Description
An event source such as S3 needs lambda:InvokeFunction permission to run a Lambda function. Actions for other purposes, such as lambda:GetFunction, do not grant invocation.
Potential impact
An incorrect invocation permission can cause event integration to fail.
Remediation
For ordinary function invocation, use Action: lambda:InvokeFunction in AWS::Lambda::Permission and restrict Principal, SourceArn, and SourceAccount to the intended caller scope. Configure and verify the event connection separately.
Examples
These excerpts change only the action for the same S3 caller. Prepare function, bucket, and the event configuration separately.
Before
yaml
Resources:
s3Permission:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt function.Arn
Action: lambda:GetFunction
Principal: s3.amazonaws.com
SourceAccount: !Ref 'AWS::AccountId'
SourceArn: !GetAtt bucket.Arn
After
yaml
Resources:
s3Permission:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt function.Arn
Action: lambda:InvokeFunction
Principal: s3.amazonaws.com
SourceAccount: !Ref 'AWS::AccountId'
SourceArn: !GetAtt bucket.Arn