- Safe Init now fetches secrets from AWS Secrets Manager in batches of 20, the most the
BatchGetSecretValueAPI accepts in a single call. Resolving more than 20 uncached secrets used to fail all of them. A batch that fails no longer discards the secrets resolved by the other ones.
- Secret resolution failures are now logged without their traceback. The renderer used in the runtime environment serializes the local variables of every frame, which would expose the values of the secrets resolved so far.
boto3is now required in a version that provides theBatchGetSecretValueAPI.
- Safe Init now automatically checks if your Lambda function's return value can be serialized to JSON. If not, it will report the issue to Sentry while allowing execution to continue normally. This helps catch issues with returning non-serializable objects like UUID instances early without breaking your Lambda's execution flow.
- Migrated the project to use uv for dependency management and virtual environments.
- Safe Init now allows you to work around the crazy 4KB limit on environment variables in AWS Lambda. Just put some of your environment variables in a JSON file (
.env.jsonby default) and Safe Init will take care of the rest.
- Safe Init will now fall back to fetching secrets from AWS Secrets Manager if fetching from Redis throws any exception.
- AWS Secrets resolution will use batch method to reduce number of API calls and network round trips.
- Safe Init will no longer add the configured AWS Secrets Manager secret ARN prefix to the specified value if it already contains a prefix.
- Setting Slack webhook URLs and custom loggers using monkey patching wasn't working reliably and is no longer supported. Instead, use ContextVars to set your desired values and Safe Init will read them automatically.
- Fixed Slack notifications not being sent when Safe Init couldn't gather enough information to identify function execution context.
- Added a new option (
SAFE_INIT_ALWAYS_NOTIFY_SLACK) that enables Safe Init to notify Slack about failures even if a Sentry notification has been sent successfully.
- Fixed a bug where the value of an AWS Secrets Manager secret wasn't always returned as a string.
- Added a new option that allows specifying a common ARN prefix for all secrets using the
SAFE_INIT_SECRET_ARN_PREFIXenvironment variable.
- Fixed a bug where a KeyError could be raised if an environment variable was no longer found after function import phase.
- Fixed a bug where setting environment variables to a false-like value (e.g.
0,false,off,no) would not work as expected.
- Fixed a bug where resolved AWS Secrets Manager secrets were being accessible during the initialization, but not during the execution of the Lambda function.
No significant changes.
- AWS Secrets integration: Safe Init can now automatically fetch secrets from AWS Secrets Manager and inject them into your Lambda function's environment variables.
- Timeout notifications now include additional tags and attachments in Sentry events.
- Added tags to uncaught exception events in Sentry.
- Updated
README.mdwith screenshots of Slack notifications.
- Added Lambda function name to timeout notification logs and Sentry events.
- Updated package compatibility with
ddtraceanddatadog-lambdato all available versions.
- Updated
README.mdand documentation site with quick links to GitHub, PyPI and the documentation site.
- First Public Release!