2 Risposte
- Più recenti
- Maggior numero di voti
- Maggior numero di commenti
0
Turns out the problem was very simple: the "VpcConfig" statement in my CF template needed to be under the lambda's "Properties" config section.
con risposta un anno fa
0
You need to add a policy to your function that allows the lambda to attach/detatch a network interface:
SomeLambda:
Type: AWS::Serverless::Function
Properties:
# content ommitted
Policies:
- Statement:
- Sid: AttachToVpc
Effect: Allow
Action:
- ec2:CreateNetworkInterface
- ec2:DescribeNetworkInterfaces
- ec2:DeleteNetworkInterface
Resource: "*"
# more content ommitted
con risposta un anno fa
Contenuto pertinente
- AWS UFFICIALEAggiornata 2 anni fa
- AWS UFFICIALEAggiornata 3 anni fa
Thanks for the very quick response! In fact this doesn't seem necessary (in my case the managed policy AWSLambdaVPCAccessExecutionRole was attached to the lambda automatically), but your answer did lead me to the real problem, which was that my "VpcConfig" statement was outside the "Properties" heading, and thus effectively invisible to CF.