Separate delivery from business effect
Draw a timeline with receipt, durable effect, acknowledgment, and message removal. Failure between the effect and acknowledgment can leave the result completed and the message available for retry. Lambda’s SQS mapping processes at least once; the consumer must tolerate repetition. In the fictional example, a reconciliation order was recorded but the function ended before acknowledging it. Reprocessing must not create another order. FIFO send deduplication has a five-minute window; it is not a transaction with an external payments service. Define a stable identity for the business operation, retain its result, and decide how to handle an unknown external outcome. A timeout does not prove that an external operation failed. The runbook should support querying and reconciling before resending an order that may already have taken effect.
Handle the batch and protect ordering
By default, a batch failure can return messages already processed. With ReportBatchItemFailures configured and a valid response, the handler identifies individual failures. An uncaught exception still represents failure of the entire batch. In a FIFO exercise, orders F-21, F-22, and F-23 belong to one group. F-21 completed; F-22 failed; F-23 has not been processed. Stop that path and return F-22 and F-23 as failed and unprocessed respectively. Do not declare F-23 completed to free the queue. A group should match the domain requiring order, such as a portfolio. Putting all portfolios in one group can serialize independent work; using a random group per message can destroy required within-portfolio order. Document the choice against business requirements.
Available time and downstream pressure
For Lambda with a standard queue and batch window, inspected guidance recommends visibility timeout of at least six times the function timeout plus the window. With 35 seconds and a five-second window, the reference is 215 seconds. This is operational guidance, not a completion promise or the minimum service-validated bound; function timeout cannot exceed visibility. For custom consumers, extending visibility should follow real progress. Align concurrency with downstream capacity. In FIFO with three active groups and a maximum of eight, the group limit bounds concurrent invocations at three before other limits apply. For mappings without provisioned mode, sum maxima for queues sharing one function and compare with reserved concurrency. Adding consumers without assessing the database may merely increase timeouts and retries.
Recover without erasing failure evidence
A DLQ isolates messages needing analysis; it does not repair the payload or confirm the business effect. Retain reason, identity, attempts, and redrive authorization. In FIFO, moving a message to the DLQ can let later messages advance, breaking the operation sequence expected by the application. The owner must decide how to pause or reconcile that group. For a standard queue, DLQ expiry still depends on the original enqueue time. If DLQ retention is 72 hours and the message is already 30 hours old, approximately 42 remain, assuming no further change. Do not confuse age since DLQ entry with total age. At handover, combine backlog, in-flight work, isolated messages, and reconciled outcomes. Completion means an observed business result, not merely an empty main queue.
Original FIFO worksheet; not a deployable handler
Group = portfolio-17
F-21: durable completion
F-22: processing failure
F-23: unprocessed
ReportBatchItemFailures enabled
Return failures: F-22, F-23
Do not execute F-23 ahead of unresolved F-22Order R-804 has an unknown external result after a timeout. APS preserves identity and queries the outcome before authorizing another attempt.
Common pitfalls
Confusing FIFO with external atomicity; returning success for unfinished work; increasing concurrency against a saturated dependency; treating the DLQ as resolved storage.
Related topics: Consistency, transactions, and Regions
Retries must preserve the business outcome; ordering, time, and recovery need explicit decisions.
Reference: Using Lambda with Amazon SQS · SAP-C02