A developer is troubleshooting an AWS Lambda function that intermittently fails with a 'Task timed out' error, even though the function's configured timeout is 30 seconds. Upon inspecting CloudWatch Logs, they observe that the function often completes its core logic within 10-15 seconds but sometimes hangs for an extended period before the timeout. The Lambda function accesses resources within a VPC. What is the MOST likely cause of this intermittent timeout issue?
- AInsufficient memory allocated to the Lambda function, causing it to throttle.
- BThe Lambda function is failing to establish network connectivity to VPC resources due to incorrect security group rules or an overloaded NAT Gateway.
- CThe Lambda execution role lacks permissions to invoke other AWS services, causing a silent failure and timeout.
- DThe Lambda function is running out of disk space in its /tmp directory, leading to I/O errors.
Show answer & explanationAnswer & explanation
Correct answer: B. The Lambda function is failing to establish network connectivity to VPC resources due to incorrect security group rules or an overloaded NAT Gateway.
Intermittent 'Task timed out' errors, especially when core logic completes quickly but the function hangs, are often indicative of network connectivity issues within a VPC. If the Lambda cannot reach required VPC resources or cannot send its results back due to network problems (e.g., security groups, NAT Gateway), it will eventually time out.
Why the other options are wrong
- A. Insufficient memory typically leads to 'Out of memory' errors or increased duration, but not usually a silent hang before timeout after core logic completion.
- C. Lack of permissions usually results in 'Access Denied' errors, not a silent hang and subsequent timeout.
- D. Running out of disk space would typically result in specific disk-related errors, not a generic 'Task timed out' after core logic completion.
Lambda VPC Timeout
Lambda functions configured for VPC access can experience timeouts if network connectivity to VPC resources or the internet (via NAT Gateway) is improperly configured, leading to execution hangs.
- Security groups or NACLs can block traffic.
- Subnet routing to NAT Gateway or internet gateway is critical for external access.
- Elastic Network Interface (ENI) creation/deletion overhead can also contribute to cold start latency.
Memory trick: Lambda's network woes often lead to timeout woes.