A developer is troubleshooting an AWS Step Functions state machine that invokes a Lambda function. The state machine is failing with `Lambda.Unknown` errors, but the Lambda function's CloudWatch logs show successful executions with no errors. The Step Functions execution history shows the `Lambda.Unknown` error occurring immediately after the Lambda task state starts. What is the MOST likely root cause of this `Lambda.Unknown` error?
- AThe Lambda function's code has a runtime error that is not being logged to CloudWatch.
- BThe Lambda function is being throttled by AWS Lambda service limits.
- CThe Lambda function's timeout is shorter than the Step Functions task timeout, causing a mismatch.
- DThe Step Functions execution role lacks permissions to invoke the Lambda function.
Show answer & explanationAnswer & explanation
Correct answer: D. The Step Functions execution role lacks permissions to invoke the Lambda function.
A `Lambda.Unknown` error from Step Functions, especially when Lambda logs show success and the error occurs immediately, usually indicates a permissions issue where Step Functions cannot invoke the Lambda function. If Step Functions lacks the `lambda:InvokeFunction` permission for the target Lambda function, it cannot initiate the invocation, resulting in this generic 'unknown' error from Step Functions' perspective.
Why the other options are wrong
- A. If there was a runtime error in Lambda, it would typically be logged to CloudWatch by Lambda itself, contradicting the problem statement that logs show successful executions.
- B. If Lambda was throttled, Step Functions would typically receive a `Lambda.TooManyRequestsException` or `States.TaskFailed` with a throttling-related message, not `Lambda.Unknown`.
- C. If Lambda's timeout was shorter, the Lambda function would time out, and Step Functions would typically report a `Lambda.Timeout` error or `States.TaskFailed` with a timeout message, not `Lambda.Unknown`.
Step Functions Lambda.Unknown Error
The `Lambda.Unknown` error in AWS Step Functions often indicates that the Step Functions execution role lacks the necessary permissions to invoke the target Lambda function. It signifies an inability to initiate the Lambda task rather than an error within the Lambda function itself.
- Typically points to IAM permissions issues for the Step Functions execution role.
- Occurs when Step Functions cannot even *start* the Lambda invocation.
- Lambda logs often appear empty or show no related errors, as the invocation never truly begins from Lambda's perspective.
Memory trick: Step Function's 'Lambda Unknown': Check the Role's Invoke permissions, or it's simply gone.