You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

API Gateway无权限执行sts:AssumeRole问题求助(已配置角色权限)

解决API Gateway无法假设指定IAM角色的问题

Hey there, let's figure out why you're hitting that permission error with API Gateway and your Lambda role.

First, let's recap the error you're seeing:

Sat Nov 09 02:12:13 UTC 2019 : Execution failed due to configuration error: API Gateway does not have permission to assume the provided role arn:aws:iam::193693970645:role/service-role/DoubleMeLambda-role-0erzzpmz

The root issue here is your IAM role's trust relationship doesn't grant API Gateway permission to assume it. Right now, your trust policy only allows lambda.amazonaws.com to use the role:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "lambda.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

Even though you gave the role full * permissions, that only controls what the role can do once it's assumed. The trust relationship controls who can assume the role in the first place. Here's how to fix it:

Step 1: Update the Trust Relationship to Include API Gateway

Modify your role's trust policy to add apigateway.amazonaws.com as an allowed service principal. The updated policy should look like this:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": ["lambda.amazonaws.com", "apigateway.amazonaws.com"]
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

Step 2: Verify the Role's Permissions (Optional but Best Practice)

While you're using full * permissions for testing, in real scenarios you should restrict the role to only the actions it needs. For API Gateway invoking Lambda, the necessary permission is lambda:InvokeFunction. Here's an example policy snippet if you want to tighten things up later:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "lambda:InvokeFunction",
      "Resource": "arn:aws:lambda:YOUR_REGION:193693970645:function:YOUR_LAMBDA_FUNCTION_NAME"
    }
  ]
}

Step 3: Redeploy Your API

After updating the IAM role, don't forget to redeploy your API Gateway stage. Sometimes changes to IAM permissions take a minute to propagate, but redeploying ensures API Gateway picks up the updated role settings.

That should resolve the "does not have permission to assume the provided role" error. Even though sharing the same role between Lambda and API Gateway isn't ideal for production, it should work once the trust relationship is fixed.

内容的提问来源于stack exchange,提问作者Michael Durrant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:32:54