Lambda授权器未授予权限问题排查求助
自定义Lambda授权器返回策略未生效,DynamoDB查询权限被拒绝
在学习项目中配置了Lambda授权器,通过查询DynamoDB表$DYNAMODB_TABLE_PROJECTS判断对$DYNAMODB_TABLE_TASKS的访问权限,但返回的策略未按预期生效,出现以下权限错误:
An error occurred (AccessDeniedException) when calling the Query operation: User: arn:aws:sts::984689749767:assumed-role/task-estimator-backend-dev-eu-central-1-lambdaRole/task-estimator-backend-dev-taskGetAll is not authorized to perform: dynamodb:Query on resource: arn:aws:dynamodb:eu-central-1:984689749767:table/task-estimator-backend-dev-tasks because no identity-based policy allows the dynamodb:Query action
已尝试的操作
- 通过Policy Simulator验证策略有效性
- 引入人为错误确认策略是否被评估
- 默认授予所有权限后改为DENY,仍无效果
配置详情
Serverless.yml
provider: name: aws stage: ${opt:stage, 'dev'} region: 'eu-central-1' runtime: python3.9 memorySize: 128 environment: DYNAMODB_TABLE_TASKS: ${self:service}-${self:provider.stage}-tasks DYNAMODB_TABLE_PROJECTS: ${self:service}-${self:provider.stage}-projects httpApi: authorizers: customAuthorizer: type: request functionName: authorizerFunc
api.yml
taskGetAll: handler: functions/tasks.get_tasks events: - httpApi: method: get path: /tasks/get authorizer: name: customAuthorizer # Authorization authorizerFunc: handler: functions/auth.get_permissions role: authRole
authRole IAM角色(授权器Lambda权限)
authRole: Type: AWS::IAM::Role Properties: RoleName: authRole AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: - lambda.amazonaws.com Action: sts:AssumeRole Policies: - PolicyName: myPolicyName PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: - dynamodb:GetItem - dynamodb:Query Resource: - Fn::GetAtt: - DynamoTableProjects - Arn - Effect: "Allow" Action: - logs:CreateLogGroup - logs:CreateLogStream - logs:PutLogEvents Resource: "*"
授权器生成的策略文档
{ "principalId":"59e30e90", "policyDocument":{ "Version":"2012-10-17", "Statement":[ { "Effect":"Allow", "Action":[ "dynamodb:GetItem", "dynamodb:Query" ], "Resource":[ "arn:aws:dynamodb:*:*:table/task-estimator-backend-dev-tasks", "arn:aws:dynamodb:*:*:table/task-estimator-backend-dev-tasks/index/*" ] }, { "Effect":"Allow", "Action":[ "execute-api:Invoke", "execute-api:ManageConnections" ], "Resource":"arn:aws:execute-api:*:*:*" }, { "Effect":"Allow", "Action":[ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents" ], "Resource":"*" } ] } }
问题根源与解决方案
核心误解
Lambda授权器返回的策略仅用于API Gateway层面的请求准入控制,决定是否允许请求转发到后端Lambda。而目标Lambda执行DynamoDB操作时,使用的是自身的IAM执行角色(错误信息中的task-estimator-backend-dev-eu-central-1-lambdaRole),这个角色才需要配置访问$DYNAMODB_TABLE_TASKS的权限,授权器的策略无法直接赋予Lambda资源访问权限。
解决步骤
给目标Lambda的执行角色添加DynamoDB权限
在Serverless配置的provider部分添加iamRoleStatements,明确允许对应DynamoDB操作:provider: # 保留原有配置... iamRoleStatements: - Effect: Allow Action: - dynamodb:Query - dynamodb:GetItem Resource: - !GetAtt DynamoTableTasks.Arn - !Join ['/', [!GetAtt DynamoTableTasks.Arn, 'index/*']]精简授权器的策略内容
授权器只需控制API Gateway的调用权限,无需包含DynamoDB或日志权限,修改后的策略示例:{ "principalId":"59e30e90", "policyDocument":{ "Version":"2012-10-17", "Statement":[ { "Effect":"Allow", "Action":[ "execute-api:Invoke" ], "Resource":"arn:aws:execute-api:eu-central-1:984689749767:*/*/GET/tasks/get" } ] } }(建议将Resource限定到具体的API路径,提升安全性)
补充验证
- 部署更新后的配置后,检查目标Lambda的执行角色是否已包含新增的DynamoDB权限
- 确认授权器仅负责API请求的准入,资源访问权限由Lambda自身角色管控
内容的提问来源于stack exchange,提问作者felix
相关产品推荐
相关产品推荐

