Review IAM resource scope for Lambda InvokeFunction

Limit Lambda invocation permission to the required function, version, or alias ARN.

Description

An IAM policy that allows lambda:InvokeFunction on overly broad resources can permit unintended function calls. Restrict the Region, account, and version or alias scope as well as the function name to the required targets.

Potential impact

  • Unapproved function execution can misuse application features or increase costs.
  • New functions or aliases can fall within a broad pattern and unintentionally expand access.

Remediation

Allow only the function, version, or alias ARNs actually used for invocation. Specify the Region and account, and do not routinely add both unqualified and qualified ARNs. Test required invocations and those that should be denied.

Examples

These are IAM policy excerpts. Review the identity using the policy and other applicable permissions separately, and replace the example Region and account with actual values.

Before

hcl
resource "aws_iam_policy" "example" {
  name = "policy"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "lambda:InvokeFunction",
        ]
        Effect   = "Allow"
        Resource = [
          "arn:aws:lambda:us-east-1:123456789012:function:*:*"
        ]
      },
    ]
  })
}

After

hcl
resource "aws_iam_policy" "example" {
  name = "policy"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "lambda:InvokeFunction",
        ]
        Effect   = "Allow"
        Resource = [
          "arn:aws:lambda:us-east-1:123456789012:function:approved-function",
          "arn:aws:lambda:us-east-1:123456789012:function:approved-function:*"
        ]
      },
    ]
  })
}

The revision narrows the function name to approved-function, but retains :* for all versions and aliases. Use the exact required ARNs in practice. Both ARN forms are not always needed.

References