[{"data":1,"prerenderedAt":65},["ShallowReactive",2],{"pattern-lambda-microvm-custom-domain-cdk":3,"pattern-group-lambda-microvm-custom-domain-cdk":64},{"id":4,"title":5,"architectureURL":6,"cleanup":7,"contributors":10,"deploy":12,"description":16,"extension":17,"framework":18,"gitHub":19,"highlight":6,"introBox":25,"language":32,"level":33,"meta":34,"patternArch":35,"patternGroup":6,"patternGroupLabel":6,"resources":49,"s3URL":6,"services":6,"stem":59,"testing":60,"videoId":6,"__hash__":63},"patterns\u002Fpatterns\u002Flambda-microvm-custom-domain-cdk.json","Custom domains for AWS Lambda MicroVMs with Application Load Balancer",null,{"text":8},[9],"Delete the stack: \u003Ccode>npx cdk destroy\u003C\u002Fcode>.",[11],"content\u002Fcontributors\u002Ffrank-scarfo.json",{"text":13},[14,15],"npm install","npx cdk deploy","Serve each AWS Lambda MicroVM under a domain you own via an Application Load Balancer Host header rewrite over PrivateLink, with no CloudFront or request-path compute.","json","AWS CDK",{"template":20},{"repoURL":21,"templateURL":22,"projectFolder":23,"templateFile":24},"https:\u002F\u002Fgithub.com\u002Faws-samples\u002Fserverless-patterns\u002Ftree\u002Fmain\u002Flambda-microvm-custom-domain-cdk","serverless-patterns\u002Flambda-microvm-custom-domain-cdk","lambda-microvm-custom-domain-cdk","lib\u002Fmicrovm-custom-domains-stack.ts",{"headline":26,"text":27},"How it works",[28,29,30,31],"This pattern gives each AWS Lambda MicroVM a domain you own (e.g. \u003Cuuid>.microvms.example.com) instead of exposing the service-generated \u003Cuuid>.lambda-microvm.\u003Cregion>.on.aws endpoint. It is built entirely from load-balancing and networking primitives: there is no CloudFront and no compute in the request path.","A client sends HTTPS to \u003Cuuid>.microvms.example.com. Route 53 resolves a wildcard record to an Application Load Balancer, which terminates TLS with a wildcard ACM certificate. A listener rule matches the host with a regex condition, then a host-header-rewrite Transform swaps only the base-domain suffix (preserving everything ahead of it) to rewrite Host to \u003Cuuid>.lambda-microvm.\u003Cregion>.on.aws.","The ALB forwards to an IP target group whose targets are the private ENI IPs of a MicroVM interface VPC endpoint, reaching the MicroVM service over AWS PrivateLink. The service routes to the correct MicroVM using the rewritten Host header and enforces the JWE auth token the client supplied. Because a Transform (not a redirect) performs the rewrite, the customer's domain stays intact end to end.","CORS is handled entirely at the ALB (a 204 preflight rule plus inserted Access-Control-Allow-* response headers), so no change is required inside the MicroVM. The CDK app also includes an optional, demo-only single-page app and provisioning API that can be removed to deploy the pure networking pattern.","TypeScript","300",{},{"icon1":36,"icon2":41,"line1":45},{"x":37,"y":38,"service":39,"label":40},20,50,"alb","Application Load Balancer",{"x":42,"y":38,"service":43,"label":44},80,"lambda-microvms","AWS Lambda MicroVMs",{"from":46,"to":47,"label":48},"icon1","icon2","",{"bullets":50},[51,53,56],{"text":44,"link":52},"https:\u002F\u002Fdocs.aws.amazon.com\u002Flambda\u002Flatest\u002Fdg\u002Flambda-microvms-guide.html",{"text":54,"link":55},"Introducing URL and Host header rewrite with AWS Application Load Balancers","https:\u002F\u002Faws.amazon.com\u002Fblogs\u002Fnetworking-and-content-delivery\u002Fintroducing-url-and-host-header-rewrite-with-aws-application-load-balancers\u002F",{"text":57,"link":58},"AWS PrivateLink interface VPC endpoints","https:\u002F\u002Fdocs.aws.amazon.com\u002Fvpc\u002Flatest\u002Fprivatelink\u002Finterface-endpoints.html","patterns\u002Flambda-microvm-custom-domain-cdk",{"text":61},[62],"See the GitHub repo for detailed testing instructions.","0kXaVMo5acwM96gpbQXUxqqc1eCxC-mGrMDt6Jekdtk",[],1789209289960]