I have some lambda functions(node.js) in AWS, that will connect to postgresql and doing some query and get the results back, so i am trying to make one configuration file for database which has the user, password, database name, port ... So what will be the best way to share a common configuration file to all lambda function?
3 Answers
It is possible to share common files between different Lambda Functions using Layers. You can create a zip file for the Layer pretty much the same way you do that for a Function.
The layer package will look more or less like this:
your-lambda-layer.zip
└ nodejs/node_modules/shared-package
In the code it can be referenced like this:
const shared = require('shared-package');
The shared-package can contain your code or configurations.
AWS Provides two services for this purpose.
AWS Secrets Manager is the latest service which has version controlled secrets and automatically rotates keys.
You can either store is as individual keys or combine all keys, store them as one key.
Secrets Manager Example:
https://docs.aws.amazon.com/AWSJavaScriptSDK/latest/AWS/SecretsManager.html#getSecretValue-property
var params = {
SecretId: "MyTestDatabaseSecret",
VersionStage: "AWSPREVIOUS"
};
secretsmanager.getSecretValue(params, function(err, data) {
if (err) console.log(err, err.stack); // an error occurred
else console.log(data); // successful response
/*
data = {
ARN: "arn:aws:secretsmanager:us-west-2:123456789012:secret:MyTestDatabaseSecret-a1b2c3",
CreatedDate: <Date Representation>,
Name: "MyTestDatabaseSecret",
SecretString: "{\n \"username\":\"david\",\n \"password\":\"BnQw&XDWgaEeT9XGTT29\"\n}\n",
VersionId: "EXAMPLE1-90ab-cdef-fedc-ba987SECRET1",
VersionStages: [
"AWSPREVIOUS"
]
}
*/
});
Systems Manager Parameter Store:
https://docs.aws.amazon.com/AWSJavaScriptSDK/latest/AWS/SSM.html#getParameter-property
var params = {
Name: 'STRING_VALUE', /* required */
WithDecryption: true || false
};
ssm.getParameter(params, function(err, data) {
if (err) console.log(err, err.stack); // an error occurred
else console.log(data); // successful response
});
EDIT1:
For sharing common files from a common storage, it is not possible as now. You can store the file in s3 and pull from there. It is going to have a heavy cold start.
Define your shared code in a AWS Lambda Layer using AWS::Lambda::LayerVersion or AWS::Serverless::LayerVersion and then reference to it in your lambda functions. For example with AWS SAM :
MyFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: function_code/
Handler: app.lambda_handler
Runtime: nodejs8.10
Layers:
- !Ref MySharedLayer
MySharedLayer:
Type: AWS::Serverless::LayerVersion
Properties:
LayerName: SharedLayerName
Description: Some shared code
ContentUri: layer_code/
CompatibleRuntimes:
- nodejs8.10
LicenseInfo: 'My License'
RetentionPolicy: Retain
The layer code will be available in the /opt folder and can be included in your lambda functions.