Description
A broad source_arn in a Lambda permission allows multiple API Gateway stages, methods and paths to use the same function invocation permission. Unnecessary scope can let new paths or configuration changes lead to unintended function calls.
This permission controls where the API Gateway service may invoke Lambda. Whether anonymous clients may call the API depends on the API’s authentication, authorization and resource policies.
Potential impact
- Unintended API paths may forward requests to the function.
- Unnecessary invocations can increase costs or processing load.
Remediation
Grant API Gateway only the required lambda:InvokeFunction permission and restrict source_arn to the actual API ID, stage, method and path. Review function and alias permissions together with API caller authentication and authorization. Test that approved invocations succeed and out-of-scope invocations are rejected.
Examples
These examples compare Lambda invocation permissions for the API Gateway service. Replace the Region, account ID, API ID, function name and alias with the actual integration values. Dev is a Lambda alias and prod is an API stage name; they are separate settings.
Before
- name: Lambda 호출 권한 설정
lambda_policy:
state: present
function_name: functionName
alias: Dev
statement_id: api-gateway-invoke
action: lambda:InvokeFunction
principal: apigateway.amazonaws.com
source_arn: arn:aws:execute-api:eu-central-1:123456789012:api-id/*/*
Wildcards permit multiple stages and invocation paths. This is not a grant of anonymous access to API clients.
After
- name: Lambda 호출 권한 설정
lambda_policy:
state: present
function_name: functionName
alias: Dev
statement_id: api-gateway-invoke
action: lambda:InvokeFunction
principal: apigateway.amazonaws.com
source_arn: arn:aws:execute-api:eu-central-1:123456789012:api-id/prod/GET/orders
This limits invocation to GET /orders in the prod stage. It does not itself add authentication or authorization for API clients.