Description
When several AWS::Serverless::Function resources share an execution role, permissions needed by one function may also be granted to the others. Separate access according to each function’s purpose and required resources. Different role names alone do not establish least privilege; inspect the attached policies too.
Potential impact
- A compromised or malfunctioning function may access resources outside its intended work.
- Changing a shared role’s policy can affect the permissions and behavior of several functions.
Remediation
- Identify each function’s required actions and resources and separate execution roles accordingly. Keep unnecessary permissions out even when reusing policies.
- Verify the role’s trust policy and actual permissions, then test required calls and rejection of unintended access.
Examples
Set FunctionImage to the actual ECR image URI to deploy. Replace the role ARNs with existing roles in your account that Lambda can assume. Their permission policies are not defined in these examples.
Before
Transform: AWS::Serverless-2016-10-31
Parameters:
FunctionImage:
Type: String
Resources:
Function1:
Type: AWS::Serverless::Function
Properties:
PackageType: Image
ImageUri: !Ref FunctionImage
Role: arn:aws:iam::123456789012:role/lambda-role
Function2:
Type: AWS::Serverless::Function
Properties:
PackageType: Image
ImageUri: !Ref FunctionImage
Role: arn:aws:iam::123456789012:role/lambda-role
Both functions use the same execution role. If their permission needs differ, sharing the role may grant unnecessary access.
After
Transform: AWS::Serverless-2016-10-31
Parameters:
FunctionImage:
Type: String
Resources:
Function1:
Type: AWS::Serverless::Function
Properties:
PackageType: Image
ImageUri: !Ref FunctionImage
Role: arn:aws:iam::123456789012:role/function1-role
Function2:
Type: AWS::Serverless::Function
Properties:
PackageType: Image
ImageUri: !Ref FunctionImage
Role: arn:aws:iam::123456789012:role/function2-role
Each function uses a separate role. Restrict each role’s policies to the function’s actual needs rather than relying on its name.