How to run a AWS X-Ray sidecar container in a private subnet

We are running cloud native applications in a private VPC meaning the elastic network interfaces don't have direct internet access, not even through a NAT Gateway. Instead the AWS Lambda and ECS Fargate tasks targeted in these subnets with there elastic network interfaces (ENI) have to use a custom outbound

AWS supports the targeting of a Lambda function behind an application load balancer. Most likely you probably deploy most of your Lambda functions on the AWS API Gateway (same as us). However in case you don't need custom & AWS_IAM authorisation out-of-the-box using the ALB target group for your

