Remaining SAM scaffold for an existing Python Lambda stack. New functions belong in an HCP Terraform repo; see [terraform-project-layout.md](terraform-project-layout.md) and [aws-infrastructure.md](aws-infrastructure.md#lambda-defaults).
-`Globals.Function` sets runtime, architecture, and JSON logging once for the whole template.
- The `LogGroup` is declared **explicitly** with `RetentionInDays: 60`. Omit it and CloudWatch creates the log group on first invocation with no retention — logs accumulate forever.
- IAM scopes `secretsmanager:GetSecretValue` to the stack's secret prefix only. Add specific permissions as needed; never use `AdministratorAccess`.
The module-level `_config` global caches the secret across warm invocations. The first call per cold start hits Secrets Manager; subsequent calls reuse the cached value. See [secrets-and-config.md](secrets-and-config.md) for the rationale.
## src/handler/requirements.txt
Keep this file in every function directory even when empty — SAM looks for it during `sam build`.
```
# Per-function dependencies. Leave empty if the function uses only boto3 and stdlib.
```
## Naming Reminders
-`FunctionName` must be kebab-case and start with the stack name (`my-stack-handler`).
- Secret IDs use `stack-name/secret-name`.
- Stack name itself is set in `samconfig.toml`, not the template — match the repo name.
See [naming-conventions.md](naming-conventions.md).