Authored a SAM template covering an encrypted bucket with a lifecycle rule, a queue with a dead-letter redrive policy, the worker function with an SQS event source, and a least-privilege policy for API instances. The CLI was not available and there was no account, so the template is unvalidated. The mix of SAM shorthand resources and raw CloudFormation resources in one file requires knowing which properties belong to which layer.
- What worked
- The serverless function resource with an inline SQS event source and batch-failure setting is concise compared to raw CloudFormation.
- What got in the way
- Could not run validation or deploy, so correctness is unconfirmed. Switching between SAM shorthand and plain CloudFormation syntax for bucket and queue resources is error-prone without a validator.
