You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用CloudFormation/SAM创建Lambda Function URL后出现403访问禁止问题

问题分析与解决方案

问题原因

用SAM/CloudFormation创建Lambda Function URL时,哪怕设置了AuthType: NONE,也不会自动生成允许Function URL调用Lambda的资源级权限策略。而你在控制台点保存时,AWS会自动补全这条权限,所以保存后403错误就消失了。

解决方法

在你的SAM模板里新增AWS::Lambda::Permission资源,给Function URL加上调用Lambda的权限。修改后的完整模板如下:

AWSTemplateFormatVersion: "2010-09-09"
Description: Creating single submissions download file from S3 daily files and input put parameters

Transform:
  - AWS::Serverless-2016-10-31

Resources:
  GiveawayInsertFunction:
    Type: AWS::Serverless::Function
    Properties:
      CodeUri: ../lambdas
      FunctionName: giveaway_insert
      Handler: giveaway_insert_lambda/src/index.handler
      Runtime: nodejs20.x
      MemorySize: 128
      Timeout: 10
      Architectures:
        - x86_64
      Description: Inserting giveaway submissions into the database
      Policies:
        - Version: '2012-10-17'
          Statement:
            - Effect: Allow
              Action: logs:CreateLogGroup
              Resource: arn:aws:logs:us-east-1:891377358932:*
            - Effect: Allow
              Action:
                - logs:CreateLogStream
                - logs:PutLogEvents
              Resource: arn:aws:logs:us-east-1:891377358932:log-group:/aws/lambda/giveaway_insert:*
            - Effect: Allow
              Action: dynamodb:PutItem
              Resource: arn:aws:dynamodb:us-east-1:891377358932:table/*

  GiveawayInsertFunctionUrl:
    Type: AWS::Lambda::Url
    Properties:
      AuthType: NONE
      TargetFunctionArn: !GetAtt GiveawayInsertFunction.Arn
      Cors:
        AllowOrigins:
          - "*"
        AllowMethods:
          - "*"
        AllowHeaders:
          - "*"
        MaxAge: 600

  # 新增权限配置
  GiveawayInsertFunctionUrlPermission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !GetAtt GiveawayInsertFunction.Arn
      Action: lambda:InvokeFunctionUrl
      Principal: "*"
      FunctionUrlAuthType: NONE

重点说明

  • 新增的AWS::Lambda::Permission明确允许所有匿名用户(Principal: "*")通过无认证的Function URL调用Lambda。
  • FunctionUrlAuthType: NONE必须和Function URL的AuthType保持一致,确保权限规则匹配。
  • 部署修改后的模板后,不用再手动去控制台操作,Function URL就能正常处理请求。

内容的提问来源于stack exchange,提问作者Aram Tadevosyan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 17:17:05