Important: This documentation covers Yarn 1 (Classic).
For Yarn 2+ docs and migration guide, see yarnpkg.com.

Package detail

serverless-vpc-discovery

amplify-education53.1kMIT6.0.0

Serverless Plugin to modify VPC values

serverless discovery VPC, serverless plugins, api gateway, lambda, aws, VPC, aws lambda, amazon, amazon web services, serverless.com

readme

serverless-vpc-discovery

serverless Build Status npm version MIT licensed Codacy Badge npm downloads

The vpc discovery plugin takes the given vpc name, subnet tag key/value, and security group tag key/value or names in the serverless file to setup the vpc configuration for the lambda.

Basically we use this config:

vpcDiscovery:
    vpcName: '<vpc_name>'
    subnets:
      - tagKey: <tag_name>
        tagValues:
          - '<tag_vale>'
    securityGroups:
      - tagKey: <tag_name>
        tagValues:
          - '<tag_value>'

To generate this config:

vpc:
    subnetIds:
        - subnet-123456789
        ...
    securityGroupIds:
        - sg-123456789
        ...

For each lambda function.

Note: The core serverless provider.vpc settings will be used, if they are set, instead of vpcDiscovery. You can use also mix settings. For example you may set provider.vpc.subnetIds while using vpcDiscovery to set the securityGroupIds. Take a look at official documentation.

About Amplify

Amplify builds innovative and compelling digital educational products that empower teachers and students across the country. We have a long history as the leading innovator in K-12 education - and have been described as the best tech company in education and the best education company in tech. While others try to shrink the learning experience into the technology, we use technology to expand what is possible in real classrooms with real students and teachers.

Learn more at https://www.amplify.com

Getting Started

Prerequisites

Make sure you have the following installed before starting:

Also allow the lambda to have the following IAM permissions:

  • ec2:CreateNetworkInterface
  • ec2:DescribeNetworkInterfaces
  • ec2:DeleteNetworkInterface

Installation

Run:

# From npm (recommended)
npm install serverless-vpc-discovery

# From github
npm install https://github.com/amplify-education/serverless-vpc-discovery.git

Then make the following edits to your serverless.yaml file:

plugins:
  - serverless-vpc-discovery

# Optional: Either set `custom.vpcDiscovery` or `functions.<function name>.vpcDiscovery`
custom:
  vpcDiscovery:
    vpcName: '<vpc_name>'

    # optional if `securityGroups` option is specified
    # list of tag key and values 
    subnets:
      - tagKey: <tag_name>

        # an array of values
        tagValues:
          - '<tag_value>'

    # optional if `subnets` option is specified
    # list of tag key and value or names
    securityGroups:
      - tagKey: <tag_name>

        # an array of values
        tagValues:
          - '<tag_value>'

      # optional if `tagKey` and `tagValues` are specified
      # an array of values
      - names:
          - '<security_group_name>'

# Optional: Either set `custom.vpcDiscovery` or `functions.<function name>.vpcDiscovery`
functions:
  example:
    handler: handler.example
    # inherit `custom.vpcDiscovery` config in case `custom.vpcDiscovery` is specified

  example2:
    handler: handler.example

    # skip vpc configuration for the current function
    vpcDiscovery: false

  example3:
    handler: handler.example

    # inherit `custom.vpcDiscovery` config in case `custom.vpcDiscovery` is specified and override security group names
    vpcDiscovery:
      vpcName: '<vpc_name>'
      securityGroups:
        - tagKey: <tag_name>

          # an array of values
          tagValues:
            - '<tag_value>'

  example4:
    handler: handler.example
    # override or set basic subnets and security groups items
    vpcDiscovery:
      vpcName: '<vpc_name>'

      # optional if `custom.vpcDiscovery.securityGroups` option is specified
      subnets:
        - tagKey: <tag_name>

          # an array of values
          tagValues:
            - '<tag_value>'

      # optional if `custom.vpcDiscovery.subnets` option is specified
      securityGroups:

        # optional if `names` option is specified
        - tagKey: <tag_name>

          # an array of values
          tagValues:
            - '<tag_value>'

        # optional if `tagKey` and `tagValues` are specified
        # an array of values
        - names:
            - '<security_group_name>'

Running Tests

To run the test:

npm test

All tests should pass.

To run integration tests, set an environment variable TEST_VPC_NAME to the VPC you will be testing for. Then,

export AWS_PROFILE=your_profile
export TEST_VPC_NAME=vpc_name
npx npm run build
npx npm run integration-test

If there is an error build and install the node_module inside the serverless-vpc-discovery folder:

npm build
npm install .

Deploying with the plugin

When deploying run:

serverless deploy

And that should be it! Good Luck!

How it Works

The vpc, subnets, and security groups are found by filtering based on a specified tag name. Vpc and subnets are found under the tag name tag:Name. Security groups are found by the name of the group under group-name.

The vpc is found first as it is used to find the subnets and security groups. Once all of the subnets and security groups are found the serverless service provider creates a vpc object and stores the subnets and security groups.

Responsible Disclosure

If you have any security issue to report, contact project maintainers privately. You can reach us at github@amplify.com

Contributing

We welcome pull requests! For your pull request to be accepted smoothly, we suggest that you:

  1. For any sizable change, first open a GitHub issue to discuss your idea.
  2. Create a pull request. Explain why you want to make the change and what it’s for. We’ll try to answer any PR’s promptly.

changelog

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

[6.0.0] - 2024-11-25

Changed

  • Dropped Node14.x support
  • Updated packages

[5.0.2] - 2024-01-19

Fixed

  • Fixed EC2 client credentials initialization

[5.0.1] - 2024-01-19

Changed

  • Updated credentials initialization

[5.0.0] - 2023-12-15

Changed

  • Moved from AWS SDK V1 to AWS SDK V3
  • Speed up VPC config setup by caching

[4.1.0] - 2023-03-09

Changed

  • Outdated packages updated
  • Minimum node version updated to 14

[4.0.2] - 2022-04-11

Changed

  • Add integration with serverless 3 logging
  • Change Github workflows to run tests both with sls 2 and 3

[4.0.1] - 2022-04-08

Changed

  • Fixed audit issues. Added dependabot config

[4.0.0] - 2022-04-08

Changed

  • Added compability with serverless 3

[3.1.2] - 2021-09-01

Changed

  • Fixed y18n vulnerability

[3.1.1] - 2021-09-01

Changed

  • Added serverless schema validation. Thank you @ROSeaboyer (53)

[3.1.0] - 2021-09-01

Changed

  • Dropped support of node versions < 12
  • Replaced Travis pipeline items with GitHub workflow

[3.0.0] - 2020-12-24

Added

  • Support for getting subnets and security groups by any tag key/value

Changed

  • Important! The subnetNames and securityGroupNames options have been deprecated and will be removed in the next major release. The new options are subnets and securityGroups.
  • Important! Drop vpc option support. The new option is vpcDiscovery.

[2.3.0] - 2020-12-11

Changed

  • Allow usage of wildcards in subnet and security group names. Thank you @RLRabinowitz (#41)

[2.2.1] - 2020-12-02

Changed

  • Fixed travis build

[2.2.0] - 2020-12-02

Changed

  • Set custom.vpcDiscovery optional.
  • Update travis config for github release tagging

[2.1.0] - 2020-11-17

Changed

  • Important! The vpc option has been deprecated but it still will work for a while. The new option is vpcDiscovery.
  • The VPC config applies to each function instead of the provider option.
  • Fixed logic for checking missing subnets and security groups.

Added

  • A possibility to specify custom config for each function by specifying function.vpcDiscovery config
  • Added warning and info messages

[2.0.0] - 2020-11-13

Changed

  • The code rewritten to TypeScript. Added improvements. Updated travis config, lint and test scripts.

[1.0.13] - 2018-10-10

Added

  • Added our own configuration for AWS SDK's built in retry mechanism, increasing it from 3 retries to 20 so that this plugin is more easily used in an automated environment.

[1.0.12] - 2018-08-01

Added

  • This CHANGELOG file to make it easier for future updates to be documented. Sadly, will not be going back to document changes made for previous versions.