AWS S3配置Lambda触发器报错后,如何通过命令行创建触发器?
Got it, let's work through this together. That "unable to validate destination configurations" error almost always boils down to permission issues between S3 and your Lambda function—so we'll fix that first, then walk through creating the trigger via the AWS CLI.
S3 can't trigger your Lambda function unless you explicitly grant it permission, and your Lambda's resource policy needs to whitelist the bucket as a valid trigger source. Skip this step, and the CLI will throw the same error as the UI.
Add a permission policy to your Lambda function
Run this AWS CLI command to grant S3 the right to invoke your Lambda. Swap in your own values for the placeholders:aws lambda add-permission \ --function-name "your-lambda-function-name" \ --principal s3.amazonaws.com \ --statement-id "s3-bucket-trigger-allowance" \ --action "lambda:InvokeFunction" \ --source-arn "arn:aws:s3:::your-target-bucket-name" \ --source-account "your-12-digit-aws-account-id"--function-name: Use your Lambda's name or full ARN--principal: Specifies S3 as the allowed caller--statement-id: A unique, descriptive ID for this permission rule (e.g.,s3-trigger-for-my-bucket)--action: Grants permission to invoke the Lambda function--source-arn: The full ARN of your S3 bucket--source-account: Your 12-digit AWS account ID
Confirm the policy was added
Double-check with this command to ensure the permission is in place:aws lambda get-policy --function-name "your-lambda-function-name"
Now that permissions are sorted, let's create the trigger with the exact settings you used in the UI:
Run this put-bucket-notification-configuration command, replacing the placeholders with your values:
aws s3api put-bucket-notification-configuration \ --bucket "your-target-bucket-name" \ --notification-configuration '{ "LambdaFunctionConfigurations": [ { "Id": "your-event-name", "LambdaFunctionArn": "arn:aws:lambda:your-region:your-account-id:function:your-lambda-function-name", "Events": ["s3:ObjectCreated:*"], "Filter": { "Key": { "FilterRules": [ { "Name": "prefix", "Value": "your-desired-prefix" }, { "Name": "suffix", "Value": "your-desired-suffix" } ] } } } ] }'
What each part maps to your UI settings:
Id: Matches the "Event name" field from the S3 UILambdaFunctionArn: Your Lambda function's full ARN (copy this directly from the Lambda console)Events:["s3:ObjectCreated:*"]is the CLI equivalent of "All object create events" in the UIFilterRules: Sets your desired prefix and suffix (exact match for the UI's Prefix/Suffix fields)
Check that the notification configuration was applied correctly with this command:
aws s3api get-bucket-notification-configuration --bucket "your-target-bucket-name"
Quick Troubleshooting Tips:
- Ensure your AWS CLI is configured for the correct region (run
aws configureto check/update) - Double-check that the Lambda ARN and bucket ARN are spelled correctly
- If you still get errors, confirm that your CLI credentials have permissions to modify bucket notifications and Lambda policies
内容的提问来源于stack exchange,提问作者RK.

