SAM function without active X-Ray tracing

Use Active mode for functions that need to initiate tracing.

Description

A SAM function’s Tracing: Active lets Lambda sample requests and initiate X-Ray tracing. Missing required trace data can make latency or cross-service problems harder to investigate.

Potential impact

Without another tracing mechanism, finding call paths and failure points can take longer.

Remediation

Set Tracing: Active when active tracing is needed. Grant X-Ray write permissions to any explicitly supplied execution role and instrument code for downstream calls that need tracing.

Examples

The examples enable active tracing for an image-based function. Set the image and execution configuration to suit the actual environment.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  Function:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: account-id.dkr.ecr.region.amazonaws.com/ecr-repo-name:image-name
      ImageConfig:
        Command:
          - app.lambda_handler
        EntryPoint:
          - entrypoint1
        WorkingDirectory: workDir
      Tags:
        Type: AWS Serverless Function

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  Function:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: account-id.dkr.ecr.region.amazonaws.com/ecr-repo-name:image-name
      ImageConfig:
        Command:
          - app.lambda_handler
        EntryPoint:
          - entrypoint1
        WorkingDirectory: workDir
      Tags:
        Type: AWS Serverless Function
      Tracing: Active

References