AWS Lambda
AWS Lambda is a serverless compute service: you upload a function and AWS runs it when an event happens, scaling from zero to thousands of parallel executions and charging only for the requests and the execution time. There are no servers, AMIs or operating systems to patch.
Key concepts #
- Function: the code with its handler, runtime (Python, Node.js, Java, .NET, Ruby, Go through custom runtimes or container images) and settings such as memory (from 128 MB to 10,240 MB, which also determines the CPU), timeout (up to 15 minutes) and environment variables.
- Triggers (event sources): API Gateway, S3 events, SQS queues, SNS topics, DynamoDB streams, EventBridge schedules, CloudWatch Logs and more. A function URL gives a function its own HTTPS endpoint.
- Execution role: the IAM role that gives the function permissions to call other AWS services.
- Cold start: the extra time to start a new execution environment. Provisioned concurrency and SnapStart reduce it.
- Layers share libraries between functions, versions and aliases allow controlled releases, and concurrency limits protect downstream systems.
- A function can run inside a VPC to reach private resources such as RDS databases. It then needs a NAT Gateway for Internet access.
- Packages are deployed as a ZIP file (from S3 or direct upload) or as a container image from ECR.
Pricing #
Per request and per execution time (GB-seconds, depending on the memory), plus a monthly free tier. See the Lambda pricing.
With Terraform #
The resources are aws_lambda_function, aws_lambda_permission, aws_lambda_event_source_mapping, aws_lambda_alias and aws_lambda_function_url, plus the aws_iam_role for the execution role.
See also: AWS ECS and AWS Fargate for containers, AWS Step Functions to orchestrate functions.