如何配置Lambda实现DynamoDB读写操作?含IAM角色疑问
Hey there! Let's walk through exactly how to set up your Node.js Lambda function to read/write to your DynamoDB table T1, and address whether that IAM user is necessary.
一、配置Lambda执行角色的DynamoDB权限
Your Lambda function already uses an execution role (arn:aws:iam::123456789012:role/service-role/lambda1-role-rp2z9bjn)—this is the identity Lambda uses to interact with other AWS services, so we just need to add the right permissions to this role. Here's how:
- Navigate to the IAM Console
- Go to the IAM service in your AWS Console, find the "Roles" section, and search for your Lambda execution role (
lambda1-role-rp2z9bjn).
- Go to the IAM service in your AWS Console, find the "Roles" section, and search for your Lambda execution role (
- Add a Permissions Policy
- Click "Add permissions" > "Create inline policy" to make a custom policy tailored to your T1 table.
- Switch to the "JSON" tab and paste the following policy (the resource ARN matches your T1 table, so no changes needed here):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:UpdateItem", "dynamodb:DeleteItem", "dynamodb:Scan", "dynamodb:Query" ], "Resource": "arn:aws:dynamodb:us-west-2:123456789012:table/T1" } ] } - Name this policy something like
LambdaDynamoDBT1Accessand save it.
二、在Node.js Lambda中编写DynamoDB操作代码
Now that the role has permissions, you can use the AWS SDK in your Lambda code to interact with T1. Here's a quick example using the newer @aws-sdk/client-dynamodb and @aws-sdk/util-dynamodb packages (recommended for Node.js 14+):
First, install these packages if you're deploying from your local machine:
npm install @aws-sdk/client-dynamodb @aws-sdk/util-dynamodb
Then, here's sample code for basic read/write operations:
const { DynamoDBClient, GetItemCommand, PutItemCommand } = require("@aws-sdk/client-dynamodb"); const { marshall, unmarshall } = require("@aws-sdk/util-dynamodb"); // Initialize DynamoDB client with your region const client = new DynamoDBClient({ region: "us-west-2" }); // Helper function to write an item to T1 async function writeItemToTable(item) { const params = { TableName: "T1", Item: marshall(item) // Convert JS object to DynamoDB format }; const command = new PutItemCommand(params); await client.send(command); } // Helper function to read an item from T1 async function readItemFromTable(key) { const params = { TableName: "T1", Key: marshall(key) // Convert key object to DynamoDB format }; const command = new GetItemCommand(params); const response = await client.send(command); // Convert DynamoDB format back to JS object if item exists return response.Item ? unmarshall(response.Item) : null; } // Lambda handler function exports.handler = async (event) => { // Example usage: write and read an item await writeItemToTable({ id: "alexa-user-1", favoriteColor: "blue" }); const fetchedItem = await readItemFromTable({ id: "alexa-user-1" }); return { statusCode: 200, body: JSON.stringify(fetchedItem) }; };
三、那个IAM用户(user1)是否必要?
Nope, that IAM user is completely unnecessary for this use case. Here's why:
- Lambda functions rely on execution roles to authenticate with other AWS services. This is the secure, recommended approach because AWS automatically handles credential rotation—you never have to hardcode access keys in your Lambda code.
- IAM users are designed for human users or external applications that need to authenticate via access keys. Since your Lambda runs directly within AWS, it doesn't need an IAM user's credentials to access DynamoDB.
Using an IAM user here would actually introduce a security risk, as you'd have to store access keys (either in code or environment variables) which could leak. Stick with the execution role approach—it's safer and far easier to manage.
内容的提问来源于stack exchange,提问作者u936293

