> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Lambda Internals: Execution Environments, Scaling, and Cold Starts

> Learn how Lambda initializes, reuses, scales, networks, and retires execution environments, including Firecracker, ephemeral storage, and SnapStart.

AWS Lambda runs function code inside managed execution environments that it creates, initializes, reuses, freezes, and removes. Each active environment processes one invocation at a time while Lambda adds environments for concurrent work.

*Updated October 9, 2026.*

**Lambda concurrency measures simultaneous invocations; each execution environment handles at most one invocation at a time.**

## The documented isolation boundary

AWS documents Lambda as using Firecracker microVM technology for workload isolation. Firecracker is a virtual machine monitor built on Linux KVM with a deliberately small device model and several containment layers.

This boundary does not expose Lambda's fleet topology or host placement. Those details remain managed by AWS.

The environment includes the runtime, function code, extensions, configured memory and proportional CPU, and isolated writable `/tmp` storage.

## Initialization and invocation flow

1. A caller or event source sends an invocation.
2. If no suitable idle environment exists, Lambda creates one.
3. Lambda downloads code and layers, starts extensions and the runtime, and runs static initialization.
4. Lambda invokes the handler with the event.
5. After invocation, Lambda may freeze and retain the environment.
6. A later invocation can reuse clients, initialized state, and `/tmp` contents.
7. Lambda eventually shuts the environment down.

**A cold start waits for initialization; a warm start reuses an initialized environment, but reuse is never guaranteed.**

Put reusable SDK clients outside the handler, but validate stale connections and credentials. Initialization must remain idempotent because environments can be created repeatedly.

## Lifecycle and latency controls

| Mechanism | What it does | Main tradeoff |
| - | - | - |
| On-demand | Creates environments as traffic requires | Cold starts during bursts or idle recovery |
| Reserved concurrency | Reserves and caps concurrency | Does not pre-initialize |
| Provisioned concurrency | Keeps initialized environments ready | Additional charge |
| SnapStart | Restores from an initialization snapshot | Restore-specific constraints |

Reserved concurrency protects downstream systems and guarantees a function part of account concurrency. Provisioned concurrency directly controls pre-initialized capacity.

**Reserved concurrency controls allocation; provisioned concurrency controls ready capacity.**

## Concurrency and scaling

When requests exceed available environments, Lambda creates more subject to account concurrency, reserved concurrency, and per-function scaling. AWS documents 1,000 new execution environments every 10 seconds per function, with source-specific behavior and quotas.

Synchronous callers receive throttling errors when capacity is unavailable. Asynchronous invocations and event-source mappings have their own queues, retries, batching, and backpressure.

**Lambda can scale compute faster than a database can accept connections; cap concurrency and reuse or mediate connections.**

## VPC networking

Without VPC attachment, a function uses Lambda-managed networking. Attaching a function to VPC subnets does not place the execution environment itself inside those subnets. Lambda creates and reuses Hyperplane ENIs for subnet and security-group combinations.

A VPC-connected function needs NAT for general internet egress or VPC endpoints for supported services. A public subnet does not assign the function a public IP address.

**VPC attachment gives private connectivity; it does not automatically provide public internet access.**

## Ephemeral storage and reuse

Each environment has encrypted `/tmp` storage configurable from 512 MB to 10,240 MB. It can cache extracted models or transformed files across warm invocations in the same environment.

The storage is not shared across environments and is not durable. Correctness must survive an empty directory and permanent cache loss.

## SnapStart caveats

For supported runtimes, SnapStart runs initialization when a version is published, encrypts a snapshot of initialized memory and disk state, and restores new environments from it. SnapStart applies to published versions, not `$LATEST`.

Random values, identifiers, secrets, credentials, network connections, and time-sensitive state captured during initialization can become stale or duplicated. Use after-restore hooks where supported.

SnapStart and provisioned concurrency cannot both apply to the same function version.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Does Lambda always reuse a warm environment?">
    No. Lambda may reuse an idle environment, create a new one, or retire an old one at any time. Code must initialize correctly from scratch, tolerate reused globals and files, and never depend on a shutdown callback for correctness.
  </Accordion>

  <Accordion title="Does VPC attachment remove internet access?">
    The function uses the selected VPC routes for outbound connectivity. A private subnet typically needs NAT for public destinations or VPC endpoints for supported services. A public subnet alone does not assign the function a public IP address.
  </Accordion>

  <Accordion title="Is SnapStart provisioned concurrency?">
    No. SnapStart reduces initialization work by restoring environments when needed. Provisioned concurrency keeps a specified number already initialized. They have different cost and correctness tradeoffs and cannot be enabled together on one function version.
  </Accordion>
</AccordionGroup>

## Sources and further reading

* [Lambda execution environment lifecycle](https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtime-environment.html)
* [Lambda concurrency and scaling](https://docs.aws.amazon.com/lambda/latest/dg/lambda-concurrency.html)
* [Lambda VPC networking](https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html)
* [Lambda ephemeral storage](https://docs.aws.amazon.com/lambda/latest/dg/configuration-ephemeral-storage.html)
* [Firecracker for serverless computing](https://aws.amazon.com/blogs/aws/firecracker-lightweight-virtualization-for-serverless-computing/)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.