The documented isolation boundary
AWS documents Lambda as using Firecracker microVM technology for workload isolation. Firecracker is a virtual machine monitor built on Linux KVM with a deliberately small device model and several containment layers. This boundary does not expose Lambda’s fleet topology or host placement. Those details remain managed by AWS. The environment includes the runtime, function code, extensions, configured memory and proportional CPU, and isolated writable/tmp storage.
Initialization and invocation flow
- A caller or event source sends an invocation.
- If no suitable idle environment exists, Lambda creates one.
- Lambda downloads code and layers, starts extensions and the runtime, and runs static initialization.
- Lambda invokes the handler with the event.
- After invocation, Lambda may freeze and retain the environment.
- A later invocation can reuse clients, initialized state, and
/tmpcontents. - Lambda eventually shuts the environment down.
Lifecycle and latency controls
Reserved concurrency protects downstream systems and guarantees a function part of account concurrency. Provisioned concurrency directly controls pre-initialized capacity.
Reserved concurrency controls allocation; provisioned concurrency controls ready capacity.
Concurrency and scaling
When requests exceed available environments, Lambda creates more subject to account concurrency, reserved concurrency, and per-function scaling. AWS documents 1,000 new execution environments every 10 seconds per function, with source-specific behavior and quotas. Synchronous callers receive throttling errors when capacity is unavailable. Asynchronous invocations and event-source mappings have their own queues, retries, batching, and backpressure. Lambda can scale compute faster than a database can accept connections; cap concurrency and reuse or mediate connections.VPC networking
Without VPC attachment, a function uses Lambda-managed networking. Attaching a function to VPC subnets does not place the execution environment itself inside those subnets. Lambda creates and reuses Hyperplane ENIs for subnet and security-group combinations. A VPC-connected function needs NAT for general internet egress or VPC endpoints for supported services. A public subnet does not assign the function a public IP address. VPC attachment gives private connectivity; it does not automatically provide public internet access.Ephemeral storage and reuse
Each environment has encrypted/tmp storage configurable from 512 MB to 10,240 MB. It can cache extracted models or transformed files across warm invocations in the same environment.
The storage is not shared across environments and is not durable. Correctness must survive an empty directory and permanent cache loss.
SnapStart caveats
For supported runtimes, SnapStart runs initialization when a version is published, encrypts a snapshot of initialized memory and disk state, and restores new environments from it. SnapStart applies to published versions, not$LATEST.
Random values, identifiers, secrets, credentials, network connections, and time-sensitive state captured during initialization can become stale or duplicated. Use after-restore hooks where supported.
SnapStart and provisioned concurrency cannot both apply to the same function version.
Frequently asked questions
Does Lambda always reuse a warm environment?
Does Lambda always reuse a warm environment?
No. Lambda may reuse an idle environment, create a new one, or retire an old one at any time. Code must initialize correctly from scratch, tolerate reused globals and files, and never depend on a shutdown callback for correctness.
Does VPC attachment remove internet access?
Does VPC attachment remove internet access?
The function uses the selected VPC routes for outbound connectivity. A private subnet typically needs NAT for public destinations or VPC endpoints for supported services. A public subnet alone does not assign the function a public IP address.
Is SnapStart provisioned concurrency?
Is SnapStart provisioned concurrency?
No. SnapStart reduces initialization work by restoring environments when needed. Provisioned concurrency keeps a specified number already initialized. They have different cost and correctness tradeoffs and cannot be enabled together on one function version.