Broad privileges in a Serverless Framework IAM role

A function execution role allows all actions on all resources

Description

An IAM statement combining Effect: Allow, Action: "*" and Resource: "*" grants permissions for all actions and resources. Even where other policies impose limits, an execution role should contain only the permissions its functions need.

Potential impact

A compromised function or code error may affect the reading, modification or deletion of many AWS resources.

Remediation

Specify the required actions and target resources in provider.iam.role.statements. Grant actions that do not support resource scoping separately, with applicable conditions.

Examples

The statement in these excerpts grants only s3:GetObject for objects in example-bucket. Function definitions and other required permissions, such as logging, are omitted.

Before

yaml
service: service
frameworkVersion: "4"
provider:
  name: aws
  runtime: nodejs22.x
  iam:
    role:
      statements:
        - Effect: Allow
          Resource: "*"
          Action: "*"

After

yaml
service: service
frameworkVersion: "4"
provider:
  name: aws
  runtime: nodejs22.x
  iam:
    role:
      statements:
        - Effect: Allow
          Resource: arn:aws:s3:::example-bucket/*
          Action:
            - s3:GetObject

References