Review allowed actions in a Lambda resource policy

Allow actions for the actual invocation method and restrict callers and sources.

Description

The action in a Lambda resource policy identifies the operation being allowed. Ordinary function invocation by a service such as S3 requires lambda:InvokeFunction. An action for another purpose may fail to grant the needed invocation permission or allow unnecessary operations.

Other actions are not universally wrong; check the permissions required by the actual access method, such as a function URL.

Potential impact

  • An event source may be unable to invoke the function, delaying or failing processing.
  • Allowing overly broad operations or principals can expand access to the function.

Remediation

  • For ordinary function invocation, use action: lambda:InvokeFunction and allow only operations required by that access method.
  • Limit principal to the required caller. Restrict AWS service calls with supported source_arn and source_account conditions. Check the policy and event-source configuration together, and test actual invocation.

Examples

The function and Dev alias must already exist. Replace the bucket name and account ID with real values, and configure the S3 notification’s Region and destination. Adding a policy does not create the S3 notification.

Before

yaml
- name: Configure the Lambda policy
  community.aws.lambda_policy:
    state: present
    function_name: functionName
    alias: Dev
    statement_id: lambda-s3-myBucket-create-data-log
    action: lambda:CreateFunction
    principal: s3.amazonaws.com
    source_arn: arn:aws:s3:::example-bucket
    source_account: "123456789012"

After

yaml
- name: Configure the Lambda policy
  community.aws.lambda_policy:
    state: present
    function_name: functionName
    alias: Dev
    statement_id: lambda-s3-myBucket-create-data-log
    action: lambda:InvokeFunction
    principal: s3.amazonaws.com
    source_arn: arn:aws:s3:::example-bucket
    source_account: "123456789012"

Explanation:

  • Before: lambda:CreateFunction does not allow S3 to invoke the existing function.
  • After: lambda:InvokeFunction allows the specified bucket and account’s S3 invocation. The actual event connection is also required.

References