Description
When functions with different permission needs share an IAM execution role, each may receive permissions intended for the others. Separate roles and policies according to each function’s work.
Potential impact
A compromised function may access AWS resources unrelated to its own task.
Remediation
Use a dedicated role or supported per-function IAM configuration. Even with separate roles, restrict each policy’s actions and resources to what the function needs.
Examples
These examples assign a dedicated role to hello. Replace the sample ARN with the actual role and configure its Lambda trust policy and required execution permissions.
Before
yaml
service: service
frameworkVersion: "4"
provider:
name: aws
runtime: nodejs22.x
functions:
hello:
handler: handler.hello
After
yaml
service: service
frameworkVersion: "4"
provider:
name: aws
runtime: nodejs22.x
functions:
hello:
handler: handler.hello
role: arn:aws:iam::123456789012:role/hello-function-role