# Serverless app can't be deployed because of Lambda function VPC error

**URL:** <https://forum.serverless.com/t/serverless-app-cant-be-deployed-because-of-lambda-function-vpc-error/14332>\
**Category:** Serverless Framework\
**Tags:** aws, lambda, security\
**Created:** [March 10, 2021, 6:26pm UTC](https://forum.serverless.com/t/serverless-app-cant-be-deployed-because-of-lambda-function-vpc-error/14332 "2021-03-10T18:26:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![claudiadast](https://avatars.discourse-cdn.com/v4/letter/c/58f4c7/32.png) [@claudiadast](https://forum.serverless.com/u/claudiadast)\
**Post date:** [March 10, 2021, 6:26pm UTC](https://forum.serverless.com/t/serverless-app-cant-be-deployed-because-of-lambda-function-vpc-error/14332/1 "2021-03-10T18:26:22Z")

</div>

I’m trying to deploy a Lambda function that can download a file from S3 to EFS upon an S3 object being uploaded to a given bucket. This is what I have for my `serverless.yml` file so far, but when I try to deploy it, I get the error:

`Function "cfnTrigger": when using fileSystemConfig, ensure that function has vpc configured on function or provider level`

**serverless.yml:**

```
service: cfn-trigger-test
frameworkVersion: '2'

provider:
  name: aws
  runtime: python3.8
  stage: dev
  region: us-west-2
  vpc:
    securityGroupIds:
      - sg-XXXXXXXXXX
      - sg-XXXXXXXXXX
      - sg-XXXXXXXXXX
    subnetdIds:
      - subnet-XXXXXXXX

functions:
  cfnTrigger:
    handler: handler.download_files_to_efs
    description: Lambda to download S3 file to EFS folder.
    events:
      - s3:
          bucket: cfn-trigger-test
          event: s3:ObjectCreated:*
          existing: true
    fileSystemConfig:
      localMountPath: /mnt/efs
      arn: arn:aws:elasticfilesystem:us-west-2:XXXXXX:access-point/fsap-XXXXX
    iamRoleStatements:
      - Effect: "Allow"
        Action:
          - states:*
        Resource: "*"
      - Effect: Allow
        Action:
        - elasticfilesystem:ClientMount
        - elasticfilesystem:ClientWrite
        - elasticfilesystem:ClientRootAccess
        Resource:
        - arn:aws:elasticfilesystem:us-west-2:XXXXX:file-system/fs-XXXXXX

plugins:
  - serverless-step-functions
  - serverless-iam-roles-per-function

package:
  individually: true
  exclude:
    - '**/*'
  include:
    - handler.py

```

Any ideas as to where this VPC issue is coming from? The list of Security Groups I’ve included here represents the set of the Security Groups allocated to EFS and the instance it has been mounted to.

---

<div class="post-metadata">

**Author:** ![pgrzesik](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/pgrzesik/32/5054_2.png) [@pgrzesik](https://forum.serverless.com/u/pgrzesik)\
**Post date:** [March 11, 2021, 9:12am UTC](https://forum.serverless.com/t/serverless-app-cant-be-deployed-because-of-lambda-function-vpc-error/14332/2 "2021-03-11T09:12:18Z")

</div>

Hello @claudiadast - there’s a small typo in your example - you have `subnetdIds` where it should be `subnetIds` - I believe we should update schema to catch these typos. I’ve tested in locally and it should resolve your problem here. 🤞
