Lambda invocation permission misconfigured

Allow the action needed for the event source to invoke the function.

Description

An event source such as S3 needs lambda:InvokeFunction permission to run a Lambda function. Actions for other purposes, such as lambda:GetFunction, do not grant invocation.

Potential impact

An incorrect invocation permission can cause event integration to fail.

Remediation

For ordinary function invocation, use Action: lambda:InvokeFunction in AWS::Lambda::Permission and restrict Principal, SourceArn, and SourceAccount to the intended caller scope. Configure and verify the event connection separately.

Examples

These excerpts change only the action for the same S3 caller. Prepare function, bucket, and the event configuration separately.

Before

yaml
Resources:
  s3Permission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !GetAtt function.Arn
      Action: lambda:GetFunction
      Principal: s3.amazonaws.com
      SourceAccount: !Ref 'AWS::AccountId'
      SourceArn: !GetAtt bucket.Arn

After

yaml
Resources:
  s3Permission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !GetAtt function.Arn
      Action: lambda:InvokeFunction
      Principal: s3.amazonaws.com
      SourceAccount: !Ref 'AWS::AccountId'
      SourceArn: !GetAtt bucket.Arn

References