Review Lambda X-Ray tracing configuration

Configure tracing mode and permissions to investigate Lambda request latency and errors.

Description

Insufficient X-Ray trace data makes Lambda latency and error analysis harder. Active mode automatically sends traces for sampled requests. Current PassThrough mode propagates tracing context without automatically sending traces, although function code can send traces separately.

Potential impact

  • Request paths and latency across multiple services can be harder to identify.
  • Incident response may take longer when logs and metrics alone cannot narrow down the cause.

Remediation

Set tracing_config.mode to Active when automatic Lambda tracing is needed. Grant X-Ray write permissions to the execution role and configure required application instrumentation. Verify trace collection and complement sampled traces with logs and metrics.

Examples

These excerpts compare tracing settings. Supply the deployment file, execution role, supported runtime, and other function settings separately.

Before

hcl
resource "aws_lambda_function" "example" {
  filename      = "lambda_function_payload.zip"
  function_name = "lambda_function_name"
  role          = aws_iam_role.iam_for_lambda.arn
  handler       = "exports.test"

  tracing_config {
    mode = "PassThrough"
  }
}

After

hcl
resource "aws_lambda_function" "example" {
  filename      = "lambda_function_payload.zip"
  function_name = "lambda_function_name"
  role          = aws_iam_role.iam_for_lambda.arn
  handler       = "exports.test"

  tracing_config {
    mode = "Active"
  }
}

The revision uses Active tracing. It does not record every invocation, and detailed tracing of outgoing service calls may require instrumentation in the code.

References