运行调用Lambda函数的Step Function所需权限排查:角色信任策略错误及缺失策略咨询
Let's break down and fix the error you're seeing: "Neither the global service principal states.amazonaws.com, nor the regional one is authorized to assume the provided role."
Root Cause
Your processing_lambda_role IAM role currently only allows the Lambda service to assume it (via its trust policy). But Step Functions needs permission to assume this role to execute your Lambda task—this is exactly what the error is complaining about.
Step-by-Step Fixes
1. Update the Role's Trust Policy
First, modify the aws_iam_role.processing_lambda_role resource to include Step Functions as an allowed service principal. This tells AWS that Step Functions is permitted to assume this role:
resource "aws_iam_role" "processing_lambda_role" { name = local.name path = "/service-role/" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Effect = "Allow" Principal = { Service = "lambda.amazonaws.com" } Action = "sts:AssumeRole" }, // Add this block for Step Functions { Effect = "Allow" Principal = { Service = "states.amazonaws.com" } Action = "sts:AssumeRole" } ] }) }
Note: If you're working in a region where regional service principals are required (rare, but possible), replace states.amazonaws.com with your region-specific principal (e.g., us-east-1.states.amazonaws.com).
2. Clean Up Unnecessary Permissions
Your sfn_policy includes an sts:AssumeRole action that's redundant and unnecessary here. That permission would grant the role itself the ability to assume other roles, but Step Functions' access to this role is controlled by the trust policy above. Remove that statement, and also lock down the Lambda resource to your specific function (following the principle of least privilege):
resource "aws_iam_role_policy" "sfn_policy" { policy = jsonencode( { "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "lambda:InvokeFunction", "lambda:InvokeAsync" ], // Restrict to your specific Lambda ARN instead of * "Resource": "${aws_lambda_function.process_zip_files_lambda.arn}" }, { "Effect": "Allow", "Action": [ "states:StartExecution" ], "Resource": "*" } ] } ) role = aws_iam_role.processing_lambda_role.id }
Why This Works
- The updated trust policy explicitly grants Step Functions permission to assume your role, resolving the core authorization error.
- Removing the redundant
sts:AssumeRolepermission cleans up your policy and avoids confusion about where access controls are applied. - Restricting the Lambda resource to your specific function reduces your security footprint by only granting the exact permissions needed.
After applying these changes, your Step Function should be able to assume the role and successfully invoke your Lambda function.
内容的提问来源于stack exchange,提问作者x89

