Lambda调用SNS遇AuthorizationError,添加权限策略后仍报错求助
解决Lambda调用SNS Publish的权限错误问题
问题重现
测试Lambda函数时收到如下权限错误:
{ "errorMessage": "An error occurred (AuthorizationError) when calling the Publish operation: User: arn:aws:sts::466331843672:assumed-role/pill_dispense-role-57u2gjjb/pill_dispense is not authorized to perform: SNS:Publish on resource: arn:aws:sns:ap-southeast-1:466331843672:smart_pill_sns because no identity-based policy allows the SNS:Publish action", "errorType": "AuthorizationErrorException", "requestId": "11a58023-8c8d-4942-ad88-1f8a12b0c0d6", "stackTrace": [ " File \"/var/task/lambda_function.py\", line 19, in lambda_handler\n response = sns.publish(\n", " File \"/var/runtime/botocore/client.py\", line 391, in _api_call\n return self._make_api_call(operation_name, kwargs)\n", " File \"/var/runtime/botocore/client.py\", line 719, in _make_api_call\n raise error_class(parsed_response, operation_name)\n" ] }
为Lambda关联角色添加内联策略后问题依旧:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "sns:Publish", "Resource": "arn:aws:sns:ap-southeast-1:466331843672:smart_pill_sns" }, { "Effect": "Allow", "Action": [ "sns:Publish", "SNS:GetTopicAttributes", "SNS:SetTopicAttributes", "SNS:AddPermission", "SNS:RemovePermission", "SNS:DeleteTopic", "SNS:ListSubscriptionsByTopic", "SNS:Subscribe" ], "Resource": "*" } ] }
排查与解决步骤
修正IAM策略的Action大小写
AWS IAM策略中服务标识符部分需统一为小写,将策略中所有大写的SNS:替换为sns:,修正后的策略如下:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "sns:Publish", "Resource": "arn:aws:sns:ap-southeast-1:466331843672:smart_pill_sns" }, { "Effect": "Allow", "Action": [ "sns:Publish", "sns:GetTopicAttributes", "sns:SetTopicAttributes", "sns:AddPermission", "sns:RemovePermission", "sns:DeleteTopic", "sns:ListSubscriptionsByTopic", "sns:Subscribe" ], "Resource": "*" } ] }确认Lambda函数关联的角色正确
进入Lambda函数配置页面,检查「执行角色」是否为pill_dispense-role-57u2gjjb,若角色选错,切换到正确角色并保存配置。验证角色的信任策略
检查该IAM角色的信任策略是否允许Lambda服务扮演此角色,信任策略需包含以下内容:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "lambda.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }若信任策略缺失或不正确,补充后保存。
等待IAM策略生效
IAM策略变更后可能存在1-2分钟的延迟,等待后重新测试Lambda函数。检查SNS主题的资源策略(可选)
进入SNS主题配置页面,查看「访问策略」是否未拒绝该角色执行sns:Publish的请求,确保资源策略未限制角色访问。
内容的提问来源于stack exchange,提问作者Dhyan Prasad
相关产品推荐
相关产品推荐

