I kicked off a CodeStar project for a Node based serverless web service. Simple API Gateway with a Lambda behind it.

All good and simple, but configuring the Lambda to run in a VPC proved to be a very challenging task!

The error I got was: The provided execution role does not have permissions to call CreateNetworkInterface.

The internet is filled with suggestions (and many more).

But apparently I’m the first one who bumped into a new root cause…

So if you’re in the same situation then the keyword to the solution is Permission Boundaries!

Quoting the docs: A permissions…

David Treves

I love building stuff

