enabling-lambda-vpc-internet-access
aws/agent-toolkit-for-aws
How to install enabling-lambda-vpc-internet-access
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill enabling-lambda-vpc-internet-accessFull instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: enabling-lambda-vpc-internet-access description: Enables internet access for AWS Lambda functions deployed in VPC subnets by creating NAT Gateway infrastructure, configuring public/private subnet routing, and updating security groups. Use when a VPC-attached Lambda function cannot reach the internet. version: 1
Enabling Lambda VPC Internet Access
Overview
Domain expertise for enabling internet access from AWS Lambda functions running inside VPC private subnets. Lambda functions in a VPC cannot receive public IP addresses, so outbound internet access requires NAT Gateway infrastructure that routes traffic from private subnets through a public subnet to an Internet Gateway.
Enable internet access for a VPC Lambda function
To set up NAT Gateway infrastructure and configure routing for a Lambda function that needs internet access, follow the procedure exactly. See Lambda VPC internet access setup procedure.
Troubleshooting
NAT Gateway not working
Verify the route table associated with the Lambda subnets has a 0.0.0.0/0 route pointing to the NAT Gateway. See the full procedure for details.
Lambda function timeout
Check that security group outbound rules allow the necessary ports and that both the NAT Gateway and Internet Gateway are properly configured.
Network changes not taking effect
VPC networking changes can take 1–2 minutes to propagate. Wait before testing after creating a NAT Gateway or updating route tables.
Route table association issues
Confirm the Lambda function's subnets are associated with the route table that has the 0.0.0.0/0 route to the NAT Gateway.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

exploring-data-catalog
Full inventory and audit of AWS Glue Data Catalog, S3 Tables, Redshift-federated, and remote Iceberg catalogs.

exporting-rds-to-s3
Exports Amazon RDS or Aurora database snapshots to Amazon S3 in Apache Parquet format for analytics, backup, or data migration. Handles snapshot selection or creation, IAM role setup, KMS encryption, S3 bucket preparation, export task execution, progress monitoring, and data verification. Use when exporting RDS/Aurora data to S3 for Athena, Glue, or Redshift Spectrum consumption.

finding-data-lake-assets
Resolve data lake asset references across Glue, S3, S3 Tables, and Redshift catalogs.

ingesting-into-data-lake
Ingest data from S3, databases, Snowflake, BigQuery, DynamoDB, or Glue tables into your AWS data lake.

launching-ec2-instance-with-best-practices
Launch EC2 instances with secure, cost-efficient defaults including IAM roles, hardened security groups, and encrypted storage.

querying-data-lake
Execute SQL queries on Amazon Athena across Glue, S3 Tables, and Redshift catalogs with workgroup management and cost tracking.