Lambda active X-Ray tracing not configured

Use Active mode when the function needs to initiate tracing.

Description

With TracingConfig.Mode set to Active, Lambda can sample requests for X-Ray tracing. PassThrough does not have the function initiate tracing on its own.

Potential impact

Missing required trace data can make latency and error investigations harder.

Remediation

Set TracingConfig.Mode: Active when active tracing is needed, and grant the execution role permission to write to X-Ray. Instrument downstream calls when those also need tracing.

Examples

The examples compare tracing modes for a function that invokes another function during stack creation. They use Node.js 22 and AWS SDK for JavaScript v3; prepare the execution role and target function separately.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: Lambda function with cfn-response.
Resources:
  primer:
    Type: AWS::Lambda::Function
    Properties:
      Runtime: nodejs22.x
      Role: arn:aws:iam::123456789012:role/lambda-role
      Handler: index.handler
      Code:
        ZipFile: |
          var { LambdaClient, InvokeCommand } = require('@aws-sdk/client-lambda')
          var response = require('cfn-response')
          exports.handler = function(event, context) {
              console.log("REQUEST RECEIVED:\n" + JSON.stringify(event))
              // For Delete requests, immediately send a SUCCESS response.
              if (event.RequestType == "Delete") {
                  response.send(event, context, "SUCCESS")
                  return
              }
              var responseStatus = "FAILED"
              var responseData = {}
              var functionName = event.ResourceProperties.FunctionName
              var lambda = new LambdaClient({})
              lambda.send(new InvokeCommand({ FunctionName: functionName }), function(err, invokeResult) {
                  if (err) {
                      responseData = {Error: "Invoke call failed"}
                      console.log(responseData.Error + ":\n", err)
                  }
                  else responseStatus = "SUCCESS"
                  response.send(event, context, responseStatus, responseData)
              })
          }
      Description: Invoke a function during stack creation.
      TracingConfig:
        Mode: PassThrough

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: Lambda function with cfn-response.
Resources:
  primer:
    Type: AWS::Lambda::Function
    Properties:
      Runtime: nodejs22.x
      Role: arn:aws:iam::123456789012:role/lambda-role
      Handler: index.handler
      Code:
        ZipFile: |
          var { LambdaClient, InvokeCommand } = require('@aws-sdk/client-lambda')
          var response = require('cfn-response')
          exports.handler = function(event, context) {
              console.log("REQUEST RECEIVED:\n" + JSON.stringify(event))
              // For Delete requests, immediately send a SUCCESS response.
              if (event.RequestType == "Delete") {
                  response.send(event, context, "SUCCESS")
                  return
              }
              var responseStatus = "FAILED"
              var responseData = {}
              var functionName = event.ResourceProperties.FunctionName
              var lambda = new LambdaClient({})
              lambda.send(new InvokeCommand({ FunctionName: functionName }), function(err, invokeResult) {
                  if (err) {
                      responseData = {Error: "Invoke call failed"}
                      console.log(responseData.Error + ":\n", err)
                  }
                  else responseStatus = "SUCCESS"
                  response.send(event, context, responseStatus, responseData)
              })
          }
      Description: Invoke a function during stack creation.
      TracingConfig:
        Mode: Active

References