Cloud SDK Best Practices
Safe, efficient, well-scoped AWS SDK usage keeps Python services fast under load and limits blast radius when credentials leak or scripts mis-target an account.
Search across all documentation pages
Safe, efficient, well-scoped AWS SDK usage keeps Python services fast under load and limits blast radius when credentials leak or scripts mis-target an account.
sts.get_caller_identity() in destructive CLIs. Confirm account before delete operations.* actions on * resources.AWS_PROFILE documented in runbooks and CI jobs.boto3.Session once per process context. Reuse clients across requests in workers and Lambda handlers.region_name on sessions. Avoid ambiguous cross-region redirects and signing bugs.botocore.config.Config retries and timeouts. Match service p99 latency and throttle behavior.max_pool_connections for parallel uploads. Prevent connection pool starvation.SecretString, presigned URLs, or auth headers. Log ARNs and request IDs only.ClientError.response["Error"]["Code"].AccessDenied spikes after IAM changes.Backoff with jitter, reduce concurrency, and verify adaptive retry config before raising limits.
Clients for full API and newest operations; resources for ergonomic S3/DynamoDB app code - pick per call site.
Internal package with session factory, retry config, and logging decorators - version with app monorepo.
Yes for quick calls with tuned pool; offload long scans to background workers or threadpool.
Co-locate with data and users; document region in session factory - multi-region needs explicit failover design.
Safe with short TTL and least-privilege key prefix - treat leaked URL like temporary credential leak.
Policy simulator plus integration test in sandbox assuming the new role before prod promotion.
Adapter interface per capability (object store, queue); keep provider SDKs at infrastructure boundary.
Paginate with MaxItems in dev scripts; alarms on DynamoDB consumed capacity and S3 request metrics.
Large infra provisioning - use Pulumi/Terraform; boto3 for runtime ops and small idempotent ensures.
Stack versions: This page was written for Python 3.14.0 (stable 3.14, maintenance 3.13), FastAPI 0.115+, Django 5.2, Flask 3.1, Pydantic 2, PyTorch 2.6+, pandas 2.2+, Polars 1.x, ruff 0.9+, and uv 0.6+.
Reviewed by Chris St. John·Last updated Jul 19, 2026