跨CloudFormation栈WebSocket调用Lambda遇Forbidden错误排查
在CloudFormation栈(代理服务)中部署的WebSocket已实现前端成功连接,但调用跨栈Lambda的startFeedback路由时始终返回{"message": "Forbidden", "connectionId":"myConnectionID", "requestId":"myRequestId"},而同栈的$connect路由调用正常。
相关配置代码如下:
WebSocket路由定义
startFeedbackWebsocketsRoute: Type: 'AWS::ApiGatewayV2::Route' DependsOn: - 'WebsocketsApi' - 'FeedbackFlowStartFeedbackWebsocketsIntegration' Properties: ApiId: Ref: 'WebsocketsApi' RouteKey: 'startFeedback' AuthorizationType: 'NONE' Target: Fn::Join: - '/' - - 'integrations' - Ref: 'FeedbackFlowStartFeedbackWebsocketsIntegration'
集成配置
FeedbackFlowStartFeedbackWebsocketsIntegration: Type: 'AWS::ApiGatewayV2::Integration' DependsOn: 'WebsocketsApi' Properties: ApiId: Ref: 'WebsocketsApi' IntegrationType: 'AWS_PROXY' IntegrationUri: Fn::Join: - '' - - 'arn:' - Ref: 'AWS::Partition' - ':apigateway:' - Ref: 'AWS::Region' - ':lambda:path/2015-03-31/functions/' - Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn - '/invocations'
Lambda权限配置
FeedbackFlowStartFeedbackPermission: Type: 'AWS::Lambda::Permission' DependsOn: - 'WebsocketsApi' Properties: FunctionName: Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn Action: 'lambda:InvokeFunction' Principal: 'apigateway.amazonaws.com'
尝试创建关联集成的IAM角色后问题依旧:
FeedbackFlowStartFeedbackWebsocketsRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: apigateway.amazonaws.com Action: sts:AssumeRole Policies: - PolicyName: ApiGatewayInvokeLambdaPolicy PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: lambda:InvokeFunction Resource: Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn
你遗漏了以下3项关键配置:
1. 给Lambda权限添加API Gateway来源限制
当前Lambda权限仅指定了服务主体,未限制具体的API Gateway资源,导致权限验证不通过。需添加SourceArn限定只有目标WebSocket路由能触发Lambda:
FeedbackFlowStartFeedbackPermission: Type: 'AWS::Lambda::Permission' DependsOn: - 'WebsocketsApi' Properties: FunctionName: Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn Action: 'lambda:InvokeFunction' Principal: 'apigateway.amazonaws.com' SourceArn: Fn::Join: - '' - - 'arn:' - Ref: 'AWS::Partition' - ':execute-api:' - Ref: 'AWS::Region' - ':' - Ref: 'AWS::AccountId' - ':' - Ref: 'WebsocketsApi' - '/*/*/startFeedback'
SourceArn格式为arn:${partition}:execute-api:${region}:${account-id}:${api-id}/*/*/${route-key},确保权限仅对指定路由生效。
2. 集成配置关联IAM角色并补充Payload版本
你已创建API Gateway调用Lambda的IAM角色,但未在集成配置中指定该角色。需在集成配置中添加CredentialsArn属性,同时补充WebSocket代理模式必需的PayloadFormatVersion:
FeedbackFlowStartFeedbackWebsocketsIntegration: Type: 'AWS::ApiGatewayV2::Integration' DependsOn: 'WebsocketsApi' Properties: ApiId: Ref: 'WebsocketsApi' IntegrationType: 'AWS_PROXY' IntegrationUri: Fn::Join: - '' - - 'arn:' - Ref: 'AWS::Partition' - ':apigateway:' - Ref: 'AWS::Region' - ':lambda:path/2015-03-31/functions/' - Fn::ImportValue: demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn - '/invocations' CredentialsArn: Fn::GetAtt: [FeedbackFlowStartFeedbackWebsocketsRole, Arn] PayloadFormatVersion: '2.0'
添加后API Gateway会使用该角色权限调用跨栈Lambda,PayloadFormatVersion确保WebSocket代理模式的请求格式符合Lambda要求。
3. 验证跨栈导出值的准确性
确认demo-feedback-stack-${sls:stage}-FeedbackFlowStartFeedbackLambdaArn导出的ARN无拼写错误,同时检查目标栈是否已正确导出该值、当前栈是否具备导入权限。
内容的提问来源于stack exchange,提问作者Alaa

