Description
Lambda can send asynchronous events that exhaust retries or event-age limits to a separate target. Without a dead-letter queue or failure destination, those events may not be retained.
Potential impact
Losing the failed input can make investigation and reprocessing harder.
Remediation
Set DeadLetterConfig.TargetArn to a standard SQS queue or SNS topic, or configure an asynchronous failure destination. Check delivery permissions and retention and replay procedures. For an SQS event source, configure the source queue’s DLQ.
Examples
The examples add a DLQ for asynchronous invocations. Set LambdaRuntime to a supported runtime compatible with the function ZIP, and provide the target queue and execution-role permissions separately.
Before
AWSTemplateFormatVersion: '2010-09-09'
Description: VPC function.
Resources:
Function:
Type: AWS::Lambda::Function
Properties:
Handler: index.handler
Role: arn:aws:iam::123456789012:role/lambda-role
Code:
S3Bucket: my-bucket
S3Key: function.zip
Runtime: !Ref LambdaRuntime
Timeout: 5
TracingConfig:
Mode: Active
VpcConfig:
SecurityGroupIds:
- sg-085912345678492fb
SubnetIds:
- subnet-071f712345678e7c8
- subnet-07fd123456788a036
Tags:
- Key: Description
Value: VPC Function
- Key: Type
Value: AWS Lambda Function
After
AWSTemplateFormatVersion: '2010-09-09'
Description: VPC function.
Resources:
Function3:
Type: AWS::Lambda::Function
Properties:
Handler: index.handler
Role: arn:aws:iam::123456789012:role/lambda-role
Code:
S3Bucket: my-bucket
S3Key: function.zip
Runtime: !Ref LambdaRuntime
Timeout: 5
TracingConfig:
Mode: Active
VpcConfig:
SecurityGroupIds:
- sg-085912345678492fb
SubnetIds:
- subnet-071f712345678e7c8
- subnet-07fd123456788a036
Tags:
- Key: Description
Value: VPC Function
- Key: Type
Value: AWS Lambda Function
DeadLetterConfig:
TargetArn: arn:aws:sqs:us-east-1:123456789012:aaa