如何实现跨AWS区域的Lambda函数访问RDS Proxy?
Great question—since RDS Proxy is strictly tied to a single VPC and doesn’t support public access, cross-region Lambda access requires connecting the two VPCs (your Lambda’s region and RDS Proxy’s region) via AWS networking tools. Here are the most reliable, production-ready approaches:
Option 1: VPC Peering (Simplest for Two VPCs)
This is the go-to choice if you only need to connect two VPCs across regions. Here’s how to set it up:
- Create a VPC peering connection: In the AWS Console, navigate to the VPC service in either region, create a peering request between your Lambda’s VPC (Region A) and RDS Proxy’s VPC (Region B). Accept the request in the target region.
- Update route tables: For each subnet in both VPCs, add a route to the other VPC’s CIDR range, pointing to the peering connection ID.
- Adjust security groups:
- On your RDS Proxy’s security group, add an inbound rule allowing traffic from your Lambda’s VPC CIDR (or better, the Lambda’s security group ID) on your database port (e.g., 5432 for PostgreSQL, 3306 for MySQL).
- Ensure your Lambda’s security group allows outbound traffic to the RDS Proxy’s VPC CIDR on the same port.
- Deploy Lambda to its VPC: Make sure your cross-region Lambda is configured to run in your Region A VPC (with subnets and security groups set up as above). It will now be able to reach the RDS Proxy via its private DNS name or IP.
Key Notes:
- Your two VPCs must have non-overlapping CIDR blocks (e.g., don’t use 10.0.0.0/16 for both).
- Peering connections are direct between two VPCs—no transit through AWS backbone beyond the peering link.
Option 2: AWS Transit Gateway (Best for Scalable Setups)
If you anticipate adding more VPCs or regions later, Transit Gateway (TGW) is a more scalable alternative. It acts as a central hub to connect multiple VPCs across regions:
- Create a Transit Gateway: In one of your regions (or use a dedicated region), create a TGW with cross-region access enabled.
- Attach VPCs to the TGW: Add attachments for both your Lambda’s VPC (Region A) and RDS Proxy’s VPC (Region B).
- Configure TGW route tables: Create route tables to route traffic between the two VPCs, associating each VPC attachment with the appropriate route table.
- Update security groups: Same as Option 1—allow inbound traffic from the Lambda’s VPC/security group to the RDS Proxy’s security group on your database port.
- Deploy Lambda to its VPC: Ensure your Lambda is running in the Region A VPC with the correct security group and subnet access to the TGW.
Key Notes:
- TGW simplifies management if you have multiple VPCs or need to add more regions later.
- You’ll pay for data transfer across regions, same as with VPC peering.
Why Your Public RDS Connection Timed Out (Quick Side Note)
Just to circle back to your original issue with public RDS access: Lambda timeouts often happen if the Lambda isn’t configured to run in a VPC (it uses AWS’s public network, which can have latency) or if your RDS security group didn’t allow traffic from the Lambda’s dynamic public IP range. But since you’re using RDS Proxy (a great choice for connection pooling and security), the VPC-based solutions above are the right path.
Validation Steps
Once you’ve set up the network connection, test to confirm:
- Use a test Lambda function to run a simple database query via the RDS Proxy endpoint.
- If you hit issues, check route tables for correct entries, security group rules, and ensure both VPCs have "Enable DNS hostnames" and "Enable DNS resolution" enabled.
内容的提问来源于stack exchange,提问作者Anatol Zakrividoroga

