You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Lambda调用SNS遇AuthorizationError,添加权限策略后仍报错求助

解决Lambda调用SNS Publish的权限错误问题

问题重现

测试Lambda函数时收到如下权限错误:

{
    "errorMessage": "An error occurred (AuthorizationError) when calling the Publish operation: User: arn:aws:sts::466331843672:assumed-role/pill_dispense-role-57u2gjjb/pill_dispense is not authorized to perform: SNS:Publish on resource: arn:aws:sns:ap-southeast-1:466331843672:smart_pill_sns because no identity-based policy allows the SNS:Publish action",
    "errorType": "AuthorizationErrorException",
    "requestId": "11a58023-8c8d-4942-ad88-1f8a12b0c0d6",
    "stackTrace": [
        "  File \"/var/task/lambda_function.py\", line 19, in lambda_handler\n    response = sns.publish(\n",
        "  File \"/var/runtime/botocore/client.py\", line 391, in _api_call\n    return self._make_api_call(operation_name, kwargs)\n",
        "  File \"/var/runtime/botocore/client.py\", line 719, in _make_api_call\n    raise error_class(parsed_response, operation_name)\n"
    ]
}

为Lambda关联角色添加内联策略后问题依旧:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "sns:Publish",
            "Resource": "arn:aws:sns:ap-southeast-1:466331843672:smart_pill_sns"
        },
        {
            "Effect": "Allow",
            "Action": [
                "sns:Publish",
                "SNS:GetTopicAttributes",
                "SNS:SetTopicAttributes",
                "SNS:AddPermission",
                "SNS:RemovePermission",
                "SNS:DeleteTopic",
                "SNS:ListSubscriptionsByTopic",
                "SNS:Subscribe"
            ],
            "Resource": "*"
        }
    ]
}

排查与解决步骤

  • 修正IAM策略的Action大小写
    AWS IAM策略中服务标识符部分需统一为小写,将策略中所有大写的SNS:替换为sns:,修正后的策略如下:

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": "sns:Publish",
                "Resource": "arn:aws:sns:ap-southeast-1:466331843672:smart_pill_sns"
            },
            {
                "Effect": "Allow",
                "Action": [
                    "sns:Publish",
                    "sns:GetTopicAttributes",
                    "sns:SetTopicAttributes",
                    "sns:AddPermission",
                    "sns:RemovePermission",
                    "sns:DeleteTopic",
                    "sns:ListSubscriptionsByTopic",
                    "sns:Subscribe"
                ],
                "Resource": "*"
            }
        ]
    }
    
  • 确认Lambda函数关联的角色正确
    进入Lambda函数配置页面,检查「执行角色」是否为pill_dispense-role-57u2gjjb,若角色选错,切换到正确角色并保存配置。

  • 验证角色的信任策略
    检查该IAM角色的信任策略是否允许Lambda服务扮演此角色,信任策略需包含以下内容:

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Principal": {
                    "Service": "lambda.amazonaws.com"
                },
                "Action": "sts:AssumeRole"
            }
        ]
    }
    

    若信任策略缺失或不正确,补充后保存。

  • 等待IAM策略生效
    IAM策略变更后可能存在1-2分钟的延迟,等待后重新测试Lambda函数。

  • 检查SNS主题的资源策略(可选)
    进入SNS主题配置页面,查看「访问策略」是否未拒绝该角色执行sns:Publish的请求,确保资源策略未限制角色访问。

内容的提问来源于stack exchange,提问作者Dhyan Prasad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 09:34:55