Review the scope of API Gateway permission to invoke Lambda

Limit API Gateway permission to invoke Lambda to the required stage, method, and path.

Description

A broad source_arn in Lambda permission for API Gateway can allow invocation from unintended stages or methods. This permission authorizes the API Gateway service to invoke the function; it does not authenticate or authorize API clients.

Potential impact

  • An unintended API route could invoke the function if it is configured to use that integration.
  • Weak client access controls can compound this exposure, allowing misuse and higher execution costs.

Remediation

Limit source_arn to the required API stage, HTTP method, and resource path. Configure API method authentication and authorization separately, then verify that approved requests succeed and invocations from unnecessary routes are denied.

Examples

These excerpts show Lambda invocation permission. Configure the referenced API and function separately. Replace prod, GET, and orders with the actual deployment stage, method, and path.

Before

hcl
resource "aws_lambda_permission" "example" {
  statement_id  = "AllowAPIGatewayInvoke"
  action        = "lambda:InvokeFunction"
  function_name = aws_lambda_function.example.function_name
  principal     = "apigateway.amazonaws.com"
  source_arn    = "${aws_api_gateway_rest_api.example.execution_arn}/*/*"
}

After

hcl
resource "aws_lambda_permission" "example" {
  statement_id  = "AllowAPIGatewayInvoke"
  action        = "lambda:InvokeFunction"
  function_name = aws_lambda_function.example.function_name
  principal     = "apigateway.amazonaws.com"
  source_arn    = "${aws_api_gateway_rest_api.example.execution_arn}/prod/GET/orders"
}

The revised grant is limited to GET /orders in the prod stage. This change alone does not configure user authentication for the API.

References