Description
The action in a Lambda resource policy identifies the operation being allowed. Ordinary function invocation by a service such as S3 requires lambda:InvokeFunction. An action for another purpose may fail to grant the needed invocation permission or allow unnecessary operations.
Other actions are not universally wrong; check the permissions required by the actual access method, such as a function URL.
Potential impact
- An event source may be unable to invoke the function, delaying or failing processing.
- Allowing overly broad operations or principals can expand access to the function.
Remediation
- For ordinary function invocation, use action: lambda:InvokeFunction and allow only operations required by that access method.
- Limit principal to the required caller. Restrict AWS service calls with supported source_arn and source_account conditions. Check the policy and event-source configuration together, and test actual invocation.
Examples
The function and Dev alias must already exist. Replace the bucket name and account ID with real values, and configure the S3 notification’s Region and destination. Adding a policy does not create the S3 notification.
Before
yaml
- name: Configure the Lambda policy
community.aws.lambda_policy:
state: present
function_name: functionName
alias: Dev
statement_id: lambda-s3-myBucket-create-data-log
action: lambda:CreateFunction
principal: s3.amazonaws.com
source_arn: arn:aws:s3:::example-bucket
source_account: "123456789012"
After
yaml
- name: Configure the Lambda policy
community.aws.lambda_policy:
state: present
function_name: functionName
alias: Dev
statement_id: lambda-s3-myBucket-create-data-log
action: lambda:InvokeFunction
principal: s3.amazonaws.com
source_arn: arn:aws:s3:::example-bucket
source_account: "123456789012"
Explanation:
- Before: lambda:CreateFunction does not allow S3 to invoke the existing function.
- After: lambda:InvokeFunction allows the specified bucket and account’s S3 invocation. The actual event connection is also required.