enabling-lambda-vpc-internet-access

par aws

Enables internet access for AWS Lambda functions deployed in VPC subnets by creating NAT Gateway infrastructure, configuring public/private subnet routing, and…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill enabling-lambda-vpc-internet-access

Enabling Lambda VPC Internet Access

Overview

Domain expertise for enabling internet access from AWS Lambda functions running inside VPC private subnets. Lambda functions in a VPC cannot receive public IP addresses, so outbound internet access requires NAT Gateway infrastructure that routes traffic from private subnets through a public subnet to an Internet Gateway.

Enable internet access for a VPC Lambda function

To set up NAT Gateway infrastructure and configure routing for a Lambda function that needs internet access, follow the procedure exactly. See Lambda VPC internet access setup procedure.

Troubleshooting

NAT Gateway not working

Verify the route table associated with the Lambda subnets has a 0.0.0.0/0 route pointing to the NAT Gateway. See the full procedure for details.

Lambda function timeout

Check that security group outbound rules allow the necessary ports and that both the NAT Gateway and Internet Gateway are properly configured.

Network changes not taking effect

VPC networking changes can take 1–2 minutes to propagate. Wait before testing after creating a NAT Gateway or updating route tables.

Route table association issues

Confirm the Lambda function's subnets are associated with the route table that has the 0.0.0.0/0 route to the NAT Gateway.

Plus de skills de aws

agents-build
aws
Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource…
official
agents-connect
aws
À utiliser lors de la connexion de votre agent à des API, outils ou services externes via Gateway, ou pour restreindre l'accès aux outils avec des politiques Cedar. Gère la configuration de la passerelle, la cible…
official
agents-debug
aws
Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes.…
official
agents-deploy
aws
À utiliser lors du déploiement de votre agent sur AWS, ou lorsqu'un déploiement a échoué. Gère la validation pré-vol, le diagnostic des erreurs CDK/IAM/quota, la gestion des versions, le rollback,…
official
agents-get-started
aws
À utiliser lorsqu'un développeur souhaite créer un nouveau projet d'agent ou démarrer avec AgentCore. Gère la sélection du framework, le scaffolding du projet, le premier déploiement, et…
official
agents-harden
aws
À utiliser lors de la préparation de votre agent pour la production — cadrage IAM, authentification entrante (JWT, SigV4), gestion des secrets, optimisation du démarrage à froid, cycle de vie des sessions, taux…
official
agents-pay
aws
Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official