|
Hi there,
Serverless Framework v4.43.0 is now even better for AI coding agents: new commands let your agent
set up, build, deploy, and especially debug AWS services faster and more efficiently - without
spending lots of tokens querying AWS one call at a time.
It works with Claude Code, Codex, Cursor, and any other agent that reads the open Agent Skills
standard. Point your agent at this one command and it takes it from there:
serverless agent setup
Copy Agent Prompt
Browse the skills and the full release notes:
Faster, more reliable debugging with serverless agent inspect
serverless agent inspect has been available since v4.39.0. What is new in v4.43.0 is
everything around it: agentic onboarding and bundled Agent Skills that make it easy for an agent
to find and use it, so it is now the biggest change for day-to-day work.
Until now, an agent that needed to understand or debug a deployed service had to piece it together
one AWS call at a time: list the stack, describe each function, find its role, its log group, its
API, its queue, then work out which logical resource maps to which physical one. That is dozens of
round trips, and every response lands in the agent's context.
serverless agent inspect does it in one read-only command, scoped to just the
resources in your service. It runs the AWS calls in parallel and returns the result organized the
same way your serverless.yml is. Start with the index, a compact inventory of every
resource in the stack, then expand only what the task needs:
serverless agent inspect
serverless agent inspect --functions
serverless agent inspect --iam --observability
serverless agent inspect --aws-services lambda,dynamodb
serverless agent inspect --name CreateOrderLambdaFunction
-
Fewer tokens. The index is compact, a few thousand tokens for a typical
service, and you expand only the categories the task needs, so the agent reads the configuration
it needs and nothing else.
-
Faster. One command replaces dozens of separate describe calls, run in parallel
within AWS rate limits.
-
More reliable. Output is the raw AWS configuration in a fixed category order,
sorted by logical ID, and easy to diff. It reflects live values like alarm state, so it stays
accurate rather than stale. The agent works from what is actually deployed, not from guesses
about
serverless.yml.
-
Safe. Read-only. It never creates, changes, or deletes anything, and never
invokes a function. If one resource can't be described (deleted out of band, access denied), it
shows up as an error entry and the rest still comes back.
It covers Lambda functions, API Gateway (REST, HTTP, WebSocket) and load balancers, SNS,
EventBridge, Scheduler, SQS, Kinesis, IAM roles and policies, S3, DynamoDB, CloudWatch log groups,
alarms and dashboards, CloudFront, Cognito, IoT, and Sandboxes.
Here is what each command fetches and why it keeps token use down:
-
serverless agent inspect - The bare command returns a compact index of every
resource in the stack (logical ID, physical ID, type, status) with no per-resource AWS calls, so
the agent sees the whole service for a few thousand tokens and only expands what it needs.
-
--functions - Fetches Lambda functions with their versions, aliases, URLs,
permissions, event source mappings, and layers, replacing a string of separate get-function,
list-aliases, get-policy, and list-event-source-mappings calls.
-
--api - Fetches API Gateway (REST, HTTP, WebSocket) and load balancer
configuration, routes, integrations, and targets included, so the agent doesn't walk each API
one resource at a time.
-
--events - Fetches SNS topics and subscriptions, EventBridge rules and buses,
Scheduler schedules, SQS queues, and Kinesis consumers, showing what triggers what without
querying each service.
-
--iam - Fetches execution roles with their trust policy and inline and attached
policies already decoded into readable objects, so AccessDenied debugging takes one call with no
URL-decoding.
-
--storage - Fetches S3 buckets and DynamoDB tables with their full configuration,
so the agent can check a setting without hunting through several console or CLI calls.
-
--observability - Fetches CloudWatch log groups, filters, alarms, and dashboards,
so the agent finds the right log group and alarm state immediately instead of guessing names.
-
--cdn - Fetches CloudFront distributions and cache policies, so cache and origin
issues are checked in one read.
-
--identity - Fetches Cognito user pools and their clients, so auth configuration is
one call instead of several.
-
--iot - Fetches IoT topic rules and provisioning templates in one read.
-
--sandboxes - Fetches Lambda MicroVM images (Sandboxes) for services that use them.
-
--all - Expands every category in one call, useful for a full picture of a small
service. On a large stack, prefer the targeted flags above to keep output small.
-
--aws-services lambda,iam - Expands by AWS service name instead of category, so a
task about one service (say Lambda plus IAM) pulls exactly that and nothing else. It combines
with category flags.
-
--name CreateOrderLambdaFunction - Fetches one resource by logical ID, the smallest
possible output, ideal for drilling into a single function or table after reading the index. It
is repeatable.
-
--format yaml - Switches the output to YAML when a person wants to read it; the
default JSON is lossless and what agents and jq expect.
Ask an agent why a function is getting AccessDenied, and it runs
serverless agent inspect --functions --iam and sees the function configuration and
its execution role's policies together. After a deploy, it checks that what shipped matches your
config, and uses serverless diff to compare changes before deploying. It needs
sign-in and AWS credentials, and the docs list the minimal read-only IAM policy it uses.
See every flag in the docs ->
Agentic onboarding
serverless agent setup
installs the Agent Skills bundled with the CLI and prints an environment report covering sign-in,
the AWS credentials a deploy would use (resolver, profile, and SSO session expiry), and the
service. Each item comes with a one-line fix, so an agent knows exactly what to do next. Use
--dir to choose .claude/skills, .agents/skills, or both.
Sign-in now works for agents too.
serverless login
runs in a non-interactive shell: it prints the sign-in URL and waits for you to finish in the
browser. serverless login --org <name> sets your default org, and
--help for built-in commands works before you sign in. In CI with no key, the error
names SERVERLESS_ACCESS_KEY and SERVERLESS_LICENSE_KEY instead of
printing a stack trace.
Skills & Docs Support
The Framework ships its own documentation and Agent Skills inside the CLI, so your agent always
works from content that matches your installed version. Four commands give agents access:
-
serverless agent docs
- prints the documentation that ships with the installed CLI, offline, so an agent always reads
docs that match your version.
-
serverless agent skills list
- lists the skills bundled with the CLI.
-
serverless agent skills read
- prints a bundled skill without installing it.
-
serverless agent skills install - installs the skills, and now runs from any
directory. Outside a service it installs the user-level skill and explains how to get the
project skills.
These commands need no sign-in and no AWS credentials. agent docs,
agent skills list, and agent skills read also work when
serverless.yml doesn't parse.
The CLI ships four Agent Skills that teach your agent how to work with the Framework:
-
serverless-framework (new) - The start-here skill. It loads whenever a
serverless.yml is present or you run a serverless command. It tells
the agent to run serverless agent setup in every project, sort out sign-in and AWS
credentials before work that needs them, and read serverless agent docs instead of
answering from memory. It includes a first-deploy checklist (setup, credentials,
serverless package, deploy to your own stage, verify with a real request or
serverless logs), a test-first workflow on a personal stage with
serverless dev, and guidance to give databases their own service. References cover
the agent commands, the CLI, development workflow, multi-service projects, Python, and
serverless.yml.
-
serverless-upgrade (new) - Upgrades v1, v2, and v3 services to v4 without
changing what deploys. It packages the template before and after and diffs them, so every change
is proven equivalent or explained. It applies only must-fix changes, such as plugins the
Framework now builds in and v3-era syntax, and reports deprecated runtimes and everything else
as an opportunity for you to review, instead of changing them.
-
serverless-mcp (updated) - Hosts MCP servers on AWS Lambda. You write one
standard server module with the official MCP SDK, and the Framework handles the HTTPS route,
response streaming, access control, OAuth discovery, and packaging from a few lines under
mcp in serverless.yml. It also covers the
MCP_* configuration errors.
-
serverless-sandboxes (updated) - Builds isolated, ephemeral compute on AWS
Lambda MicroVMs, for running untrusted or AI-generated code and per-session or per-tenant
workloads. It covers images and instances, starting from a working example, the
serverless dev --sandbox inner loop, and deploying, including why builds take
minutes and how to handle secrets at runtime.
User-level skills install into your home skill directories and keep themselves up to date.
Function packages leave out the skills installed in your project, so they never ship to Lambda.
Other improvements
v4.43.0
-
Sandboxes and agents inherit
provider.environment, and sandbox environments accept
CloudFormation references.
-
package warns about Lambda runtimes AWS has deprecated.
-
Python dependencies ship hash-based bytecode, cutting cold starts.
-
serverless remove fully empties versioned deployment buckets and leaves sibling
stages' artifacts alone.
- esbuild packaging works in git worktrees.
- Self-referencing variables fail fast instead of hanging.
-
Dev Mode works for functions with their own IAM role and stops cleanly on
SIGTERM.
-
Clearer AWS credential errors, including a dedicated message for an expired SSO session.
-
serverless info --json lists HTTP API endpoints as plain URLs.
v4.42.0
-
bundle: false packages like classic packaging, with TypeScript compiled in place
and reproducible artifacts.
-
A new Compose
${service:...} resolver for cross-service references, including
outputs from a different stage.
-
AWS variable resolvers de-duplicate and retry requests, with standard SDK backoff.
-
serverless dev serves MCP servers declared under mcp through the
deployed endpoint with your local code.
-
Provisioned mode for
sqs, kafka, and msk events via the
new provisionedPollers property.
- SnapStart for container-image functions.
-
New Lambda runtimes:
java8.al2023, java11.al2023,
java17.al2023, nodejs26.x, and python3.15, plus durable
functions on Java 17+ and .NET 8+.
-
Sandboxes support
iam.operatorRole customization.
Get started
Update to the latest version with npm i -g serverless, then run
serverless agent setup in your service directory or ask your AI coding agent to do it
for you.
The Serverless Framework is free for individuals and organizations under $2M in annual revenue.
For larger teams,
learn about our Subscription plans
or
schedule a meeting with us.
Serverless Inc - 522 San Anselmo Ave. San Anselmo CA 94960
Click here
to unsubscribe.
|