AWS策略JSON中的‘document’字段是什么?Lambda执行角色策略中该字段含义解析
document Field in AWS IAM Policies & Lambda Execution Roles Great question—this is a core piece of AWS IAM that trips up many beginners, so let’s break it down clearly.
What is document in AWS Policy JSON?
In AWS’s IAM system, the document field is the core permission-defining block of any policy. It’s a JSON object that follows AWS’s standard IAM policy syntax, holding all the rules that determine which actions are allowed/denied, which resources those actions apply to, and any conditions that must be met for the policy to take effect.
Every valid document includes two required top-level keys:
Version: Specifies the policy syntax version (almost always2012-10-17, the latest and most flexible standard)Statement: An array of individual permission rules—each statement defines a single allow/deny rule for specific actions and resources.
Think of the document as the "rulebook" IAM uses to check if a request (like a Lambda function trying to access S3) should be permitted.
What does document refer to in your Lambda Execution Role policy?
In the Lambda execution role snippet you shared:
{ "roleName": "lambda_role", "policies": [ { "document": { "version": "2012-10-17", "statement": [ . . .(续) ] } } ] }
This document is the permission policy attached to your Lambda execution role.
Lambda execution roles are specialized IAM roles that grant Lambda functions the permissions they need to run and interact with other AWS services. The document here defines exactly what that Lambda function is allowed to do—for example, if your function needs to read data from a DynamoDB table or write logs to CloudWatch, those permissions would be spelled out in the Statement array inside this document.
For context, here’s a quick example of what that document might look like if your Lambda needs access to CloudWatch Logs and a specific S3 bucket:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents" ], "Resource": "arn:aws:logs:*:*:*" }, { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-lambda-bucket/*" } ] }
内容的提问来源于stack exchange,提问作者siddhu mk

