A client is deploying a new serverless application using AWS Lambda functions. The Lambda functions need to access a private Amazon RDS PostgreSQL database instance, which is located in a private subnet within a VPC. The Lambda functions also need to make outbound calls to external third-party APIs over the internet. The security team mandates that the Lambda functions should not have direct internet access within the VPC, and all outbound internet traffic must be routed through a NAT Gateway. How should the security architect configure the Lambda functions and VPC to meet these requirements?
- AConfigure the Lambda function with VPC access enabled, associate it with public subnets, and ensure the public subnets have an Internet Gateway attached.
- BConfigure the Lambda function with VPC access enabled, associate it with the private subnets of the RDS database, and ensure the private subnets have a route to a NAT Gateway in a public subnet.
- CConfigure the Lambda function without VPC access and use VPC Endpoints for RDS access. Provide internet access via a direct Internet Gateway attached to the Lambda execution role.
- DConfigure the Lambda function with VPC access enabled, associate it with private subnets, and attach an Internet Gateway directly to the private subnets' route tables.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure the Lambda function with VPC access enabled, associate it with the private subnets of the RDS database, and ensure the private subnets have a route to a NAT Gateway in a public subnet.
To access private resources like an RDS database in a VPC and also have outbound internet access via a NAT Gateway, Lambda functions must be configured for VPC access and placed in private subnets. These private subnets then need a route to a NAT Gateway located in a public subnet, which in turn has a route to an Internet Gateway.
Why the other options are wrong
- A. Placing Lambda in public subnets would expose it to inbound internet access, which is not desired, and might not use a NAT Gateway for outbound traffic.
- C. Lambda without VPC access cannot directly connect to a private RDS instance. Using VPC Endpoints for RDS is for private connectivity without traversing the internet, but it doesn't provide general internet access for third-party APIs.
- D. Attaching an Internet Gateway directly to private subnets would provide inbound internet access, violating the security mandate for no direct internet access and bypassing the NAT Gateway for outbound traffic.
Lambda VPC Configuration for Private Resources and Outbound Internet
To allow AWS Lambda functions to access resources within a private VPC (like RDS) and also connect to the internet for external APIs securely, the Lambda function must be configured to operate within the VPC's private subnets, with outbound internet access facilitated by a NAT Gateway.
- Lambda functions need VPC access enabled to connect to resources in a VPC.
- Place Lambda in *private* subnets to prevent inbound internet access.
- Private subnets must have a route to a NAT Gateway for outbound internet connectivity.
Memory trick: Lambda needs a 'Private Door' to the database and a 'NAT Gate' to the Internet.