You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

运行调用Lambda函数的Step Function所需权限排查:角色信任策略错误及缺失策略咨询

Fixing Step Function Role Authorization Error

Let's break down and fix the error you're seeing: "Neither the global service principal states.amazonaws.com, nor the regional one is authorized to assume the provided role."

Root Cause

Your processing_lambda_role IAM role currently only allows the Lambda service to assume it (via its trust policy). But Step Functions needs permission to assume this role to execute your Lambda task—this is exactly what the error is complaining about.

Step-by-Step Fixes

1. Update the Role's Trust Policy

First, modify the aws_iam_role.processing_lambda_role resource to include Step Functions as an allowed service principal. This tells AWS that Step Functions is permitted to assume this role:

resource "aws_iam_role" "processing_lambda_role" {
  name = local.name
  path = "/service-role/"
  assume_role_policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Principal = {
          Service = "lambda.amazonaws.com"
        }
        Action = "sts:AssumeRole"
      },
      // Add this block for Step Functions
      {
        Effect = "Allow"
        Principal = {
          Service = "states.amazonaws.com"
        }
        Action = "sts:AssumeRole"
      }
    ]
  })
}

Note: If you're working in a region where regional service principals are required (rare, but possible), replace states.amazonaws.com with your region-specific principal (e.g., us-east-1.states.amazonaws.com).

2. Clean Up Unnecessary Permissions

Your sfn_policy includes an sts:AssumeRole action that's redundant and unnecessary here. That permission would grant the role itself the ability to assume other roles, but Step Functions' access to this role is controlled by the trust policy above. Remove that statement, and also lock down the Lambda resource to your specific function (following the principle of least privilege):

resource "aws_iam_role_policy" "sfn_policy" {
  policy = jsonencode( {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "VisualEditor0",
        "Effect": "Allow",
        "Action": [
          "lambda:InvokeFunction",
          "lambda:InvokeAsync"
        ],
        // Restrict to your specific Lambda ARN instead of *
        "Resource": "${aws_lambda_function.process_zip_files_lambda.arn}"
      },
      {
        "Effect": "Allow",
        "Action": [
          "states:StartExecution"
        ],
        "Resource": "*"
      }
    ]
  } )
  role = aws_iam_role.processing_lambda_role.id
}

Why This Works

  • The updated trust policy explicitly grants Step Functions permission to assume your role, resolving the core authorization error.
  • Removing the redundant sts:AssumeRole permission cleans up your policy and avoids confusion about where access controls are applied.
  • Restricting the Lambda resource to your specific function reduces your security footprint by only granting the exact permissions needed.

After applying these changes, your Step Function should be able to assume the role and successfully invoke your Lambda function.

内容的提问来源于stack exchange,提问作者x89

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.01 02:22:34