AWS

Amazon Web Services

Lambda Java samples:

User credentials

Instead of sharing the credentials of the AWS account root user, create individual IAM users, granting each user only the permissions they require.

Follow the best practice of using the root user only to create your first IAM user.

There are two types of credentials:

Serverless blog web application architecture

IPv6 info

Lambda authorizer (API gateway)

A lambda authorizer (API gateway) requires a resource based policy statement, with principalId and policy document.

JSON example

   1 {
   2   "principalId": "user|12345",
   3   "policyDocument": {
   4     "Version": "2012-10-17",
   5     "Statement": [
   6       {
   7         "Action": "execute-api:Invoke",
   8         "Effect": "Allow",
   9         "Resource": "arn:aws:execute-api:region:account-id:api-id/stage/METHOD/path"
  10       }
  11     ]
  12   },
  13   "context": {
  14     "stringKey": "value",
  15     "numberKey": 123,
  16     "booleanKey": true
  17   }
  18 }

Add inbound rule in RDS to a lambda function

   1 RDS_DB_PORT=5432
   2 RDS_SG=$(aws rds describe-db-instances --db-instance-identifier rds-instance-id \
   3     --query "DBInstances[0].VpcSecurityGroups[*].VpcSecurityGroupId" --output text)
   4 echo "RDS security group $RDS_SG"
   5 
   6 LAMBDA_SG=$(aws lambda get-function-configuration --function-name lambda-function-name \
   7     --query "VpcConfig.SecurityGroupIds[*]" --output text)
   8 echo "Lambda function security group $LAMBDA_SG"
   9 
  10 aws ec2 authorize-security-group-ingress --group-id $RDS_SG \
  11     --protocol tcp -port $RDS_DB_PORT --source-group $LAMBDA_SG

Stuff

aws lambda list-functions
aws ecs describe-task-definition -- task-definition 
# a task definition sets a docker image for a task/container

AWS (last edited 2026-08-29 08:54:29 by vitor)