Description
A principal = "*" in aws_lambda_permission does not limit callers through the principal itself. Conditions such as source_arn also constrain the effective grant, so the wildcard alone does not establish that everyone can invoke the function.
Potential impact
- Unintended callers may invoke the function if other conditions do not sufficiently restrict access.
- Repeated calls can increase costs or misuse the functionality exposed by the function.
Remediation
Specify only the required service or account in principal. For service invocations, restrict source_arn and applicable source-account conditions, then verify that only intended events can run the function.
Examples
These invocation-permission excerpts require the function and alias to be configured separately. Replace the EventBridge rule ARN with the actual account, Region, and rule.
Before
resource "aws_lambda_permission" "example" {
statement_id = "AllowExecutionFromCloudWatch"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.test_lambda.function_name
principal = "*"
source_arn = "arn:aws:events:eu-west-1:111122223333:rule/RunDaily"
qualifier = aws_lambda_alias.test_alias.name
}
After
resource "aws_lambda_permission" "example" {
statement_id = "AllowExecutionFromCloudWatch"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.test_lambda.function_name
principal = "events.amazonaws.com"
source_arn = "arn:aws:events:eu-west-1:111122223333:rule/RunDaily"
qualifier = aws_lambda_alias.test_alias.name
}
The original grant already has a source_arn condition for one rule. The revision retains that condition and additionally limits the principal to the EventBridge service.