Lambda function policy grants broad actions

Limit permissions to required function actions, callers and sources.

Description

A Lambda function’s resource-based policy manages access to that function by other accounts or services. Specify the required actions instead of a broad lambda:* grant, and restrict the actual event source when trusting a service principal.

These permissions are separate from the execution role used by the function’s code. A function policy grant should not be interpreted as administrative access to all Lambda functions in the account.

Potential impact

  • An overly broad grant may permit function access from unintended event sources.
  • Unwanted invocations can increase costs or misuse the data and workflows handled by the function.

Remediation

  • For ordinary function invocation, allow only the required action, such as lambda:InvokeFunction.
  • Restrict principal and review source_arn and source_account conditions appropriate to the service. For S3, restrict the actual bucket ARN and owner account.
  • Verify that intended event invocations succeed and unapproved sources are denied. Minimize the execution role’s permissions separately.

Examples

These excerpts show permissions for different S3 and EventBridge integrations. Define the referenced functions separately and replace the EventBridge rule ARN with the actual value. Configure the event source and function target separately too.

Before

hcl
resource "aws_lambda_permission" "allow_all" {
  statement_id  = "AllowAllResources"
  action        = "lambda:*"
  function_name = aws_lambda_function.my_lambda.function_name
  principal     = "s3.amazonaws.com"
}

This grants lambda:* to the S3 service without a source-bucket restriction. Limit it to the required invocation action and bucket and owner account.

After

hcl
resource "aws_lambda_permission" "allow_cloudwatch" {
  statement_id  = "AllowExecutionFromCloudWatch"
  action        = "lambda:InvokeFunction"
  function_name = aws_lambda_function.test_lambda.function_name
  principal     = "events.amazonaws.com"
  source_arn    = "arn:aws:events:eu-west-1:111122223333:rule/RunDaily"
}

This alternative permits invocation from the specified EventBridge rule. It is not a direct replacement for an existing S3 integration.

References