I've been trying to read up on this, but the info I'm getting is either conflicting or I just don't understand well enough to see why there's no conflict.
I'm using CDK to set up a lambda in a vpc with an SQS queue as an event source. The SQS queue will be subscribed to SNS topics in different AWS accounts. For now my question is just behind the SQS/Lambda interaction.
I want the Lambda to be able to poll/receive messages from the SQS queue without going through public internet. At first I thought this would require the vpc/security group setup for access to SQS vpc endpoint. But I read another post where someone was saying the lambda poller itself is not running in your lambda's VPC so no vpc configuration would apply to it. If so- does the poller only operate in AWS's private 'global infrastructure'?
But that's just the polling- I'm also wondering if the polling finds messages, is the lambda also able to read and respond (e.g. let's say the lambda throws an exception, or I want to return a partial batch response- in both cases Lambda has built-in functionality to return messages to the queue. Would all this also be handled outside the VPC, on non-public internet?
I'm wondering because pretty much 100% of the documentation/examples I've found only talk about lambda publishing to SQS, or manually reading a message from the queue- not when SQS is used as a lambda eventSource.