Tutorial: Creating a response streaming Lambda function with a function URL
In this tutorial, you create a Lambda function defined as a .zip file archive with a function URL endpoint that returns a response stream. For more information about configuring function URLs, see Function URLs.
This tutorial assumes that you have some knowledge of basic Lambda operations and the Lambda console. If you haven't already, follow the instructions in Create a Lambda function with the console to create your first Lambda function.
To complete the following steps, you need the Amazon CLI version 2. Commands and the expected output are listed in separate blocks:
aws --version
You should see the following output:
aws-cli/2.13.27 Python/3.11.6 Linux/4.14.328-248.540.amzn2.x86_64 exe/x86_64.amzn.2
For long commands, an escape character (\
) is used to split a command over multiple lines.
On Linux and macOS, use your preferred shell and package manager.
In Windows, some Bash CLI commands that you commonly use with Lambda (such as zip
) are not supported by the operating system's built-in terminals.
To get a Windows-integrated version of Ubuntu and Bash, install the Windows Subsystem for Linux
Create an execution role
Create the execution role that gives your Lambda function permission to access Amazon resources.
To create an execution role
Open the Roles page
of the Amazon Identity and Access Management (IAM) console. -
Choose Create role.
Create a role with the following properties:
Trusted entity type – Amazon service
Use case – Lambda
Permissions – AWSLambdaBasicExecutionRole
Role name –
The AWSLambdaBasicExecutionRole policy has the permissions that the function needs to write logs to Amazon CloudWatch Logs. After you create the role, note down the its Amazon Resource Name (ARN). You'll need it in the next step.
Create a response streaming function (Amazon CLI)
Create a response streaming Lambda function with a function URL endpoint using the Amazon Command Line Interface (Amazon CLI).
To create a function that can stream responses
Copy the following code example into a file named
.import util from 'util'; import stream from 'stream'; const { Readable } = stream; const pipeline = util.promisify(stream.pipeline); /* global awslambda */ export const handler = awslambda.streamifyResponse(async (event, responseStream, _context) => { const requestStream = Readable.from(Buffer.from(JSON.stringify(event))); await pipeline(requestStream, responseStream); });
Create a deployment package.
zip function.zip index.mjs
Create a Lambda function with the
command. Replace the value of--role
with the role ARN from the previous step.aws lambda create-function \ --function-name
\ --runtime nodejs16.x \ --zip-file fileb://function.zip \ --handler index.handler \ --rolearn:aws:iam::123456789012:role/response-streaming-role
To create a function URL
Add a resource-based policy to your function to allow access to your function URL. Replace the value of
with your Amazon Web Services account ID.aws lambda add-permission \ --function-name my-streaming-function \ --action lambda:InvokeFunctionUrl \ --statement-id 12345 \ --principal
\ --function-url-auth-type AWS_IAM \ --statement-id url -
Create a URL endpoint for the function with the
command.aws lambda create-function-url-config \ --function-name my-streaming-function \ --auth-type AWS_IAM \ --invoke-mode RESPONSE_STREAM
Test the function URL endpoint
Test your integration by invoking your function. You can open your function's URL in a browser, or you can use curl.
curl --request GET "
" --user "<key:token>
" --aws-sigv4 "aws:amz:us-east-1:lambda" --no-buffer
Our function URL uses the IAM_AUTH
authentication type. This means that you
need to sign requests with both your Amazon access key and secret key. In the previous command,
replace <key:token>
with the Amazon access key ID. Enter your Amazon secret
key when prompted. If you don't have your Amazon secret key, you can use
temporary Amazon credentials instead.
Clean up your resources
You can now delete the resources that you created for this tutorial, unless you want to retain them. By deleting Amazon resources that you're no longer using, you prevent unnecessary charges to your Amazon Web Services account.
To delete the execution role
Open the Roles page
of the IAM console. -
Select the execution role that you created.
Choose Delete.
Enter the name of the role in the text input field and choose Delete.
To delete the Lambda function
Open the Functions page
of the Lambda console. -
Select the function that you created.
Choose Actions, Delete.
in the text input field and choose Delete.