AWS Certified Developer – Associate (DVA-C02)Troubleshooting and MonitoringMedium

A developer is creating a new AWS Lambda function that needs to access a private Amazon RDS instance within a VPC. The Lambda function is currently failing to connect to the database, resulting in connection timeout errors. The EC2 security group attached to the RDS instance allows inbound traffic on port 5432 from the security group associated with the Lambda ENI. Which of the following is the MOST likely reason for the connection failure?

  1. AThe Lambda function is not configured to run within the same VPC as the RDS instance.
  2. BThe Lambda function's execution role does not have permissions to access Amazon RDS.
  3. CThe RDS instance is not publicly accessible, and the Lambda function is attempting to connect via a public endpoint.
  4. DThe network ACL (NACL) associated with the Lambda function's subnet is blocking outbound traffic to the RDS instance.
Show answer & explanation

Correct answer: A. The Lambda function is not configured to run within the same VPC as the RDS instance.

To access resources within a VPC, a Lambda function must be configured to run within that VPC. If it's not, it runs in the Lambda service's internal VPC and cannot directly access private resources in your VPC, leading to connection timeouts when attempting to reach an RDS instance.

Why the other options are wrong

  • B. Permissions issues usually manifest as 'Access Denied' errors, not connection timeouts. The Lambda execution role needs VPC access permissions, but the core issue here is network connectivity.
  • C. The question states the RDS instance is 'private' and the error is a 'connection timeout'. If the Lambda function is not in the VPC, it won't even reach the public/private endpoint distinction to time out on a private one.
  • D. While a NACL could block traffic, the most common and fundamental reason for a Lambda to fail connecting to a private VPC resource is that it's not configured to be *in* the VPC at all.

Lambda VPC Connectivity

To access resources within an Amazon Virtual Private Cloud (VPC), an AWS Lambda function must be configured to execute within that VPC. This involves attaching the function to specific subnets and security groups within the VPC.

  • Required for access to private VPC resources (RDS, EC2, ElastiCache).
  • Lambda creates Elastic Network Interfaces (ENIs) in specified subnets.
  • Requires specific IAM permissions for VPC access.

Memory trick: Lambda must 'Enter' the VPC to see its 'Private' friends like RDS.

More Troubleshooting and Monitoring questions