Serverless functions share an execution role

Review each function’s execution role and policies so it does not inherit permissions needed only by another function.

Description

When several AWS::Serverless::Function resources share an execution role, permissions needed by one function may also be granted to the others. Separate access according to each function’s purpose and required resources. Different role names alone do not establish least privilege; inspect the attached policies too.

Potential impact

  • A compromised or malfunctioning function may access resources outside its intended work.
  • Changing a shared role’s policy can affect the permissions and behavior of several functions.

Remediation

  • Identify each function’s required actions and resources and separate execution roles accordingly. Keep unnecessary permissions out even when reusing policies.
  • Verify the role’s trust policy and actual permissions, then test required calls and rejection of unintended access.

Examples

Set FunctionImage to the actual ECR image URI to deploy. Replace the role ARNs with existing roles in your account that Lambda can assume. Their permission policies are not defined in these examples.

Before

yaml
Transform: AWS::Serverless-2016-10-31
Parameters:
  FunctionImage:
    Type: String
Resources:
  Function1:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: !Ref FunctionImage
      Role: arn:aws:iam::123456789012:role/lambda-role

  Function2:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: !Ref FunctionImage
      Role: arn:aws:iam::123456789012:role/lambda-role

Both functions use the same execution role. If their permission needs differ, sharing the role may grant unnecessary access.

After

yaml
Transform: AWS::Serverless-2016-10-31
Parameters:
  FunctionImage:
    Type: String
Resources:
  Function1:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: !Ref FunctionImage
      Role: arn:aws:iam::123456789012:role/function1-role

  Function2:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      ImageUri: !Ref FunctionImage
      Role: arn:aws:iam::123456789012:role/function2-role

Each function uses a separate role. Restrict each role’s policies to the function’s actual needs rather than relying on its name.

References