Lambda invocation principal uses a wildcard

Specify the intended service or account in Lambda invocation permissions.

Description

When Principal is * in AWS::Lambda::Permission, the principal itself does not narrow who can invoke the function. Conditions such as SourceArn and SourceAccount also affect actual access.

Potential impact

If conditions are also too broad, unintended invocations can increase costs or misuse the function’s data or behavior.

Remediation

Specify the service or account that should invoke the function. For AWS services, also apply source ARN and account restrictions supported by that service.

Examples

The examples retain source account and bucket restrictions while explicitly naming S3 as the principal. Define function and bucket as separate resources.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Grants S3 permission to invoke Lambda
Resources:
  s3Permission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !GetAtt function.Arn
      Action: lambda:InvokeFunction
      Principal: "*"
      SourceAccount: !Ref "AWS::AccountId"
      SourceArn: !GetAtt bucket.Arn

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Grants S3 permission to invoke Lambda
Resources:
  s3Permission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !GetAtt function.Arn
      Action: lambda:InvokeFunction
      Principal: s3.amazonaws.com
      SourceAccount: !Ref "AWS::AccountId"
      SourceArn: !GetAtt bucket.Arn

References