Build1 publisherNot yet confirmed elsewhere3 min readPublished
Lambda's loop detection reaches eusc-de-east-1 covering only four services
AWS Lambda's recursive loop detection reached the European Sovereign Cloud on September 10, 2026, cutting S3, SQS and SNS chains at about 16 invocations. A dev.to analysis shows that loops through other services, old SDKs or wide fan-out still get through, so eusc-de-east-1 teams need limits of their own.
The Engineer · Build desk
What happened
- The Sovereign Cloud partition opened in January 2026 with roughly 90 services and two Availability Zones instead of three.
- Native detection first shipped in commercial regions in July 2023 for SQS, SNS and Lambda, and reached S3 in October 2024.
- The partition's docs.aws.eu documentation carries the same minimum-SDK table and invocation ceiling as the commercial partition.
- Health Dashboard and email alerts for a dropped loop can take up to 3.5 hours, and email goes out at most once per function every 24 hours.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Loops routed through DynamoDB Streams, EventBridge, Kinesis or Step Functions never carry the counter, so teams using those paths have to write their own hop limit.
- exposure A Python function that bundles boto3 older than 1.24.46 drops out of protection without any error, so the SDK version inside each deployment package has to be checked.
- decision Billing alarms and Cost Anomaly Detection, the last-resort defenses, have to be confirmed working inside aws-eusc before a team relies on them there.
Recursive loops usually start as configuration slips. The author of the dev.to post writes that he has spent 16 years operating financial platforms. He says his most expensive Lambda incident came from one environment variable that held the same value for the source bucket and the target bucket [15]. The function wrote to the bucket that triggered it. Every write set off a fresh S3 event, and within minutes all of the account's concurrency was tied up in pointless invocations [15].
I think AWS got the design right for a default guardrail. The detector reads the X-Ray trace header. Events delivered by SQS, SNS or S3 carry a Lineage primitive, a resource hash plus a counter, written like Lineage=43e12f0f:5 [7]. Each time the function writes the event back to a supported service through a supported SDK, the counter goes up [7]. At roughly 16 invocations in one chain, Lambda drops the next one and returns RecursiveInvocationException [8]. Active tracing does not have to be on, and there is no charge [8].
The counter measures depth [11]. Take a loop where each invocation writes three objects. The counter still advances one step per level, but the number of invocations triples at every step [11]. At a factor of three, the 16th level alone is 3 to the 16th power, or 43,046,721 invocations [19]. "Detection bounds the chain; it does not bound the tree," the author wrote [12]. Of the four guardrails the post compares, reserved concurrency is the one that limits width [18].
The second gap is how fast anyone finds out [13]. The Health Dashboard and email path is slow and capped per function. So the post puts the alarm on the RecursiveInvocationsDropped metric, which is emitted immediately [14].
The partition widens both gaps, according to the post, because it has fewer security services and less quota automation behind them [16]. The European Sovereign Cloud is its own partition, aws-eusc, operated by EU residents [2]. It launched in January 2026 [3] and ran about eight months before detection arrived [20]. Teams arriving from eu-central-1 find IAM Identity Center, Security Hub, Inspector and CloudFront missing, and quota increases usually go through a support ticket [4]. The author wrote that "feature parity in a sovereign partition is not automatic" [17].
The other two guardrails in the comparison are structural separation and a team-built counter [18]. Separation means a prefix, a suffix or a distinct bucket. The counter covers DynamoDB and EventBridge paths [18]. In my context, separation is the first one to build. A function that writes to a different bucket than its trigger cannot start the loop from the author's incident [15]. Native detection is the backstop for the chains it can see. For SQS sources, the post adds maxReceiveCount with a dead-letter queue [18].
What to watch
- AWS extending Lineage propagation to DynamoDB Streams, EventBridge, Kinesis or Step Functions; that would retire the team-built counter for those paths.
- Security Hub, Inspector and IAM Identity Center arriving in aws-eusc, the services teams from eu-central-1 currently find missing.
- Any cut to the 3.5-hour ceiling on Health Dashboard and email loop notifications.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Lambda recursive loop detection reached the AWS European Sovereign Cloud on September 10, 2026.
ReportedSupportedSource: dev.to post on Lambda recursive loop guardrails in the Sovereign CloudView cited source - [2]
The European Sovereign Cloud is its own partition (aws-eusc) with a single region, eusc-de-east-1, in Germany, operated by EU residents; it is a logically separate environment.
- [3]
The European Sovereign Cloud has two Availability Zones instead of three and had roughly 90 services at its January 2026 launch.
- [4]
Teams arriving from eu-central-1 find IAM Identity Center, Security Hub, Inspector and CloudFront missing in the Sovereign Cloud, and quota increases usually go through a support ticket.
- [5]
Native Lambda recursive loop detection debuted in commercial regions in July 2023 for SQS, SNS and Lambda, and in October 2024 for S3.
- [6]
The docs.aws.eu documentation carries the same minimum-SDK table and the same ceiling of approximately 16 invocations per chain as the commercial partition.
- [7]
Lambda uses the X-Ray trace header: events delivered by SQS, SNS or S3 carry a Lineage primitive, a resource hash plus a counter (e.g. Lineage=43e12f0f:5), and the counter increments when the function writes the event back to a supported service using a supported SDK.
- [8]
At approximately 16 invocations in the same chain, Lambda drops the next invocation and returns RecursiveInvocationException; no X-Ray active tracing is required and there is no charge.
- [9]
Detection covers only Lambda, SQS, SNS and S3; loops through DynamoDB Streams, EventBridge, Kinesis or Step Functions do not carry the counter and are not cut.
- [10]
The counter only propagates with minimum SDK versions: Node.js 3.105.0 (v3), boto3 1.24.46, Java 2.20.81 on the 17 runtime, Go v2 1.57.0; a Python function bundling an old boto3 silently leaves the protection.
- [11]
The counter measures depth, not breadth: in a fan-out loop where one invocation produces three objects, each level multiplies the width, and sixteen hops at factor 3 is tens of millions of invocations before the cut.
- [12]
"Detection bounds the chain; it does not bound the tree."
- [13]
The Health Dashboard notification and the email can take up to 3.5 hours, and the email is sent at most once per function every 24 hours.
- [14]
The RecursiveInvocationsDropped metric is emitted immediately, and the post says that is where the alarm has to sit.
- [15]
The author, who says he has 16 years operating financial platforms, says his costliest Lambda incident was an environment variable holding the same value for source and target bucket; the function wrote to the bucket that triggered it, S3 emitted another event, and within minutes the whole account's concurrency was busy doing useless work.
- [16]
In a partition with fewer security services and less quota automation, the safety net shrinks; Cost Anomaly Detection and billing alarms remain the last-resort defense, but each has to be verified in the partition itself.
- [17]
"feature parity in a sovereign partition is not automatic"
- [18]
The post compares four guardrails: native detection (cuts at about 16 hops), structural separation (prefix/suffix, distinct bucket), reserved concurrency (limits width), and a team-built counter covering DynamoDB/EventBridge; it also lists SQS maxReceiveCount plus a DLQ on the source queue.
- [19]
At a fan-out factor of three, the 16th level of a loop alone is 43,046,721 invocations.
- [20]
The Sovereign Cloud ran about eight months without native recursive loop detection.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toLambda recursive loops: four guardrails compared in the Sovereign Cloud
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Serverless recursive loopsFollow
- Cloud cost controlsFollow
- Sovereign Cloud InfrastructureFollow