You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Lambda授权器未授予权限问题排查求助

自定义Lambda授权器返回策略未生效,DynamoDB查询权限被拒绝

在学习项目中配置了Lambda授权器,通过查询DynamoDB表$DYNAMODB_TABLE_PROJECTS判断对$DYNAMODB_TABLE_TASKS的访问权限,但返回的策略未按预期生效,出现以下权限错误:

An error occurred (AccessDeniedException) when calling the Query operation:
User: arn:aws:sts::984689749767:assumed-role/task-estimator-backend-dev-eu-central-1-lambdaRole/task-estimator-backend-dev-taskGetAll
is not authorized to perform: dynamodb:Query on resource: 
arn:aws:dynamodb:eu-central-1:984689749767:table/task-estimator-backend-dev-tasks 
because no identity-based policy allows the dynamodb:Query action

已尝试的操作

  • 通过Policy Simulator验证策略有效性
  • 引入人为错误确认策略是否被评估
  • 默认授予所有权限后改为DENY,仍无效果

配置详情

Serverless.yml

provider:
  name: aws
  stage: ${opt:stage, 'dev'}
  region: 'eu-central-1'
  runtime: python3.9
  memorySize: 128
  environment:
    DYNAMODB_TABLE_TASKS: ${self:service}-${self:provider.stage}-tasks
    DYNAMODB_TABLE_PROJECTS: ${self:service}-${self:provider.stage}-projects
  httpApi:
    authorizers:
      customAuthorizer:
        type: request
        functionName: authorizerFunc

api.yml

taskGetAll:
  handler: functions/tasks.get_tasks
  events:
    - httpApi:
        method: get
        path: /tasks/get
        authorizer:
          name: customAuthorizer

# Authorization
authorizerFunc:
  handler: functions/auth.get_permissions
  role: authRole

authRole IAM角色(授权器Lambda权限)

authRole:
  Type: AWS::IAM::Role
  Properties:
    RoleName: authRole
    AssumeRolePolicyDocument:
      Version: '2012-10-17'
      Statement:
        - Effect: Allow
          Principal:
            Service:
              - lambda.amazonaws.com
          Action: sts:AssumeRole
    Policies:
      - PolicyName: myPolicyName
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
            - Effect: Allow 
              Action:
                - dynamodb:GetItem
                - dynamodb:Query
              Resource:
                - Fn::GetAtt:
                    - DynamoTableProjects
                    - Arn 
            - Effect: "Allow"
              Action:
                  - logs:CreateLogGroup
                  - logs:CreateLogStream
                  - logs:PutLogEvents
              Resource: "*"

授权器生成的策略文档

{
  "principalId":"59e30e90",
  "policyDocument":{ 
     "Version":"2012-10-17",
     "Statement":[ 
        { 
           "Effect":"Allow",
           "Action":[ 
              "dynamodb:GetItem",
              "dynamodb:Query"
           ],
           "Resource":[ 
              "arn:aws:dynamodb:*:*:table/task-estimator-backend-dev-tasks",
              "arn:aws:dynamodb:*:*:table/task-estimator-backend-dev-tasks/index/*"
           ]
        },
        { 
           "Effect":"Allow",
           "Action":[ 
              "execute-api:Invoke",
              "execute-api:ManageConnections"
           ],
           "Resource":"arn:aws:execute-api:*:*:*"
        },
        { 
           "Effect":"Allow",
           "Action":[ 
              "logs:CreateLogGroup",
              "logs:CreateLogStream",
              "logs:PutLogEvents"
           ],
           "Resource":"*"
        }
     ]
  }
}

问题根源与解决方案

核心误解

Lambda授权器返回的策略仅用于API Gateway层面的请求准入控制,决定是否允许请求转发到后端Lambda。而目标Lambda执行DynamoDB操作时,使用的是自身的IAM执行角色(错误信息中的task-estimator-backend-dev-eu-central-1-lambdaRole),这个角色才需要配置访问$DYNAMODB_TABLE_TASKS的权限,授权器的策略无法直接赋予Lambda资源访问权限。

解决步骤

  1. 给目标Lambda的执行角色添加DynamoDB权限
    在Serverless配置的provider部分添加iamRoleStatements,明确允许对应DynamoDB操作:

    provider:
      # 保留原有配置...
      iamRoleStatements:
        - Effect: Allow
          Action:
            - dynamodb:Query
            - dynamodb:GetItem
          Resource:
            - !GetAtt DynamoTableTasks.Arn
            - !Join ['/', [!GetAtt DynamoTableTasks.Arn, 'index/*']]
    
  2. 精简授权器的策略内容
    授权器只需控制API Gateway的调用权限,无需包含DynamoDB或日志权限,修改后的策略示例:

    {
      "principalId":"59e30e90",
      "policyDocument":{ 
         "Version":"2012-10-17",
         "Statement":[ 
            { 
               "Effect":"Allow",
               "Action":[ "execute-api:Invoke" ],
               "Resource":"arn:aws:execute-api:eu-central-1:984689749767:*/*/GET/tasks/get"
            }
         ]
      }
    }
    

    (建议将Resource限定到具体的API路径,提升安全性)

补充验证

  • 部署更新后的配置后,检查目标Lambda的执行角色是否已包含新增的DynamoDB权限
  • 确认授权器仅负责API请求的准入,资源访问权限由Lambda自身角色管控

内容的提问来源于stack exchange,提问作者felix

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 09:24:21