Why would a lambda fn be considered untrusted client code?
If the database and the lamdba fn are both in AWS, then they're on the same "server estate". How is this any different from the server portion a web app?
If the database and the lamdba fn are both in AWS, then they're on the same "server estate". How is this any different from the server portion a web app?
No good solution comes to mind, aside from being very explicit. "database client" vs "user client".
If by client you mean "a web browser" then "a better approach is where there's code between the client and the database" makes perfect sense; but in the meaning of "client" where any code that calls the database is a client of the database, it's balderdash.
I honestly don't think that a "trust boundary" has anything to do with it, generally.