AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium
A developer is writing an AWS Lambda function that needs to make HTTP requests to an external API. The external API requires a static IP address for whitelisting purposes. The Lambda function is currently deployed inside a VPC, but it does not have direct internet access. How can the developer configure the Lambda function to meet this requirement?
- AConfigure a NAT Gateway in a public subnet and route Lambda traffic through it.
- BDeploy the Lambda function in a public subnet with a public IP address.
- CUse a VPC Endpoint for the external API to bypass internet access.
- DAttach an Elastic IP address directly to the Lambda function's ENI.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure a NAT Gateway in a public subnet and route Lambda traffic through it.
Lambda functions deployed within a private VPC subnet require a NAT Gateway in a public subnet to access the internet. The NAT Gateway provides a static public IP address for outbound traffic, satisfying the whitelisting requirement of the external API.
Why the other options are wrong
- B. Deploying Lambda in a public subnet is not recommended for security reasons and may still require a NAT Gateway for outbound internet access if it's in a private subnet and needs to reach external services.
- C. VPC Endpoints are for accessing AWS services privately, not external third-party APIs.
- D. Elastic IPs cannot be directly attached to Lambda ENIs; they are associated with EC2 instances or NAT Gateways.
NAT Gateway for Lambda in VPC
A NAT Gateway enables instances in a private subnet of a VPC to connect to the internet or other AWS services, while preventing the internet from initiating connections to those instances.
- Allows outbound internet access for private subnets.
- Provides a static public IP address for egress traffic.
- Requires deployment in a public subnet.
Memory trick: Private Lambda needs NAT to chat with the static outside world.