enabling-lambda-vpc-internet-access
aws/agent-toolkit-for-aws
Enable internet access for Lambda functions in VPC subnets via NAT Gateway infrastructure
What is enabling-lambda-vpc-internet-access?
This skill configures NAT Gateway infrastructure and routing to allow AWS Lambda functions deployed in VPC private subnets to reach the internet. Use it when a VPC-attached Lambda cannot access external services or APIs.
- Creates NAT Gateway infrastructure in public subnets
- Configures route tables with 0.0.0.0/0 routes to NAT Gateway
- Updates security group outbound rules for internet access
- Associates Lambda subnets with properly configured route tables
- Troubleshoots connectivity issues and propagation delays
How to install enabling-lambda-vpc-internet-access
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill enabling-lambda-vpc-internet-access- Existing VPC with private and public subnets
- Lambda function already deployed in VPC private subnet
- AWS IAM permissions to create NAT Gateways and modify route tables
How to use enabling-lambda-vpc-internet-access
- 1.Identify the VPC and private subnets where your Lambda function runs
- 2.Create a NAT Gateway in a public subnet with an Elastic IP
- 3.Add a 0.0.0.0/0 route to the NAT Gateway in the route table associated with Lambda subnets
- 4.Verify security group outbound rules allow required ports and protocols
- 5.Test Lambda internet connectivity; wait 1–2 minutes for changes to propagate
Use cases
- Lambda function calling external APIs or third-party services from a VPC
- Downloading dependencies or packages from the internet during Lambda execution
- VPC-attached Lambda needing to send logs or data to external monitoring systems
- Enabling outbound HTTPS connections from Lambda in private subnets
- Restoring internet connectivity after Lambda deployment in VPC fails
- AWS infrastructure engineers
- DevOps practitioners managing Lambda deployments
- Cloud architects designing VPC networking
- Backend developers troubleshooting Lambda connectivity issues
enabling-lambda-vpc-internet-access FAQ
Lambda functions in VPC private subnets cannot receive public IPs. They need a NAT Gateway in a public subnet to route outbound traffic through an Internet Gateway.
Yes. The Internet Gateway allows traffic from the public subnet to the internet, and the NAT Gateway translates private subnet traffic to use the public subnet's route.
Route table and security group changes can take 1–2 minutes to propagate. Wait before retesting Lambda connectivity.
Check that the route table has the 0.0.0.0/0 route to NAT Gateway, security group outbound rules allow the target port, and both gateways are properly configured.
Yes, but NAT Gateways are AWS-managed, more reliable, and recommended. NAT Instances require manual management and patching.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: enabling-lambda-vpc-internet-access description: Enables internet access for AWS Lambda functions deployed in VPC subnets by creating NAT Gateway infrastructure, configuring public/private subnet routing, and updating security groups. Use when a VPC-attached Lambda function cannot reach the internet. version: 1
Enabling Lambda VPC Internet Access
Overview
Domain expertise for enabling internet access from AWS Lambda functions running inside VPC private subnets. Lambda functions in a VPC cannot receive public IP addresses, so outbound internet access requires NAT Gateway infrastructure that routes traffic from private subnets through a public subnet to an Internet Gateway.
Enable internet access for a VPC Lambda function
To set up NAT Gateway infrastructure and configure routing for a Lambda function that needs internet access, follow the procedure exactly. See Lambda VPC internet access setup procedure.
Troubleshooting
NAT Gateway not working
Verify the route table associated with the Lambda subnets has a 0.0.0.0/0 route pointing to the NAT Gateway. See the full procedure for details.
Lambda function timeout
Check that security group outbound rules allow the necessary ports and that both the NAT Gateway and Internet Gateway are properly configured.
Network changes not taking effect
VPC networking changes can take 1–2 minutes to propagate. Wait before testing after creating a NAT Gateway or updating route tables.
Route table association issues
Confirm the Lambda function's subnets are associated with the route table that has the 0.0.0.0/0 route to the NAT Gateway.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

exploring-data-catalog
Inventory and audit AWS Glue Data Catalog, S3 Tables, Redshift-federated, and Iceberg catalogs.

exporting-rds-to-s3
Export RDS/Aurora snapshots to S3 in Parquet format for analytics and migration.

finding-data-lake-assets
Resolve data lake asset references across Glue, S3, and Redshift catalogs.

ingesting-into-data-lake
Ingest data from S3, databases, Snowflake, BigQuery, DynamoDB, or Glue tables into your AWS data lake.

investigating-incidents-with-aws-devops-agent
Agent skill from aws/agent-toolkit-for-aws.

launch-with-aws
Migrate vibe-coded and frontend web apps to AWS with generated infrastructure code.