Review the action in Lambda permission

The action in a Lambda resource policy should match the purpose of the grant.

Description

An action in aws_lambda_permission that does not match its purpose can prevent required invocation or grant unnecessary permissions. Function invocation requires lambda:InvokeFunction, but Lambda resource policies can also allow other supported actions, such as lambda:GetFunction.

Potential impact

  • An event source may fail to invoke the function, delaying or interrupting processing.
  • Unnecessary action permissions complicate policy management and access control.

Remediation

Set action to lambda:InvokeFunction when the purpose is function invocation. For other actions, confirm the need and service support. Restrict principal and source_arn to the required scope and test the intended integration after deployment.

Examples

These excerpts grant CloudWatch Logs permission to invoke a function. Configure the referenced function and log group separately.

Before

hcl
resource "aws_lambda_permission" "example" {
  action        = "lambda:DeleteFunction"
  function_name = aws_lambda_function.logging.function_name
  principal     = "logs.eu-west-1.amazonaws.com"
  source_arn    = "${aws_cloudwatch_log_group.default.arn}:*"
}

After

hcl
resource "aws_lambda_permission" "example" {
  action        = "lambda:InvokeFunction"
  function_name = aws_lambda_function.logging.function_name
  principal     = "logs.eu-west-1.amazonaws.com"
  source_arn    = "${aws_cloudwatch_log_group.default.arn}:*"
}

lambda:DeleteFunction is not the invocation permission needed for this log-delivery integration. The revision grants invocation to the same principal and log-group source.

References