A developer is building an application that integrates with a third-party service. This service requires a static IP address for its allowlist to permit incoming connections. The application will run on AWS Lambda functions in a VPC. How can the developer ensure that the Lambda functions access the third-party service from a consistent, static IP address?
- ADeploy the Lambda function in a private subnet and route outbound traffic through a NAT Gateway with an Elastic IP address.
- BAttach an Elastic IP address directly to the Lambda function.
- CConfigure the Lambda function to use a public IP address directly.
- DUse an API Gateway endpoint with a custom domain and a static IP.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploy the Lambda function in a private subnet and route outbound traffic through a NAT Gateway with an Elastic IP address.
When a Lambda function is in a VPC and needs to access the internet or external services, its outbound traffic goes through a NAT Gateway. By associating an Elastic IP address with the NAT Gateway, all outbound traffic from the Lambda function (which is in a private subnet) will originate from that static Elastic IP, satisfying the third-party service's allowlist requirement.
Why the other options are wrong
- B. Elastic IPs cannot be directly attached to Lambda functions. They are attached to EC2 instances or NAT Gateways.
- C. Lambda functions in a VPC do not directly get public IP addresses for egress; they use private IPs within the VPC.
- D. API Gateway is for incoming requests to the Lambda, not for outbound requests from Lambda to a third-party service.
Lambda Static Egress IP
To provide a Lambda function in a VPC with a static outbound IP address, deploy it in a private subnet and route its outbound traffic through a NAT Gateway that has an Elastic IP address associated with it.
- Lambda in VPC private subnet
- Outbound traffic via NAT Gateway
- NAT Gateway has an Elastic IP
Memory trick: Lambda goes private, then NATs out with a fixed IP.