- Newest
- Most votes
- Most comments
Hi,
The ENIs used by Lambda functions you attach to your VPCs are a special type of ENI called a hyperplane ENI. They are owned by the Lambda service and shouldn't be possible for you to modify directly to choose via Elastic IP a given address that you prefer.
See :
- official doc: https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html#configuration-vpc-enis
- this article: https://aws.plainenglish.io/lambda-hyperplane-enis-03af1dcd6845 for more details
Didier
I. Service Quotas Dashboard For testing in eu-central-1, check the service limits to make certain you are not exceeding limits for ENIs, Ips or EIPs in the region. Use the "AWS Service Quotas Dashboard" to verify.
Source Service Quotas Dashboard https://us-west-2.console.aws.amazon.com/servicequotas/home?region=us-west-2#
II. Lambda functions and Hyperplane ENI invocation
- Hyperplane ENIs are not directly visible to you, and you don’t need to configure or manage them. However, knowing how they work can help you to understand your function’s behavior when you attach it to a VPC.
- For new functions, while Lambda is creating a Hyperplane ENI, your function remains in the Pending state and you can’t invoke it. Your function transitions to the Active state only when the Hyperplane ENI is ready, which can take several minutes.
Source: Giving Lambda functions access to resources in an Amazon VPC https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html#configuration-vpc-enis
III. Logs. Logs Logs. Enable Enhanced Monitoring. "You can perform queries to help you more efficiently and effectively respond to operational issues."
*Source: * Analyzing log data with CloudWatch Logs Insights. https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AnalyzingLogData.html
IV. YouTube video AWS EC2 Technical Salon with Mayumi Hiramatsu and Dheerendra Talur Hyperplane: An elastic, distributed network appliance. https://www.youtube.com/watch?v=GkYGo1M3vyc
Channel: Inside Amazon - About What unites our employees across teams and geographies is that we are all striving to delight our customers and make their lives easier. The scope and scale of our mission drives us to seek diverse perspectives, be resourceful, and navigate through ambiguity. Inventing and delivering things that were never thought possible isn't easy, but we embrace this challenge every day.
By working together on behalf of our customers, we are building the future one innovative product, service, and idea at a time. Are you ready to embrace the challenge? Come build the future with us. https://www.youtube.com/@insideamazonvideos
V. VPC Section > "So it is best practice to assign the Lambda to three private subnets inside the VPC, then connect the private subnets to go through a NAT in one of the public subnets. The NAT will then have a public IP and send all traffic to the Internet Gateway."
Source:
Ask the Expert: 13 AWS Lambda design considerations you need to know about
https://www.jeffersonfrank.com/insights/aws-lambda-design-considerations/
answered 2 years ago
Relevant content
asked 4 years ago
asked 3 years ago
- AWS OFFICIALUpdated 2 years ago

Hi Didier, I already can do it in other regions. When we put lambda into a VPC and attach elastic ip address to related public subnet all request will send on elastic ip address.
I guess it could cause problem on high traffic but practically we can attach elastic ip to ENI that attached to Lambda.
@Aren Sade, Didier's reply is correct. Lambda's hyperplane ENIs are not designed for you to modify directly. Lambda can also provision additional ENIs for scaling or maintenance purposes, or delete existing ones without involving you, further highlighting the infeasibility of you controlling elastic IP associations for them. Instead, you should set up a NAT gateway for controlling the elastic IP(s) the Lambda's outbound connections to the internet will originate in.