2 Respostas
- Mais recentes
- Mais votos
- Mais comentários
0
Turns out the problem was very simple: the "VpcConfig" statement in my CF template needed to be under the lambda's "Properties" config section.
respondido há um ano
0
You need to add a policy to your function that allows the lambda to attach/detatch a network interface:
SomeLambda:
Type: AWS::Serverless::Function
Properties:
# content ommitted
Policies:
- Statement:
- Sid: AttachToVpc
Effect: Allow
Action:
- ec2:CreateNetworkInterface
- ec2:DescribeNetworkInterfaces
- ec2:DeleteNetworkInterface
Resource: "*"
# more content ommitted
respondido há um ano
Conteúdo relevante
- AWS OFICIALAtualizada há 3 anos
- AWS OFICIALAtualizada há um ano
Thanks for the very quick response! In fact this doesn't seem necessary (in my case the managed policy AWSLambdaVPCAccessExecutionRole was attached to the lambda automatically), but your answer did lead me to the real problem, which was that my "VpcConfig" statement was outside the "Properties" heading, and thus effectively invisible to CF.