Lambda invocation permission uses a wildcard principal

Name the required service or account in Lambda invocation permission and restrict its source conditions.

Description

A principal = "*" in aws_lambda_permission does not limit callers through the principal itself. Conditions such as source_arn also constrain the effective grant, so the wildcard alone does not establish that everyone can invoke the function.

Potential impact

  • Unintended callers may invoke the function if other conditions do not sufficiently restrict access.
  • Repeated calls can increase costs or misuse the functionality exposed by the function.

Remediation

Specify only the required service or account in principal. For service invocations, restrict source_arn and applicable source-account conditions, then verify that only intended events can run the function.

Examples

These invocation-permission excerpts require the function and alias to be configured separately. Replace the EventBridge rule ARN with the actual account, Region, and rule.

Before

hcl
resource "aws_lambda_permission" "example" {
  statement_id  = "AllowExecutionFromCloudWatch"
  action        = "lambda:InvokeFunction"
  function_name = aws_lambda_function.test_lambda.function_name
  principal     = "*"
  source_arn    = "arn:aws:events:eu-west-1:111122223333:rule/RunDaily"
  qualifier     = aws_lambda_alias.test_alias.name
}

After

hcl
resource "aws_lambda_permission" "example" {
  statement_id  = "AllowExecutionFromCloudWatch"
  action        = "lambda:InvokeFunction"
  function_name = aws_lambda_function.test_lambda.function_name
  principal     = "events.amazonaws.com"
  source_arn    = "arn:aws:events:eu-west-1:111122223333:rule/RunDaily"
  qualifier     = aws_lambda_alias.test_alias.name
}

The original grant already has a source_arn condition for one rule. The revision retains that condition and additionally limits the principal to the EventBridge service.

References