13 ms·
AWS Lambda function URLs: Built-in HTTPS endpoints
- notyourday 5y agoWhere are at least ACL and green header filtering?! This is 2022. If this is not supported at the entry point the product should be sent back to design.
- brentmitchell25 5y agoMy previous company had thousands of lambda functions and api gateway integrations and near impossible to do anything with confidence when you starting integrating with all the other cloud offerings. My current environment is similar scale, but all containers it's night and day difference when it comes to confidence. We can move 100x faster when you can reproduce environments locally or separate account in seconds or minutes with everything baked in. I don't think I could move back, but hey at least this might eliminate a few API Gateway integrations.
- yuppie_scum 5y agoCan’t you run local lambda in Localstack or something like that?
- brentmitchell25 5y agoIt's alright, but continued to find bugs and edges cases with it. The challenge is when there are a bunch of integrations cross-accounts, eventbridge, cloudwatch, etc. that you just can't emulate well locally. Or once you do, it doesn't work a month from now because things change (e.g. a developer is using a new feature that isn't supported by localstack or something). In container land, you don't have to worry about these cloud integrations. You just spin up the services you want in a docker compose file, k8s deployments, helm charts, etc. and you basically have everything without having to worry about being a AWS specific blackbelt guru expert.
- yuppie_scum 5y agoYou just have to be a Kubernetes black belt guru expert. It is better but it’s not all rainbows and butterflies on this side of the fence either. Generally it boils down to the stack taking way too many resources to run locally, or still needing access to various persistent data stores, etc..
- brentmitchell25 5y agoYou don't have to run kubernetes for containers, but even then, only 4 of our engineers know and operate kubernetes. It allows us to enforce routing, authn, and authz standards everywhere (and test locally). Application engineers only need a simple command to run their stack and some code templates to build and test applications. Not much knowledge is typically needed on their part. Is it always perfect? No, but it's a lot simpler then wiring up a bunch of vendor specific offerings.
- rimutaka 5y agoI use https://github.com/rimutaka/lambda-debug-proxy https://github.com/rimutaka/lambda-debug-proxy to run Lambdas locally while still being part of the AWS pipeline. It eliminates the need to emulate the input/output. That tool is for Rust only, but there is no reason why it can't be ported to other languages.
- rurp 5y agoMy work is heavy serverless and nobody I work with has had any luck with Localstack, myself included. It's just too limited, fragile, and buggy to work for anything we do. Our stack isn't anything particularly unusual either, it's just that if you are using Lambdas heavily they are probably tied in with a whole bunch of other AWS services in ways that are hard to replicate locally; and Localstack just isn't up to the task. While there are some nice benefits to serverless workloads on AWS, local development and reproing production bugs are major weak points.
- mitch3x3 5y agoSam local?
- merek 5y agoSAM local isn't a perfect emulation of the cloud based lambda environment. This is why AWS SAM added the "Accelerate" feature, making it easier to deploy code to the cloud for testing purposes. https://aws.amazon.com/blogs/compute/accelerating-serverless-development-with-aws-sam-accelerate/ https://aws.amazon.com/blogs/compute/accelerating-serverless...
- dsanchez97 5y agoIf you are using Python and looking for a framework to quickly get your Aws Lambda Functions up and running, try out the framework I am developing. It is still in the early stages, but it has some optimizations that make it simple to do things like use 3rd party packages. If you are interested, a good place to start are the docs on how to connect functions to Api Gateway https://staging.cdevframework.io/docs/examples/httpendpoints/ https://staging.cdevframework.io/docs/examples/httpendpoints.... If you want the developer experience of Django with the benefits of Serverless Compute platforms check it out!
- paxys 5y agoNice! Of course this has always been possible to do, but removing the API Gateway dependency will make simple use cases a lot simpler.
- laurencerowe 5y agoIt's super frustrating that AWS has no equivalent to GCP's Cloud Run which offers fast startup, scales to zero but offers the flexibility and simply exposing HTTP to the container it runs. Lambda has scale to zero and fast startup but its custom RPC interface (presumably an outgrowth of its batch processing origins) does not support streaming responses, has awkward response size limits, and prevents multiple requests from being executed concurrently on the same instance (so caches cannot be shared.) Fargate provides the flexibility from simply running an HTTP server inside a container but at the cost of slower startup and no ability to scale to zero.
- recuter 5y agoFargate is what, 3 cents an hour? And of course it can scale to zero, it uses standard autoscaling groups. It will scale however you want, heck use custom scaling logic with your control plane running in Lambda :) https://docs.aws.amazon.com/autoscaling/application/userguide/application-auto-scaling-step-scaling-policies.html https://docs.aws.amazon.com/autoscaling/application/userguid...
- suprfsat 5y agoFor 3 cents a _month_ Cloud Run can store over a gigabyte of containers and run them on-demand.
- laurencerowe 5y agoMy understanding was that you would get error responses from the load balancer if you set Fargate to scale all the way down to zero: https://serverfault.com/a/951440 https://serverfault.com/a/951440
- wahnfrieden 5y agoscale to zero means without downtime
- otterley 5y agoThe closest analogous service that runs containers in the simplest manner possible would be AWS App Runner: https://aws.amazon.com/apprunner/ https://aws.amazon.com/apprunner/ It scales almost to zero (minimum cost is the memory dedicated to a single task).
- oneupwallstreet 5y agoThis is fantastic, I'm making an iOS application that is 100% serverless. Having no servers feels great but managing API Gateway endpoints is annoying. I don't know about performance but Google Cloud Functions definitely had an edge there, because I believe they had native function endpoints since launch. I wonder if it's worth changing my current API Gateway endpoints to the built in Lambda URL's, since I haven't launched yet.
- anshumankmr 5y agoFor someone who has only worked with Cloud Functions on GCP, can someone explain to me how is this different?
- mhoad 5y agoI was wondering the same, I only know the GCP ecosystem and there I already consider cloud functions to be a “legacy” choice relative to Cloud Run where I no longer need to have a 1 to 1 relationship between requests and invocations along with a bunch of other advantages. Every time I peek over into the AWS ecosystem I’m very glad I don’t have to work in it. This seems like it’s multiple years behind what GCP has unless I’m missing something obvious?
- ep103 5y agoSo its a public https endpoint, with no built in throttling? This... doesn't seem like a ddos vulnerability to anyone? All it would take is one script kiddie to rack up an unsuspectingly large aws bill, no?
- politelemon 5y agoThere's a paragraph dedicated to this in TFA.
- ep103 5y agoThat wasn't very polite, mr. lemon. Also, I'm not sure what you're referring to, having read it twice.
- AndrewDucker 5y agoI wish that Azure Functions had this. I have a function triggered by Cron once a day that goes wrong about once a month. I trigger it again using the debugging tools, but it would be nice if I could just hit a URL to trigger it again.
- vlucas 5y agoI use EasyCron (https://www.easycron.com https://www.easycron.com) for some simple scheduled tasks. Basically just hit a URL on a set schedule. I include a specific API key in there and the URL is not discoverable, so it works well for me. It's a nice way to do cron/scheduled tasks without any extra work. Just deploy another serverless endpoint and have something else hit that on a schedule. If anything goes wrong, EasyCron notifies me and I just hit the URL directly to re-run the task. Simple and crude, but highly effective and near zero effort.
- Jochim 5y agoUnless I'm misunderstanding your use case, Azure functions have had HTTP triggers[0] for years, the bindings documentation even calls out support for binding different trigger types to the same function. I was actually surprised that AWS has only just received support. [0] https://docs.microsoft.com/en-us/azure/azure-functions/functions-bindings-http-webhook-trigger?tabs=in-process%2Cfunctionsv2&pivots=programming-language-csharp https://docs.microsoft.com/en-us/azure/azure-functions/funct...
- AndrewDucker 5y agoI don't believe you can have multiple triggers for the same function, so I can't bind it to a time trigger and a http trigger. If you can find an example for doing otherwise I'd be delighted!
- Jochim 5y agoI dug a little further and it looks like you're correct, I had mixed up the concepts of triggers and input bindings after reading the documentation that claims: > You can mix and match different bindings to suit your needs. Bindings are optional and a function might have one or multiple input and/or output bindings.[0] However, there is some documentation explaining how to execute a function that does not have a HTTP trigger via HTTP[1]. The example uses the function app's master key though, it'd be interesting to see if that's a requirement or if you could use a key scoped only for invocation of the specific function. [0]https://docs.microsoft.com/en-us/azure/azure-functions/functions-triggers-bindings?tabs=csharp https://docs.microsoft.com/en-us/azure/azure-functions/funct... [1]https://docs.microsoft.com/en-us/azure/azure-functions/functions-manually-run-non-http https://docs.microsoft.com/en-us/azure/azure-functions/funct...
- miyuru 5y agoAlthough it doesn't mention in the blog post, the HTTPS endpoints are dual-stacked. Seems like AWS is actually launching new endpoints with IPv6 support by default now.
- lysecret 5y agoReally Cool addition. I just moved my lambdas from API Gateway to ALB (because of API G limit to 30s). I also use Serverless framework. It was a day of work, but developing with ALB is a bit more of pain. Maybe this would be better. Are there any timeout or mb constraints on these URLs?
- nhoughto 5y agoYeah didn’t see anything about timeouts or body size limits.. is a good question. Lambda + apigw vs invoke vs alb vs the rest having different limits has got me a few times.
- lysecret 5y agoCould you elaborate a bit? I find this really interesting. My story is: I started with invoke (with boto3) then I wanted some more abstraction and use normal Requests. So i moved them to serverless framework with API Gateway. Then the 30 sec timeout became an issue (I do data engineering stuff). So i moved them to ALB. And now everything runs, but the ALB serverless support isn't great. (why do i have to give everything a unique priority aaahh :D)
- nhoughto 5y agoSo lambda invoke direct via api has 6mb limit: https://docs.aws.amazon.com/lambda/latest/dg/gettingstarted-limits.html https://docs.aws.amazon.com/lambda/latest/dg/gettingstarted-... But api gw is 10mb, not for lambda tho, confuse: https://docs.aws.amazon.com/apigateway/latest/developerguide/limits.html https://docs.aws.amazon.com/apigateway/latest/developerguide... Use s3 object lambda and have no limit to push to s3 with logic, adds a bit of latency tho https://aws.amazon.com/blogs/aws/introducing-amazon-s3-object-lambda-use-your-code-to-process-data-as-it-is-being-retrieved-from-s3/ https://aws.amazon.com/blogs/aws/introducing-amazon-s3-objec... All historical but hard to understand the limits as a poor user.. Ended up going with cloudflare workers for s3 uploads with extra logic just to avoid the unknown, workers are great btw.
- Hardik_Shah 5y ago
- tealpod 5y agoToday we are coincidentally releasing the beta for https://tinyfunction.com/ https://tinyfunction.com/ TinyFunction is the simplest NodeJS and Python function deployer. All functions are deployed in AWS.
- GoodJokes 5y ago
- azth 5y agoCan anyone using lambda at scale pitch in regarding costs? It seems companies are using it to build pipelines which could be much cheaper by writing full services as opposed to small functions that you pay for per invocation.
- cebert 5y agoI don’t work at a startup, but am working on a startup-like project where we are building a greenfield application that allows law enforcement officers to collaboratively edit reports such as accident reports. The entire API is built on Lambda, S3, and DynamoDB. The experience has been wonderful so far. We have a large dev team (~12-16 devs) working on the project and our dev account costs are only $100-250/mo. We even deploy each PR to the cloud to run automated tests against. Our production costs have been very manageable too. Lambda/serverless has been great for us. Our organization is relatively new to building SaaS cloud apps and doesn’t have the most mature devops practices (we’re growing there). Building this app on Lambda and DynamoDB and letting AWS help us with most of the scaling has really been a win for the team.
- ShakataGaNai 5y agoThey are fast to setup and require zero care and feeding. That's the big "time to market" cost. Beyond that, depends on your use case. I love using Lambda for webhooks that may be called anywhere from a few times a day to thousands of times per day. Once they get to the point of being "oh wow, this one lambda is expensive", you can clearly afford the budget to move it to a real server. But below that $20/mo mark (which is more than 5 million invocations of a small function) - you're golden.
- ijidak 5y agoMy lambda bill is $4,000 per month for 21,000,000 invocations per month. Something seems off compared to your numbers. Maybe the length of a single execution?
- theshrike79 5y agoLambda cost is invocation time * memory size pretty much. If your lambda bill is $4k a month, either your functions run multiple seconds each or you're using multiple gigs of memory.
- rmbyrro 5y agoAmazing, now I don't have to pay API Gateway to do just an HTTP routing.
- k__ 5y agoAs far as I know, you can call the Lambda via the AWS SDK.
- throwaway2016a 5y agoYou can but that has security + protocol implications and is not as useful for general web consumers. This seems better IMHO.
- nhoughto 5y agoYeah you need an aws iam identity to call lambda invoke, for public consumer this is better.
- websap 5y agoYou could always use an ALB? ALB has some nice extensions as well.
- giaour 5y agoDon't ALBs have a minimum hourly cost? Last time I looked into this, you couldn't run an ALB for less than ~$17/month. Definitely cheaper than API gateways for even a moderate amount of traffic, but API gateway costs scale down to zero for unused or rarely used endpoints.
- coredog64 5y agoWhat ALBs don’t have is a maximum payload size. :) Note: The “official” way to work around this is to write your large payload to S3 and then create a pre-signed S3 URL that you return to the caller instead.
- wnevets 5y agofinally. Having to setup a gateway is so cumbersome.
- scoot 5y agoClaudia.js is an absolute godsend when it comes to writing and deploying Lambda functions. Can't recommend it highly enough: https://www.claudiajs.com/ https://www.claudiajs.com/
- ankit70 5y agoHow is it different than cloudflare workers?
- ignoramous 5y agoCloudflare Workers is head and shoulders above AWS CloudFront Functions and Lambda@Edge [0], if you can fit your workloads in 50ms (CPU time) or 30ms (IO time). Workers is wayy cheaper, wayy faster [1]. Workers has 1MB script size limit (post compression), so that's there, too, and can run WASM or JS workloads (which CloudFront Functions can't, but Lambda@Edge can). As for AWS Lambda Function URLs: Well, it isn't comparable to Workers at all. But if my use case fits Workers, then that's what I'd would prefer. In fact, I've gone many lengths to make my workload fit Workers. Deno Deploy is another viable alternative. [0] https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/edge-functions.html https://docs.aws.amazon.com/AmazonCloudFront/latest/Develope... [1] dated, but relevant: https://medium.com/@zackbloom/serverless-pricing-and-costs-aws-lambda-and-lambda-edge-169bfb58db75 https://medium.com/@zackbloom/serverless-pricing-and-costs-a...
- vlovich123 5y agoJust some small corrections. I think you mean 30s of CPU time for unbound workers? Time spent waiting for i/o can be “infinite”. I think maybe you’re referring to billing where we bill on wall clock time for unbound workers (vs CPU time for bundled workers). For proxied requests, billing even stops once you hand back the Response object. If you need more than 1MB of script size, please reach out to Cloudflare support.
- ShakataGaNai 5y agoOP meant 30/50 ms under the guise of "Workers is wayy cheaper, wayy faster". You can have unbounded workers that do whatever you want. But the cheap Bundled workers need to stay under 50ms https://developers.cloudflare.com/workers/platform/limits/#worker-limits https://developers.cloudflare.com/workers/platform/limits/#w...
- petercooper 5y agoVery pleased by this addition! :-) Note that it creates special .on.aws URLs so if you want to use your own domain to future proof the endpoint (against linkrot if you ever leave AWS, say) you'll want to set up a redirect/proxy for yourself (whereas API Gateway does custom domains). Also an interesting note from the docs about how said URL is generated: "Because this process is deterministic, it may be possible for anyone to retrieve your account ID from the <url-id>." I don't know how much of a problem this could be, but it's worth being aware of.
- taf2 5y agoshould be able to add these as origin's behind cloudfront since it support multiple origins... /lambda/* could be routed to your functions /* everything else your main app
- alexhf 5y agoIn my opinion, AWS account IDs are not sensitive information.
- otterley 5y agoNor does AWS believe so: https://www.lastweekinaws.com/blog/are-aws-account-ids-sensitive-information/ https://www.lastweekinaws.com/blog/are-aws-account-ids-sensi...
- chc 5y agoYeah, account IDs aren't actually publicly listed, but should be treated as such. No part of your security should rest on an AWS account ID staying secret.
- sorry_outta_gas 5y agothey are useful for social engineering and phishing
- bikingbismuth 5y ago
- euph0ria 5y agoIs it possible to front this with your own domain using a CNAME or are the function URLs dynamically genrerated on each commit/upload/build?
- oxplot 5y agoYou can always proxy it (e.g. Cloudflare).
- ShakataGaNai 5y agoFor a lot of use cases if you proxy it through something external like Cloudflare, you might as well just write the code in Cloudflare Functions. Even faster as no proxying will be required.
- oxplot 5y agoYou can't run a docker images on Cloudflare functions, nor can you run a code with 10GB size.
- paxys 5y agoYes, but you'll have to either set up a proxy or do a client-side redirect.
- aeyes 5y agoYou can't use your own domain/certificate. If you CNAME it the cert will be invalid.
- JoshTriplett 5y agoIt sounds like you can get a stable URL for a function, but it'll still be a Lambda URL. I'd love to use this with a custom domain, without having to use an API Gateway.
- nl 5y agoHow is it that my UX looks completely different to the blog post? I don't have advanced settings. Instead I have to go "Configuration->Function URL" to find this.
- zozbot234 5y agoAWS Lambda has now gone full PHP. Never go full PHP.
- tored 5y agoWe live in such bizarre time, things that technology already solved in the past is now considered innovative.
- joeframbach 5y agoNot sure I understand what you mean, can you elaborate?
- russtrotter 5y agoReference to the movie quote in "Tropic Thunder" from Robert Downey Jr.s character.
- mnapoli 5y agoLast step: https://bref.sh https://bref.sh
- supahfly_remix 5y agoIs this similar to a cgi-bin script?
- tyingq 5y agoCloser to fastcgi, but yes.
- cobertos 5y agoNow if only you could add an EIP to a lambda function without a VPC NAT and the $20/mo minimum that comes with it.
- coredog64 5y agoOr just allow an IPv6 address to be attached.
- pugz 5y agoIt's not an official AWS offering, but there is this project that can automatically add EIPs to VPC-attached Lambda functions for you. Then you don't need the NAT gateway. https://github.com/glassechidna/lambdaeip https://github.com/glassechidna/lambdaeip
- epolanski 5y agoI'm confused, the whole news is that you can directly call lambdas without having to go through API gateway, like you do on cloudflare?
- justin_oaks 5y agoYes, that's the whole news. It's exciting to those of us who had to live without that feature until now.
- dlhavema 5y agoI think the idea here is that you don't have to set up API gateway anymore to get HTTP/API access to your lambda. You still can of course but it's one less thing you have to do. Like another comment said you can expose it through IAM/SDK but then you're getting random permissions credentials whatever out to the world as well.
- pojzon 5y agoAre those function urls backed by WAF and AWS Shield ? If not -> get prepared for huge bill of ddosed function invocations. I hope we can at least attach something to those urls.
- recuter 5y agoYou can and should limit the number of parallel invocations and as a result your maximum bill. If you want ddos protection and proper rate limiting amazon will happily charge you for it several different ways. Maybe you can hide these urls behind cloudflare if you're penny pinching..
- icecap12 5y agoI was thinking the same. What we have here is a security nightmare. You have executable code on globally unique URLs with no protective mechanisms in front of it except for the ability to do IAM. Yikes.
- astral303 5y agoNot for WAF. The original article states that you must use API Gateway if you want AWS WAF.
- joe_hoyle 5y agoIs it not possible to set the lambda url has an origin in CloudFront and get WAF protection that way? For all production workloads we typically have cloudfront in front of everything.
- daenz 5y agoVery happy to hear it has first-class alias support. Now if only they would allow per-alias environment variables...