A developer needs to deploy an AWS Lambda function that processes sensitive customer data. The function needs to connect to an Amazon RDS database instance located in a private subnet within a VPC. Additionally, the Lambda function should only access specific AWS services (e.g., S3, DynamoDB) via private endpoints, without routing traffic through the public internet. How should the Lambda function be configured?
- AUse a Lambda@Edge function and configure its permissions to access RDS and other AWS services directly.
- BConfigure the Lambda function to run inside the VPC, assign it to a private subnet, and create VPC interface endpoints for S3 and DynamoDB.
- CDeploy the Lambda function outside the VPC and configure security groups to allow outbound access to RDS and public endpoints for S3/DynamoDB.
- DPlace the Lambda function in a public subnet within the VPC and configure a NAT Gateway for outbound access to RDS and other AWS services.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure the Lambda function to run inside the VPC, assign it to a private subnet, and create VPC interface endpoints for S3 and DynamoDB.
To connect to RDS in a private subnet and access other AWS services privately, the Lambda function must be configured to run within the VPC in a private subnet. VPC interface endpoints for S3 and DynamoDB ensure that traffic to these services remains within the AWS network, enhancing security and reducing latency.
Why the other options are wrong
- A. Lambda@Edge functions are for CDN-related processing and cannot be placed inside a VPC or configured for private access to RDS or other services in this manner.
- C. Lambda outside VPC cannot directly access resources in private subnets. Public endpoints for S3/DynamoDB would expose traffic to the internet.
- D. Placing Lambda in a public subnet is not ideal for sensitive data processing, and a NAT Gateway routes traffic through the public internet, which violates the private access requirement for S3/DynamoDB.
Lambda VPC & Endpoints
Configuring an AWS Lambda function to operate within a VPC allows it to access private resources like RDS. VPC Endpoints enable private access to other AWS services (S3, DynamoDB) from within the VPC, bypassing the public internet.
- Lambda in VPC for private resource access (e.g., RDS).
- VPC interface endpoints ensure private access to services like S3/DynamoDB.
- Enhances security by keeping traffic within the AWS network.
Memory trick: VPC for private access, Endpoints for private service roads.