how to use vpc endpoint with ses in serverless

Viewed 3106

I have functions deployed in vpc which doesn't have nat gateway/ internet access. Goal: Send email through SES from this function (in vpc)

I have tried using public private subnet with nat gateway to send emails and it works fine. But i am trying to use it vi VPC endpoint. i have created an email vpc endpoint but not sure how to configure it in serverless.yml. Have tried setting up configs as said in
https://www.serverless.com/framework/docs/providers/aws/guide/serverless.yml/

but nothing working because there is no mention for ses.

3 Answers

You need the following configuration so that CloudFormation creates the resource. (Note the variables in brackets)

resources:
  Resources:  
    VPCEndpointForSES:
      Type: AWS::EC2::VPCEndpoint
      Properties:
        PrivateDnsEnabled: True
        SecurityGroupIds:
          - <ID of the VPC Security Group>
        ServiceName: 'com.amazonaws.<AWS Region String>.email-smtp'
        SubnetIds:
          - <Subnet of your VPC>
          - <Subnet of your VPC>
          - <Subnet of your VPC>
        VpcEndpointType: Interface
        VpcId: <ID of your VPC>

Have you looked at AWS PrivateLink for VPC Endpoints?

You won't need to set up an Internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. Your VPC can communicate with AWS SES within the Amazon network using AWS PrivateLink.

Note that VPC Endpoints currently do not support cross-region requests—ensure that you create your endpoint in the same region in which you plan to issue your API calls to Amazon SES.

You will need to create a security group and a VPC Interface Point. There's a step by step example here

Additional Resources: AWS PrivateLink Interface Endpoints

Related