Serverless部署的Lambda未触发cognitoidentityserviceprovider.listUsers回调求助
listUsers Timeout with No CloudWatch Logs Hey there! As a fellow Serverless developer, I’ve run into this exact frustrating issue before—nothing’s worse than a function timing out with zero logs to clue you in. Let’s walk through the most likely causes and fixes step by step:
1. Missing IAM Permissions for Cognito ListUsers
First up, your Lambda’s execution role needs explicit permission to call cognito-idp:ListUsers on your target user pool. Without this, the request might hang silently instead of throwing a clear error.
Check your serverless.yml and make sure your IAM role includes this statement:
provider: name: aws runtime: nodejs18.x iamRoleStatements: - Effect: Allow Action: - cognito-idp:ListUsers Resource: "arn:aws:cognito-idp:${self:provider.region}:${aws:accountId}:userpool/YOUR_USER_POOL_ID"
Replace YOUR_USER_POOL_ID with your actual Cognito user pool ID. This ensures Lambda can authenticate its request to Cognito.
2. Lambda in a VPC Without Internet Access
If your Lambda is attached to a VPC (common for internal resource access), it might lack outbound access to Cognito’s public endpoint. By default, Lambda in a VPC can’t reach public services unless you have:
- A NAT Gateway attached to your VPC’s public subnet (so private subnets can route traffic out), or
- A VPC Endpoint for Cognito Identity Provider (to access Cognito privately without internet)
Without either, your Lambda’s request to Cognito will hang indefinitely until timeout—and since the request never completes, you won’t get error logs in CloudWatch.
3. Improper Async Code Handling
If you’re misusing callbacks or promises, your function might not wait for the listUsers call to finish, or fail to trigger the callback properly when errors occur.
Bad Example (Callback-based, no error handling):
exports.handler = (event, context, callback) => { const AWS = require('aws-sdk'); const cognito = new AWS.CognitoIdentityServiceProvider(); const params = { UserPoolId: 'YOUR_USER_POOL_ID' }; cognito.listUsers(params, (err, data) => { if (err) console.log(err); // Fails to call callback on error, leaving Lambda hanging else callback(null, data); }); };
If an error hits here (like permission issues) and you don’t invoke callback(err), Lambda will wait until timeout because it thinks the function is still running.
Good Example (Async/Await with proper error handling):
exports.handler = async (event) => { const AWS = require('aws-sdk'); const cognito = new AWS.CognitoIdentityServiceProvider(); const params = { UserPoolId: 'YOUR_USER_POOL_ID' }; try { const users = await cognito.listUsers(params).promise(); return { statusCode: 200, body: JSON.stringify(users) }; } catch (err) { console.error('Error listing users:', err); return { statusCode: 500, body: JSON.stringify({ error: err.message }) }; } };
Using async/await ensures the function waits for the listUsers call to complete, and try/catch guarantees errors get logged to CloudWatch for debugging.
4. Wrong User Pool ID or Region
Double-check that your UserPoolId is correct, and that the AWS SDK uses the same region as your user pool. A mismatched region will send requests to the wrong endpoint, leading to hangs or silent failures.
You can explicitly set the region if needed:
const cognito = new AWS.CognitoIdentityServiceProvider({ region: 'us-east-1' });
Quick Test to Narrow It Down
Since you mentioned creating a test function, try deploying a minimal Lambda (without VPC if possible) with the correct IAM permissions and the async/await code above. If this works, you know the issue is either VPC-related or permission-related in your original function.
内容的提问来源于stack exchange,提问作者Unnikrishnan M R

