Review IAM role separation for Serverless Framework functions

A shared role can grant functions permissions needed only by other functions

Description

When functions with different permission needs share an IAM execution role, each may receive permissions intended for the others. Separate roles and policies according to each function’s work.

Potential impact

A compromised function may access AWS resources unrelated to its own task.

Remediation

Use a dedicated role or supported per-function IAM configuration. Even with separate roles, restrict each policy’s actions and resources to what the function needs.

Examples

These examples assign a dedicated role to hello. Replace the sample ARN with the actual role and configure its Lambda trust policy and required execution permissions.

Before

yaml
service: service
frameworkVersion: "4"
provider:
  name: aws
  runtime: nodejs22.x

functions:
  hello:
    handler: handler.hello

After

yaml
service: service
frameworkVersion: "4"
provider:
  name: aws
  runtime: nodejs22.x

functions:
  hello:
    handler: handler.hello
    role: arn:aws:iam::123456789012:role/hello-function-role

References