Description
An action in aws_lambda_permission that does not match its purpose can prevent required invocation or grant unnecessary permissions. Function invocation requires lambda:InvokeFunction, but Lambda resource policies can also allow other supported actions, such as lambda:GetFunction.
Potential impact
- An event source may fail to invoke the function, delaying or interrupting processing.
- Unnecessary action permissions complicate policy management and access control.
Remediation
Set action to lambda:InvokeFunction when the purpose is function invocation. For other actions, confirm the need and service support. Restrict principal and source_arn to the required scope and test the intended integration after deployment.
Examples
These excerpts grant CloudWatch Logs permission to invoke a function. Configure the referenced function and log group separately.
Before
resource "aws_lambda_permission" "example" {
action = "lambda:DeleteFunction"
function_name = aws_lambda_function.logging.function_name
principal = "logs.eu-west-1.amazonaws.com"
source_arn = "${aws_cloudwatch_log_group.default.arn}:*"
}
After
resource "aws_lambda_permission" "example" {
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.logging.function_name
principal = "logs.eu-west-1.amazonaws.com"
source_arn = "${aws_cloudwatch_log_group.default.arn}:*"
}
lambda:DeleteFunction is not the invocation permission needed for this log-delivery integration. The revision grants invocation to the same principal and log-group source.