You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Lambda调用STS AssumeRole带tenant_id标签权限问题排查

问题:Lambda通过STS扮演角色时权限报错

问题背景

我有一个AWS CDK应用,需要让Lambda函数通过AWS STS扮演指定角色并获取带有tenant_id标签的凭证。Lambda生成的凭证将用于虚拟浏览器,而非Lambda自身。

待扮演角色的CDK代码

const pdfUserRole = new Role(this, "PDFTenantUserRole", {
  assumedBy: new ServicePrincipal("lambda.amazonaws.com").withSessionTags(),
  description: "Role assumed by the pdf service for a user",
});

pdfUserRole.addToPolicy(
  new PolicyStatement({
    actions: ["sts:TagSession"],
    resources: ["*"],
  })
);

Lambda函数的CDK定义

this.pdfGeneratorFunction = new LambdaFunctionTypescript(
  this,
  "Handler",
  {
    tracing: Tracing.PASS_THROUGH,
    entry: getFilePath(import.meta.url, "pdf-generator-function.ts"),
    memorySize: 1536,
    layers: [],
    initialPolicy: [
      new PolicyStatement({
        resources: [pdfUserRole.roleArn],
        actions: ["sts:AssumeRole", "sts:TagSession"],
      }),
    ],
  }
);

Lambda处理程序代码(扮演角色逻辑)

const sts = new STSClient({});

const getCredentials = async (tenantId: string) => {
  return sts.send(
    new AssumeRoleCommand({
      RoleArn: userRoleArn,
      RoleSessionName: "PDFGenerator_" + tenantId,
      TransitiveTagKeys: ["tenant_id"],
      Tags: [
        {
          Key: "tenant_id",
          Value: tenantId,
        },
      ],
    })
  );
};

报错信息

User: arn:aws:sts:::assumed-role/PDFGeneratorHandlerServiceRole/PDFGeneratorHandler is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam:::role/PDFGeneratorPDFTenantUserRole

我怀疑是主体权限问题,看起来调用身份是服务角色而非Lambda本身,尝试添加两者的信任关系也无效。

问题原因与修复步骤

核心问题

待扮演角色PDFTenantUserRole的信任策略只允许lambda.amazonaws.com服务主体扮演,但实际发起AssumeRole请求的是Lambda服务角色的临时会话身份(即arn:aws:sts::...:assumed-role/...),而非Lambda服务本身。原信任策略不匹配实际调用主体,导致权限被拒绝。

修复方案

修改PDFTenantUserRole的信任策略,允许Lambda的服务角色(或其会话身份)扮演该角色:

方式1:直接指定Lambda服务角色为信任主体

const pdfUserRole = new Role(this, "PDFTenantUserRole", {
  // 替换为Lambda的服务角色作为信任主体
  assumedBy: new ArnPrincipal(this.pdfGeneratorFunction.role!.roleArn),
  description: "Role assumed by the pdf service for a user",
  // 保留会话标签支持
  maxSessionDuration: Duration.hours(1),
});

方式2:使用条件限制,允许Lambda服务角色的会话身份扮演

如果需要更灵活的控制,可以通过条件判断调用者是否为Lambda服务角色的会话:

const pdfUserRole = new Role(this, "PDFTenantUserRole", {
  assumedBy: new AnyPrincipal(),
  description: "Role assumed by the pdf service for a user",
  maxSessionDuration: Duration.hours(1),
});

// 添加信任策略条件,只允许指定Lambda服务角色的会话身份调用
pdfUserRole.assumeRolePolicy?.addStatements(
  new PolicyStatement({
    effect: Effect.ALLOW,
    principals: [new AnyPrincipal()],
    actions: ["sts:AssumeRole"],
    conditions: {
      "StringLike": {
        "aws:PrincipalArn": `${this.pdfGeneratorFunction.role!.roleArn}*`
      }
    }
  })
);

补充说明

  1. Lambda服务角色的initialPolicy已正确包含sts:AssumeRole和sts:TagSession权限,无需修改。
  2. 原代码中withSessionTags()已启用会话标签支持,修复信任策略后标签传递逻辑可正常生效。
  3. 多租户场景下的TransitiveTagKeys和Tags配置无误,修复后即可生成带租户标签的凭证。

内容的提问来源于stack exchange,提问作者pfried

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 17:33:30