Description
When Principal is * in AWS::Lambda::Permission, the principal itself does not narrow who can invoke the function. Conditions such as SourceArn and SourceAccount also affect actual access.
Potential impact
If conditions are also too broad, unintended invocations can increase costs or misuse the function’s data or behavior.
Remediation
Specify the service or account that should invoke the function. For AWS services, also apply source ARN and account restrictions supported by that service.
Examples
The examples retain source account and bucket restrictions while explicitly naming S3 as the principal. Define function and bucket as separate resources.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Grants S3 permission to invoke Lambda
Resources:
s3Permission:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt function.Arn
Action: lambda:InvokeFunction
Principal: "*"
SourceAccount: !Ref "AWS::AccountId"
SourceArn: !GetAtt bucket.Arn
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Grants S3 permission to invoke Lambda
Resources:
s3Permission:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt function.Arn
Action: lambda:InvokeFunction
Principal: s3.amazonaws.com
SourceAccount: !Ref "AWS::AccountId"
SourceArn: !GetAtt bucket.Arn