Review API Gateway’s Lambda invocation scope

Allow API Gateway to invoke the function only from required stages, methods and paths.

Description

A broad source_arn in a Lambda permission allows multiple API Gateway stages, methods and paths to use the same function invocation permission. Unnecessary scope can let new paths or configuration changes lead to unintended function calls.

This permission controls where the API Gateway service may invoke Lambda. Whether anonymous clients may call the API depends on the API’s authentication, authorization and resource policies.

Potential impact

  • Unintended API paths may forward requests to the function.
  • Unnecessary invocations can increase costs or processing load.

Remediation

Grant API Gateway only the required lambda:InvokeFunction permission and restrict source_arn to the actual API ID, stage, method and path. Review function and alias permissions together with API caller authentication and authorization. Test that approved invocations succeed and out-of-scope invocations are rejected.

Examples

These examples compare Lambda invocation permissions for the API Gateway service. Replace the Region, account ID, API ID, function name and alias with the actual integration values. Dev is a Lambda alias and prod is an API stage name; they are separate settings.

Before

yaml
- name: Lambda 호출 권한 설정
  lambda_policy:
    state: present
    function_name: functionName
    alias: Dev
    statement_id: api-gateway-invoke
    action: lambda:InvokeFunction
    principal: apigateway.amazonaws.com
    source_arn: arn:aws:execute-api:eu-central-1:123456789012:api-id/*/*

Wildcards permit multiple stages and invocation paths. This is not a grant of anonymous access to API clients.

After

yaml
- name: Lambda 호출 권한 설정
  lambda_policy:
    state: present
    function_name: functionName
    alias: Dev
    statement_id: api-gateway-invoke
    action: lambda:InvokeFunction
    principal: apigateway.amazonaws.com
    source_arn: arn:aws:execute-api:eu-central-1:123456789012:api-id/prod/GET/orders

This limits invocation to GET /orders in the prod stage. It does not itself add authentication or authorization for API clients.

References