使用CloudFormation/SAM创建Lambda Function URL后出现403访问禁止问题
问题分析与解决方案
问题原因
用SAM/CloudFormation创建Lambda Function URL时,哪怕设置了AuthType: NONE,也不会自动生成允许Function URL调用Lambda的资源级权限策略。而你在控制台点保存时,AWS会自动补全这条权限,所以保存后403错误就消失了。
解决方法
在你的SAM模板里新增AWS::Lambda::Permission资源,给Function URL加上调用Lambda的权限。修改后的完整模板如下:
AWSTemplateFormatVersion: "2010-09-09" Description: Creating single submissions download file from S3 daily files and input put parameters Transform: - AWS::Serverless-2016-10-31 Resources: GiveawayInsertFunction: Type: AWS::Serverless::Function Properties: CodeUri: ../lambdas FunctionName: giveaway_insert Handler: giveaway_insert_lambda/src/index.handler Runtime: nodejs20.x MemorySize: 128 Timeout: 10 Architectures: - x86_64 Description: Inserting giveaway submissions into the database Policies: - Version: '2012-10-17' Statement: - Effect: Allow Action: logs:CreateLogGroup Resource: arn:aws:logs:us-east-1:891377358932:* - Effect: Allow Action: - logs:CreateLogStream - logs:PutLogEvents Resource: arn:aws:logs:us-east-1:891377358932:log-group:/aws/lambda/giveaway_insert:* - Effect: Allow Action: dynamodb:PutItem Resource: arn:aws:dynamodb:us-east-1:891377358932:table/* GiveawayInsertFunctionUrl: Type: AWS::Lambda::Url Properties: AuthType: NONE TargetFunctionArn: !GetAtt GiveawayInsertFunction.Arn Cors: AllowOrigins: - "*" AllowMethods: - "*" AllowHeaders: - "*" MaxAge: 600 # 新增权限配置 GiveawayInsertFunctionUrlPermission: Type: AWS::Lambda::Permission Properties: FunctionName: !GetAtt GiveawayInsertFunction.Arn Action: lambda:InvokeFunctionUrl Principal: "*" FunctionUrlAuthType: NONE
重点说明
- 新增的
AWS::Lambda::Permission明确允许所有匿名用户(Principal: "*")通过无认证的Function URL调用Lambda。 FunctionUrlAuthType: NONE必须和Function URL的AuthType保持一致,确保权限规则匹配。- 部署修改后的模板后,不用再手动去控制台操作,Function URL就能正常处理请求。
内容的提问来源于stack exchange,提问作者Aram Tadevosyan
相关产品推荐
相关产品推荐

