You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨CloudFormation栈WebSocket调用Lambda遇Forbidden错误排查

问题描述

在CloudFormation栈(代理服务)中部署的WebSocket已实现前端成功连接,但调用跨栈Lambda的startFeedback路由时始终返回{"message": "Forbidden", "connectionId":"myConnectionID", "requestId":"myRequestId"},而同栈的$connect路由调用正常。

相关配置代码如下:

WebSocket路由定义

startFeedbackWebsocketsRoute:
    Type: 'AWS::ApiGatewayV2::Route'
    DependsOn:
      - 'WebsocketsApi'
      - 'FeedbackFlowStartFeedbackWebsocketsIntegration'
    Properties:
      ApiId:
        Ref: 'WebsocketsApi'
      RouteKey: 'startFeedback'
      AuthorizationType: 'NONE'
      Target:
        Fn::Join:
          - '/'
          - - 'integrations'
            - Ref: 'FeedbackFlowStartFeedbackWebsocketsIntegration'

集成配置

FeedbackFlowStartFeedbackWebsocketsIntegration:
    Type: 'AWS::ApiGatewayV2::Integration'
    DependsOn: 'WebsocketsApi'
    Properties:
      ApiId:
        Ref: 'WebsocketsApi'
      IntegrationType: 'AWS_PROXY'
      IntegrationUri:
        Fn::Join:
          - ''
          - - 'arn:'
            - Ref: 'AWS::Partition'
            - ':apigateway:'
            - Ref: 'AWS::Region'
            - ':lambda:path/2015-03-31/functions/'
            - Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn
            - '/invocations'

Lambda权限配置

FeedbackFlowStartFeedbackPermission:
    Type: 'AWS::Lambda::Permission'
    DependsOn:
      - 'WebsocketsApi'
    Properties:
      FunctionName:
            Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn
      Action: 'lambda:InvokeFunction'
      Principal: 'apigateway.amazonaws.com'

尝试创建关联集成的IAM角色后问题依旧:

FeedbackFlowStartFeedbackWebsocketsRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: apigateway.amazonaws.com
            Action: sts:AssumeRole
      Policies:
        - PolicyName: ApiGatewayInvokeLambdaPolicy
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action: lambda:InvokeFunction
                Resource: 
                  Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn

解决方案

你遗漏了以下3项关键配置:

1. 给Lambda权限添加API Gateway来源限制

当前Lambda权限仅指定了服务主体,未限制具体的API Gateway资源,导致权限验证不通过。需添加SourceArn限定只有目标WebSocket路由能触发Lambda:

FeedbackFlowStartFeedbackPermission:
    Type: 'AWS::Lambda::Permission'
    DependsOn:
      - 'WebsocketsApi'
    Properties:
      FunctionName:
            Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn
      Action: 'lambda:InvokeFunction'
      Principal: 'apigateway.amazonaws.com'
      SourceArn:
        Fn::Join:
          - ''
          - - 'arn:'
            - Ref: 'AWS::Partition'
            - ':execute-api:'
            - Ref: 'AWS::Region'
            - ':'
            - Ref: 'AWS::AccountId'
            - ':'
            - Ref: 'WebsocketsApi'
            - '/*/*/startFeedback'

SourceArn格式为arn:${partition}:execute-api:${region}:${account-id}:${api-id}/*/*/${route-key},确保权限仅对指定路由生效。

2. 集成配置关联IAM角色并补充Payload版本

你已创建API Gateway调用Lambda的IAM角色,但未在集成配置中指定该角色。需在集成配置中添加CredentialsArn属性,同时补充WebSocket代理模式必需的PayloadFormatVersion:

FeedbackFlowStartFeedbackWebsocketsIntegration:
    Type: 'AWS::ApiGatewayV2::Integration'
    DependsOn: 'WebsocketsApi'
    Properties:
      ApiId:
        Ref: 'WebsocketsApi'
      IntegrationType: 'AWS_PROXY'
      IntegrationUri:
        Fn::Join:
          - ''
          - - 'arn:'
            - Ref: 'AWS::Partition'
            - ':apigateway:'
            - Ref: 'AWS::Region'
            - ':lambda:path/2015-03-31/functions/'
            - Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn
            - '/invocations'
      CredentialsArn:
        Fn::GetAtt: [FeedbackFlowStartFeedbackWebsocketsRole, Arn]
      PayloadFormatVersion: '2.0'

添加后API Gateway会使用该角色权限调用跨栈Lambda,PayloadFormatVersion确保WebSocket代理模式的请求格式符合Lambda要求。

3. 验证跨栈导出值的准确性

确认demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn导出的ARN无拼写错误,同时检查目标栈是否已正确导出该值、当前栈是否具备导入权限。


内容的提问来源于stack exchange,提问作者Alaa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 03:24:53