for common create and update workflows. For configuration that is not available through deploy, such as weighted revision routing or connecting a Web Function to a VPC, use the aws lambda-web commands for specific API operations.

Synopsis

  deploy
--name <value>
[--code <value>]
[--hello-world]
[--create]
[--runtime <value>]
[--entry-point <value>]
[--execution-role-arn <value>]
[--bucket-name <value>]
[--env <value>]
[--unset-env <value>]
[--timeout-seconds <value>]
[--max-concurrency-per-environment <value>]
[--kms-key-arn <value>]
[--application-log-level <value>]
[--system-log-level <value>]
[--revision-description <value>]
[--include-hidden-files]
[--force-include <value>]
[--no-wait]
[--activation-timeout <value>]
[--progress-frequency <value>]
[--endpoint-name <value>]
[--endpoint-type <value>]
[--auth-type <value>]
[--auto-deployment-mode <value>]
[--regions <value>]
[--tags <value>]
[--max-environments <value>]
[--rate-limit <value>]
[--description <value>]
[--debug]
[--endpoint-url <value>]
[--no-verify-ssl]
[--no-paginate]
[--output <value>]
[--query <value>]
[--profile <value>]
[--region <value>]
[--version <value>]
[--color <value>]
[--no-sign-request]
[--ca-bundle <value>]
[--cli-read-timeout <value>]
[--cli-connect-timeout <value>]
[--cli-binary-format <value>]
[--no-cli-pager]
[--cli-auto-prompt]
[--no-cli-auto-prompt]
[--cli-error-format <value>]

Options

--name (string) [required] Name of the Web Function. The name must be between 2 and 64 characters long. It can contain letters, numbers, hyphens (-), and underscores (_). It cannot start or end with a hyphen or underscore.

--code (string) Path to the directory that contains the Web Function source code. This option is required when you create a Web Function unless you use --hello-world. For an existing Web Function, omit this option to update configuration and reuse the deployed code. With --hello-world, the default is ./<name>.

--hello-world (boolean) Create and deploy a minimal TypeScript starter that listens on port 3000. Set LOCAL_PORT to use a different port for local development. The starter uses nodejs24.x. Only --name is required.

--create (boolean) Confirm creation of a Web Function or endpoint without a prompt. If you omit this option in an interactive terminal, the command prompts for confirmation. In a non-interactive environment, you must specify this option when creation is required.

--runtime (string) Runtime identifier for the Web Function. When you create a Web Function, the default is nodejs24.x. When you update a Web Function, the command reuses its current runtime.

--entry-point (string) Path to the entry file, relative to --code. The entry file must start the HTTP server. If you omit this option, the command checks the main and exports fields in package.json, then checks common files such as index.js and server.js. If the entry file is not index.js, the command adds an index.js wrapper that imports it. To have the runtime load a file directly, set AWS_LAMBDA_NODEJS_ENTRYPOINT with --env instead. Do not use --entry-point and AWS_LAMBDA_NODEJS_ENTRYPOINT together.

--execution-role-arn (string) Amazon Resource Name (ARN) of an AWS Identity and Access Management (AWS IAM) execution role. When you create a Web Function and omit this option, the command creates a role named awscli-lambdaweb-<name>. When you update a Web Function and omit this option, the command reuses its current role.

--bucket-name (string) Name of an existing Amazon Simple Storage Service (Amazon S3) bucket for the deployment package. If you omit this option, the command uses a managed bucket named awscli-lambdaweb-<account-id>-<region>-an.

--env (string) Environment variable in KEY=VALUE format. To specify multiple variables, repeat this option for each variable. For example, --env KEY1=VALUE1 --env KEY2=VALUE2. For an existing Web Function, the command adds or replaces the specified keys and preserves other variables. To remove a variable, use --unset-env. To select the file that the runtime loads, set AWS_LAMBDA_NODEJS_ENTRYPOINT with this option. Do not use AWS_LAMBDA_NODEJS_ENTRYPOINT with --entry-point.

--unset-env (string) Name of an environment variable to remove from an existing Web Function. You can specify this option multiple times. The command applies this option after --env, so removal takes precedence when you specify the same key with both options. This option has no effect when you create a Web Function.

--timeout-seconds (integer) Maximum amount of time, in seconds, that the Web Function can run. When you update a Web Function and omit this option, the command reuses its current timeout.

--max-concurrency-per-environment (integer) Maximum number of concurrent requests that each execution environment can process. When you update a Web Function and omit this option, the command reuses its current value.

--kms-key-arn (string) ARN of the AWS Key Management Service (AWS KMS) key that encrypts the Web Function revision’s code and environment variables. This key doesn’t encrypt the deployment package in Amazon S3. When you update a Web Function and omit this option, the command reuses its current AWS KMS key.

--application-log-level (string) Minimum log level for application logs. When you update a Web Function and omit this option, the command reuses its current application log level.

Possible values:

  • TRACE
  • DEBUG
  • INFO
  • WARN
  • ERROR
  • FATAL

--system-log-level (string) Minimum log level for system logs. When you update a Web Function and omit this option, the command reuses its current system log level.

Possible values:

  • DEBUG
  • INFO
  • WARN

--revision-description (string) Description for the revision.

--include-hidden-files (boolean) Include hidden files and directories in the deployment package. The command includes these build and runtime paths even when you omit this option: .next/, .nuxt/, .svelte-kit/, .output/, .prisma/, .yarn/, .pnp.cjs, .pnp.data.json, .pnp.loader.mjs, .pnp.js. The command still excludes entries that match these patterns: .git/, .svn/, .hg/, __pycache__/, node_modules/.cache/, .aws-sam/, .terraform/, .aws/, .ssh/, .DS_Store, *.pyc, *.pem, *.key, id_rsa*, .env, .env.*, .npmrc, .netrc. You can use --force-include to include an exact file, but it does not override directory exclusions.

--force-include (string) Path to a regular file, relative to --code, to include when the command would otherwise exclude it. To include multiple files, repeat this option. To include a file from a hidden directory, also use --include-hidden-files. This option cannot include symlinks or files inside an excluded directory. Verify that each file does not contain credentials or other secrets. Use AWS Secrets Manager for runtime secrets.

--no-wait (boolean) Return without waiting for endpoint activation. When you create a Web Function, the initial endpoint is included in the request. When you update a Web Function and request an endpoint change, the command waits for the revision to become Active, submits the endpoint change, and then returns.

--activation-timeout (integer) Maximum time, in seconds, to wait for activation. Default: 600.

--progress-frequency (integer) Interval, in seconds, between progress messages while the command waits for activation. Default: 5.

--endpoint-name (string) Name of the endpoint to deploy. When you create a Web Function, the default is dev. For an existing Web Function, the command updates the named endpoint or creates it after confirmation.

--endpoint-type (string) Type of endpoint to create. When you create an endpoint and omit this option, the command uses HomeRegion. After you create an endpoint, you cannot change its type. You can create another endpoint with a different type.

Possible values:

  • HomeRegion
  • MultiRegion
  • PerRegion

--auth-type (string) Authorization type for the endpoint. When you create an endpoint and omit this option, the command uses ApplicationManaged. When you update an endpoint and omit this option, the command preserves its current authorization type.

Possible values:

  • ApplicationManaged
  • IamAuth

--auto-deployment-mode (string) Automatic deployment mode for the endpoint. The default for a HomeRegion endpoint is LatestRevision. MultiRegion and PerRegion endpoints use Disabled. LatestRevision serves the newest revision. Disabled serves the configured revision weights. For an existing endpoint, omit this option to preserve its current mode.

Possible values:

  • LatestRevision
  • Disabled

--regions (string) Comma-separated list of AWS Region codes for a MultiRegion or PerRegion endpoint. For example, --endpoint-type MultiRegion --regions us-east-1,us-west-2. Include at least one AWS Region other than the home Region. For a HomeRegion endpoint, omit this option or specify only the home Region. The --region option or your AWS CLI configuration determines the home Region where the CLI sends the deploy request. You cannot change the AWS Regions after the endpoint is created.

--tags (string) Tag in KEY=VALUE format to apply to the Web Function. To specify multiple tags, repeat this option for each tag. For example, --tags KEY1=VALUE1 --tags KEY2=VALUE2. When you update a Web Function, the command adds or replaces the specified tags and preserves tags with other keys. To remove tags, use aws lambda-web untag-resource with the Web Function ARN and --tag-keys.

--max-environments (integer) Maximum number of concurrent execution environments for the endpoint. When you update an existing endpoint, omit this option to preserve its current value.

--rate-limit (integer) Maximum number of requests per second for the endpoint. The supported values and effective limit can vary by AWS account or AWS Region. When you update an existing endpoint, omit this option to preserve its current value.

--description (string) Description for the endpoint. For an existing endpoint, the command updates the description when this value differs from the current description.

Global Options

--debug (boolean)

Turn on debug logging.

--endpoint-url (string)

Override command’s default URL with the given URL.

--no-verify-ssl (boolean)

By default, the AWS CLI uses SSL when communicating with AWS services. For each SSL connection, the AWS CLI will verify SSL certificates. This option overrides the default behavior of verifying SSL certificates.

--no-paginate (boolean)

Disable automatic pagination. If automatic pagination is disabled, the AWS CLI will only make one call, for the first page of results.

--output (string)

The formatting style for command output.

  • json
  • text
  • table
  • yaml
  • yaml-stream
  • off

--query (string)

A JMESPath query to use in filtering the response data.

--profile (string)

Use a specific profile from your credential file.

--region (string)

The region to use. Overrides config/env settings.

--version (string)

Display the version of this tool.

--color (string)

Turn on/off color output.

  • on
  • off
  • auto

--no-sign-request (boolean)

Do not sign requests. Credentials will not be loaded if this argument is provided.

--ca-bundle (string)

The CA certificate bundle to use when verifying SSL certificates. Overrides config/env settings.

--cli-read-timeout (int)

The maximum socket read time in seconds. If the value is set to 0, the socket read will be blocking and not timeout. The default value is 60 seconds.

--cli-connect-timeout (int)

The maximum socket connect time in seconds. If the value is set to 0, the socket connect will be blocking and not timeout. The default value is 60 seconds.

--cli-binary-format (string)

The formatting style to be used for binary blobs. The default format is base64. The base64 format expects binary blobs to be provided as a base64 encoded string. The raw-in-base64-out format preserves compatibility with AWS CLI V1 behavior and binary values must be passed literally. When providing contents from a file that map to a binary blob fileb:// will always be treated as binary and use the file contents directly regardless of the cli-binary-format setting. When using file:// the file contents will need to properly formatted for the configured cli-binary-format.

  • base64
  • raw-in-base64-out

--no-cli-pager (boolean)

Disable cli pager for output.

--cli-auto-prompt (boolean)

Automatically prompt for CLI input parameters.

--no-cli-auto-prompt (boolean)

Disable automatically prompt for CLI input parameters.

--cli-error-format (string)

The formatting style for error output. By default, errors are displayed in enhanced format.

  • legacy
  • json
  • yaml
  • text
  • table
  • enhanced

Examples

Note

To use the following examples, you must have the AWS CLI installed and configured. See the Getting started guide in the AWS CLI User Guide for more information.

Unless otherwise stated, all examples have unix-like quotation rules. These examples will need to be adapted to your terminal’s quoting rules. See Using quotation marks with strings in the AWS CLI User Guide .

These examples use us-east-1 as the AWS Region for deployment. The command selects the AWS Region from --region, the AWS_DEFAULT_REGION environment variable, or your AWS CLI configuration. You can use a different AWS Region. Endpoint and console URLs reflect the AWS Region used for the deployment. A MultiRegion endpoint uses the global endpoint domain. The endpoint identifiers are fictitious and do not identify live resources.

Example 1: To create and deploy a starter application

The following deploy example creates a TypeScript starter in ./my-app and deploys it. The command creates or reuses an Amazon Simple Storage Service (Amazon S3) deployment bucket and an AWS Identity and Access Management (IAM) execution role. It then creates the Web Function and endpoint. The target path can be new or can identify an existing empty directory.

aws lambda-web deploy --name my-app --hello-world

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 2: To create a Web Function from existing source code

The following deploy example creates a Web Function from an existing HTTP server. The --create option skips the confirmation prompt. If you omit --bucket-name or --execution-role-arn, the command creates or reuses the deployment bucket and execution role as needed.

aws lambda-web deploy --name my-app --code ./app --create

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 3: To deploy new source code

The following deploy example deploys a revision to an existing Web Function and updates its endpoint.

aws lambda-web deploy --name my-app --code ./app

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 4: To deploy source code with environment variables

The following deploy example deploys new source code and adds or replaces two application environment variables.

aws lambda-web deploy \
    --name my-app \
    --code ./app \
    --env APP_ENV=staging \
    --env FEATURE_FLAG=on

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 5: To update configuration without uploading source code

The following deploy example updates an environment variable and the request timeout. Because the command omits --code, it reuses the deployed source code.

aws lambda-web deploy \
    --name my-app \
    --env APP_ENV=production \
    --timeout-seconds 60

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 6: To create another endpoint

The following deploy example creates a staging endpoint for an existing Web Function and reuses its deployed source code. The --create option skips the confirmation prompt.

aws lambda-web deploy \
    --name my-app \
    --endpoint-name staging \
    --create

Output:

https://f6g7h8i9j0.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 7: To create a MultiRegion endpoint

The following deploy example creates a MultiRegion endpoint in two AWS Regions for an existing Web Function and reuses its deployed source code. The --create option skips the confirmation prompt.

aws lambda-web deploy \
    --name my-app \
    --endpoint-name global \
    --endpoint-type MultiRegion \
    --regions us-east-1,us-west-2 \
    --create

Output:

https://k1l2m3n4o5.lambda-web.global.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 8: To deploy a built entry file with its dependencies

The following deploy example packages the project root and uses dist/index.js as the entry file. Using --code . instead of --code ./dist includes dependencies such as node_modules that are outside the output directory. The command does not bundle the application.

If you omit --entry-point, the command checks the main and exports fields in package.json, then checks common entry files.

aws lambda-web deploy \
    --name my-app \
    --code . \
    --entry-point dist/index.js

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app

Example 9: To select the entry file with an environment variable

The following deploy example sets AWS_LAMBDA_NODEJS_ENTRYPOINT so that the runtime loads src/server.mjs directly. Do not use AWS_LAMBDA_NODEJS_ENTRYPOINT and --entry-point together.

aws lambda-web deploy \
    --name my-app \
    --code ./app \
    --env AWS_LAMBDA_NODEJS_ENTRYPOINT=src/server.mjs

Output:

https://a1b2c3d4e5.x9y.lambda-web.us-east-1.on.aws
Console: https://us-east-1.console.aws.amazon.com/lambda/home#/web-functions/my-app