> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/resilience-testing/chaos-testing/probes/probe-template-library/aws/aws-lambda-function-status-check.md).

# AWS Lambda Function Status Check

AWS Lambda Function Status Check is a built-in Command Probe template that validates whether an AWS Lambda function exists and is in the `Active` state during a chaos experiment. Use it to assert that serverless functions stay available and invocable while a fault disrupts your application.

The probe runs the `healthchecks` utility bundled in the chaos probe image, queries the AWS Lambda API, and prints `[Pass]` when the function is in the `Active` state. The comparator marks the probe as passed when the output contains `[Pass]`.

{% hint style="info" %}
**BUILT-IN PROBE TEMPLATE**

This is a built-in Command Probe template that runs on Kubernetes chaos infrastructure. Add it to an experiment from the probe library and customize its inputs. Go to [Built-in probe templates](/resilience-testing/chaos-testing/probes/probe-templates.md) to browse the full library, or go to [Command probe](/resilience-testing/chaos-testing/probes/command-probe.md) to understand how command probes work.
{% endhint %}

***

### Use cases <a href="#use-cases" id="use-cases"></a>

Use this probe template to:

* Verify that Lambda functions stay active during chaos experiments.
* Validate function availability after configuration changes.
* Monitor serverless application health and readiness.
* Confirm that functions remain deployable and invocable.

***

### How the probe works <a href="#how-the-probe-works" id="how-the-probe-works"></a>

The template configures a Command Probe that runs `healthchecks -name lambda-update-function`. The utility resolves the function named in `FUNCTION_NAME` in the supplied `REGION`, calls the AWS Lambda API, and prints `[Pass]` when the function exists and is in the `Active` state. The comparator passes the probe when the output contains `[Pass]`, and fails it otherwise.

***

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* **Chaos infrastructure:** A Kubernetes chaos infrastructure with network access to the AWS Lambda API endpoints.
* **AWS credentials:** Cloud credentials available to the chaos infrastructure, with the permissions listed below.
* **Target function exists:** The function named in `FUNCTION_NAME` exists in `REGION`.

***

### Permissions required <a href="#permissions-required" id="permissions-required"></a>

The credentials used by the probe need the following AWS actions:

```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "lambda:GetFunction"
      ],
      "Resource": "*"
    }
  ]
}
```

The probe uses the AWS credentials available to your chaos infrastructure. Go to [AWS IAM integration](/resilience-testing/chaos-engineering/faults/chaos-fault-categories/aws/security-configurations/aws-iam-integration.md) to set up access through IAM Roles for Service Accounts (IRSA), or go to [common policy for all AWS faults](/resilience-testing/chaos-engineering/faults/chaos-fault-categories/aws/security-configurations/policy-for-all-aws-faults.md) to apply a single superset policy.

***

### Probe properties <a href="#probe-properties" id="probe-properties"></a>

#### Command <a href="#command" id="command"></a>

```bash
healthchecks -name lambda-update-function
```

#### Comparator <a href="#comparator" id="comparator"></a>

| Type   | Criteria | Value    |
| ------ | -------- | -------- |
| string | contains | `[Pass]` |

The probe passes when the command output contains `[Pass]`, which indicates that the Lambda function is in the `Active` state.

#### Environment variables <a href="#environment-variables" id="environment-variables"></a>

| Variable        | Description                                                                 | Required | Default |
| --------------- | --------------------------------------------------------------------------- | -------- | ------- |
| `FUNCTION_NAME` | Name of the Lambda function to check (for example, `my-lambda-function`).   | Yes      | -       |
| `REGION`        | AWS region where the Lambda function is located (for example, `us-east-1`). | Yes      | -       |

***

### Run properties <a href="#run-properties" id="run-properties"></a>

| Property          | Description                                                                      | Type    | Default |
| ----------------- | -------------------------------------------------------------------------------- | ------- | ------- |
| `timeout`         | Maximum time to wait for the probe to complete (for example, `30s`, `1m`, `5m`). | String  | `300s`  |
| `interval`        | Time between probe executions (for example, `5s`, `30s`, `1m`).                  | String  | `10s`   |
| `attempt`         | Number of retry attempts before the probe is marked as failed.                   | Integer | `1`     |
| `pollingInterval` | Time between retry attempts (for example, `1s`, `5s`, `10s`).                    | String  | -       |
| `initialDelay`    | Initial delay before the probe starts (for example, `0s`, `10s`, `30s`).         | String  | -       |
| `stopOnFailure`   | Stop the experiment if the probe fails.                                          | Boolean | `false` |
| `verbosity`       | Log verbosity level (`info`, `debug`, `trace`).                                  | String  | -       |

***

### Troubleshooting <a href="#troubleshooting" id="troubleshooting"></a>

<details>

<summary>AWS Lambda Function Status Check probe fails with an authorization error</summary>

The credentials available to the chaos infrastructure do not have the required Lambda permissions in the target region. Confirm that the IAM policy attached to the role or IRSA service account includes lambda:GetFunction, and that any policy condition allows the region passed in REGION.

</details>

<details>

<summary>AWS Lambda Function Status Check probe reports the function was not found</summary>

The function did not resolve in the supplied REGION. Verify that FUNCTION\_NAME matches the function name exactly, that REGION matches the function region, and that the AWS account used by the credentials owns the function.

</details>

<details>

<summary>AWS Lambda Function Status Check probe fails because the function is not Active</summary>

The function exists but is in a Pending or Failed state, which can happen during configuration updates or while VPC-attached functions provision elastic network interfaces. Increase the run-property timeout and attempt count so the probe waits for the function to return to Active, and review the function's last update status in the AWS console.

</details>

***

### Related probe templates <a href="#related-probe-templates" id="related-probe-templates"></a>

* [AWS ECS Service Status Check](/resilience-testing/chaos-testing/probes/probe-template-library/aws/aws-ecs-service-status-check.md): Validate the desired state of an Amazon ECS service.
* [AWS EC2 Instance Status Check](/resilience-testing/chaos-testing/probes/probe-template-library/aws/aws-ec2-instance-status-check.md): Validate the state of EC2 instances.
* [Built-in probe templates](/resilience-testing/chaos-testing/probes/probe-templates.md): Browse the full probe template library.
