{
  "id": 13516250,
  "title": "Using a Lambda Function URL with AWS CloudFront via AWS CDK",
  "url": "https://urgent.news/2026/10/10/using-a-lambda-function-url-with-aws-cloudfront-via-aws-cdk",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T20:07:32.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/ashishpandeyone/using-a-lambda-function-url-with-aws-cloudfront-via-aws-cdk-5058"
  },
  "original_language": "en",
  "account": "Here is the story written from scratch using only the facts provided:\n\nOne of the author's friends who works with AWS CDK wanted to know if it's possible to use a Lambda function accessible via a function URL with a CloudFront distribution. The friend initially tried using an HttpOrigin but couldn't get it working. The author decided to research whether this was feasible and documented the process.\n\nTo get started, the author created a new CDK TypeScript project using npx cdk init app --language typescript. Next, they created a stack for the Lambda function that would be accessible through a function URL in lib/fnurl-stack.ts. The key configuration was setting the invokeMode property to RESPONSE_STREAM, which enables response streaming for the function.\n\nThe Lambda function was implemented using Node.js with the NodejsFunction class from aws-cdk-lib/aws-lambda-nodejs. The functionUrl property was added to the function, specifying the authType as NONE and the invokeMode as RESPONSE_STREAM. The resulting function URL endpoint was output using a CfnOutput resource.\n\nAfter setting up the function URL, the author installed esbuild as a development dependency to enable local bundling. They then wrote the Lambda handler function in streaming-response-test.ts, which returned a response stream. The handler used the awslambda.HttpResponseStream module to create a writable stream and set the response content type.\n\nThe author's journey demonstrated that it is possible to use a Lambda function with a function URL as an origin for a CloudFront distribution. By configuring the function URL with RESPONSE_STREAM mode and properly granting CloudFront the necessary permissions in the Lambda resource policy, the function could be invoked by CloudFront and return a streamed response.",
  "summary": "Update, October 2026: two things have changed since I wrote this. The nodejs20.x Lambda runtime stopped receiving security patches on 30 April 2026, so use Runtime.NODEJS_24_X for new functions. And CloudFront now supports Origin Access Control for function URLs: FunctionUrlOrigin.withOriginAccessControl(fnUrl) with authType: FunctionUrlAuthType.AWS_IAM lets only your distribution invoke the URL,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}