You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Lambda实现DynamoDB读写操作?含IAM角色疑问

配置Lambda访问DynamoDB表T1的指南

Hey there! Let's walk through exactly how to set up your Node.js Lambda function to read/write to your DynamoDB table T1, and address whether that IAM user is necessary.

一、配置Lambda执行角色的DynamoDB权限

Your Lambda function already uses an execution role (arn:aws:iam::123456789012:role/service-role/lambda1-role-rp2z9bjn)—this is the identity Lambda uses to interact with other AWS services, so we just need to add the right permissions to this role. Here's how:

  • Navigate to the IAM Console
    • Go to the IAM service in your AWS Console, find the "Roles" section, and search for your Lambda execution role (lambda1-role-rp2z9bjn).
  • Add a Permissions Policy
    • Click "Add permissions" > "Create inline policy" to make a custom policy tailored to your T1 table.
    • Switch to the "JSON" tab and paste the following policy (the resource ARN matches your T1 table, so no changes needed here):
      {
          "Version": "2012-10-17",
          "Statement": [
              {
                  "Effect": "Allow",
                  "Action": [
                      "dynamodb:GetItem",
                      "dynamodb:PutItem",
                      "dynamodb:UpdateItem",
                      "dynamodb:DeleteItem",
                      "dynamodb:Scan",
                      "dynamodb:Query"
                  ],
                  "Resource": "arn:aws:dynamodb:us-west-2:123456789012:table/T1"
              }
          ]
      }
      
    • Name this policy something like LambdaDynamoDBT1Access and save it.

二、在Node.js Lambda中编写DynamoDB操作代码

Now that the role has permissions, you can use the AWS SDK in your Lambda code to interact with T1. Here's a quick example using the newer @aws-sdk/client-dynamodb and @aws-sdk/util-dynamodb packages (recommended for Node.js 14+):

First, install these packages if you're deploying from your local machine:

npm install @aws-sdk/client-dynamodb @aws-sdk/util-dynamodb

Then, here's sample code for basic read/write operations:

const { DynamoDBClient, GetItemCommand, PutItemCommand } = require("@aws-sdk/client-dynamodb");
const { marshall, unmarshall } = require("@aws-sdk/util-dynamodb");

// Initialize DynamoDB client with your region
const client = new DynamoDBClient({ region: "us-west-2" });

// Helper function to write an item to T1
async function writeItemToTable(item) {
  const params = {
    TableName: "T1",
    Item: marshall(item) // Convert JS object to DynamoDB format
  };
  const command = new PutItemCommand(params);
  await client.send(command);
}

// Helper function to read an item from T1
async function readItemFromTable(key) {
  const params = {
    TableName: "T1",
    Key: marshall(key) // Convert key object to DynamoDB format
  };
  const command = new GetItemCommand(params);
  const response = await client.send(command);
  // Convert DynamoDB format back to JS object if item exists
  return response.Item ? unmarshall(response.Item) : null;
}

// Lambda handler function
exports.handler = async (event) => {
  // Example usage: write and read an item
  await writeItemToTable({ id: "alexa-user-1", favoriteColor: "blue" });
  const fetchedItem = await readItemFromTable({ id: "alexa-user-1" });

  return {
    statusCode: 200,
    body: JSON.stringify(fetchedItem)
  };
};

三、那个IAM用户(user1)是否必要?

Nope, that IAM user is completely unnecessary for this use case. Here's why:

  • Lambda functions rely on execution roles to authenticate with other AWS services. This is the secure, recommended approach because AWS automatically handles credential rotation—you never have to hardcode access keys in your Lambda code.
  • IAM users are designed for human users or external applications that need to authenticate via access keys. Since your Lambda runs directly within AWS, it doesn't need an IAM user's credentials to access DynamoDB.

Using an IAM user here would actually introduce a security risk, as you'd have to store access keys (either in code or environment variables) which could leak. Stick with the execution role approach—it's safer and far easier to manage.

内容的提问来源于stack exchange,提问作者u936293

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:36:19