A developer is creating a new AWS Lambda function that needs to access a private Amazon RDS PostgreSQL database instance within a VPC. The Lambda function is configured with the correct VPC, subnets, and security groups. However, when the Lambda function attempts to connect to the database, it times out. Other EC2 instances in the same subnets can connect to the database without issues. What is the MOST likely cause of the Lambda function's connection failure?
- AThe Lambda function's execution role does not have the necessary permissions to access RDS.
- BThe RDS database's security group does not allow inbound connections from the Lambda function's security group.
- CThe subnets chosen for the Lambda function are private subnets without a NAT Gateway or VPC Endpoint for external services.
- DThe security group associated with the Lambda ENI does not allow outbound connections to the RDS port.
Show answer & explanationAnswer & explanation
Correct answer: B. The RDS database's security group does not allow inbound connections from the Lambda function's security group.
Since other EC2 instances in the same subnets can connect, the issue is not with the subnets or the database itself. If the Lambda function is timing out, it means the connection attempt is not being accepted by the RDS instance. The most common cause for this is that the RDS security group is not configured to allow inbound traffic from the security group associated with the Lambda function's Elastic Network Interface (ENI).
Why the other options are wrong
- A. IAM permissions are for AWS API calls, not direct database connections. Database access is controlled by security groups and database credentials.
- C. This scenario typically causes issues when Lambda needs to reach *external* services (e.g., S3, SNS, internet). For *internal* VPC resources like RDS, private subnets are correct, and a NAT Gateway/VPC Endpoint is not required for the connection to the DB itself.
- D. If the Lambda's security group blocked outbound connections, it wouldn't even be able to initiate the connection. The timeout indicates the connection was attempted but not accepted. Lambda's security group usually has outbound rules allowing all traffic (0.0.0.0/0).
Lambda VPC Connectivity
When a Lambda function is configured to run inside a VPC, it gets an Elastic Network Interface (ENI) in the specified subnets. Its network access is then governed by the security groups attached to that ENI and the network configuration of the VPC.
- Lambda ENIs have their own security groups.
- Communication with resources in the same VPC is via private IP addresses.
- Requires a NAT Gateway in private subnets for outbound internet access.
Memory trick: Lambda's VPC woes: Security Groups are the gatekeepers, both ways.