AWS Lambda MicroVMs is a serverless compute building block that provides VM-level isolation, near-instant startup performance, and state retention. You can now give each user or job their own execution environment to securely run just-in-time code, whether user or AI-generated. You do this without managing virtualization infrastructure or choosing between isolation, speed, and state retention. Lambda MicroVMs are powered by Firecracker virtualization, the technology underpinning AWS Lambda.
When you run a workload on AWS Lambda MicroVMs , each MicroVM is reachable at a service-generated endpoint that looks like 92cfc7f9-…. That works, but many teams want to expose their MicroVMs under a domain they own, such as 92cfc7f9-…. When a browser is the client, they also want to satisfy cross-origin resource sharing (CORS) without changing the application inside the MicroVM. Both are achievable today, entirely from load-balancing and networking primitives. There is no Amazon CloudFront distribution and no compute in the request path.
All you need is an Application Load Balancer (ALB) that terminates TLS with your AWS Certificate Manager (ACM) certificate, rewrites the Host header, and forwards the request over AWS PrivateLink . In this post you’ll deploy that pattern with the AWS Cloud Development Kit (AWS CDK) , map a wildcard of custom domains onto your MicroVMs, and let the ALB handle CORS for you. The complete, deployable example is available as a pattern on Serverless Land . This walkthrough centers on the reusable networking pattern.
The sample also includes a small demo application that provisions a MicroVM and mints an access token , which we reference but do not detail here. com/ (with the MicroVM access headers described later) reaches the right MicroVM, with your domain intact end to end. The key component is the ALB host header rewrite , introduced in URL and host header rewrite for Application Load Balancers . A listener rule matches the incoming custom host with a regex condition , captures the MicroVM ID from the left-most label, and a host-header-rewrite transform rewrites the Host header to .
