SAM function without retention for failed asynchronous events

Configure retention for events that asynchronous invocations cannot process.

Description

A SAM function’s DeadLetterQueue is a target for asynchronous Lambda events that exhaust retries or age limits. Without a DLQ or failure destination, those events may be difficult to investigate or replay.

Potential impact

Missing failed inputs can delay incident investigation and recovery.

Remediation

Set Type and TargetArn under DeadLetterQueue for a standard SQS queue or SNS topic, or use an asynchronous failure destination. For an SQS event source, configure the source queue’s DLQ.

Examples

The examples add an asynchronous DLQ to an image-based function. Set the image URI, execution settings, and queue ARN to actual resources, and check delivery permissions.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  Function:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: account-id.dkr.ecr.region.amazonaws.com/ecr-repo-name:image-name
      ImageConfig:
        Command:
          - app.lambda_handler
        EntryPoint:
          - entrypoint1
        WorkingDirectory: workDir
      Tags:
        Type: AWS Serverless Function

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  Function:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: account-id.dkr.ecr.region.amazonaws.com/ecr-repo-name:image-name
      ImageConfig:
        Command:
          - app.lambda_handler
        EntryPoint:
          - entrypoint1
        WorkingDirectory: workDir
      Tags:
        Type: AWS Serverless Function
      DeadLetterQueue:
        TargetArn: arn:aws:sqs:us-east-1:123456789012:aaa
        Type: SQS

References