使用Serverless Framework创建AWS Lambda函数时遇403权限拒绝错误
问题:Serverless部署Lambda函数时出现AccessDeniedException错误
问题背景
尝试运行Serverless的「Python HTTP API」Lambda示例,生成了如下serverless.yaml文件,仅添加了区域以及本地通过aws configure配置的lambda-user配置文件:
service: aws-python-http-api-project frameworkVersion: '3' provider: name: aws runtime: python3.9 stage: dev region: ap-south-1 profile: lambda-user functions: hello: handler: handler.hello events: - httpApi: path: / method: get
lambda-user这个AWS用户拥有以下权限:
- AmazonAPIGatewayAdministrator
- AmazonS3FullAccess
- AWSCloudFormationFullAccess
- AWSLambda_FullAccess
- AWSLambdaRole
- CloudWatchLogsFullAccess
- IAMFullAccess
运行serverless deploy时无法创建Lambda函数,报错如下:
serverless deploy Deploying aws-python-http-api-project to stage dev (ap-south-1) Warning: Not authorized to perform: lambda:GetFunction for at least one of the lambda functions. Deployment will not be skipped even if service files did not change. ✖ Stack aws-python-http-api-project-dev failed to deploy (74s) Environment: darwin, node 17.2.0, framework 3.28.1, plugin 6.2.3, SDK 4.3.2 Credentials: Local, "lambda-user" profile Docs: docs.serverless.com Support: forum.serverless.com Bugs: github.com/serverless/serverless/issues Error: CREATE_FAILED: HelloLambdaFunction (AWS::Lambda::Function) Resource handler returned message: "Service returned error code AccessDeniedException (Service: Lambda, Status Code: 403, Request ID: d7ea8db6-1a2f-4035-ae12-3c8ce1a7eea0)" (RequestToken: fef6b145-da36-d147-337d-f8c719d5dbe5, HandlerErrorCode: GeneralServiceException)
CloudFormation堆栈事件同样显示创建Lambda函数失败,报错信息一致。
解决方案
排查后确认,问题根源是AWS账户因可疑活动被暂停,联系AWS支持团队完成账户验证后,所有服务恢复正常,部署成功。
内容的提问来源于stack exchange,提问作者Aditya Mishra
相关产品推荐
相关产品推荐

