API Gateway无权限执行sts:AssumeRole问题求助(已配置角色权限)
Hey there, let's figure out why you're hitting that permission error with API Gateway and your Lambda role.
First, let's recap the error you're seeing:
Sat Nov 09 02:12:13 UTC 2019 : Execution failed due to configuration error: API Gateway does not have permission to assume the provided role arn:aws:iam::193693970645:role/service-role/DoubleMeLambda-role-0erzzpmz
The root issue here is your IAM role's trust relationship doesn't grant API Gateway permission to assume it. Right now, your trust policy only allows lambda.amazonaws.com to use the role:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "lambda.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
Even though you gave the role full * permissions, that only controls what the role can do once it's assumed. The trust relationship controls who can assume the role in the first place. Here's how to fix it:
Step 1: Update the Trust Relationship to Include API Gateway
Modify your role's trust policy to add apigateway.amazonaws.com as an allowed service principal. The updated policy should look like this:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": ["lambda.amazonaws.com", "apigateway.amazonaws.com"] }, "Action": "sts:AssumeRole" } ] }
Step 2: Verify the Role's Permissions (Optional but Best Practice)
While you're using full * permissions for testing, in real scenarios you should restrict the role to only the actions it needs. For API Gateway invoking Lambda, the necessary permission is lambda:InvokeFunction. Here's an example policy snippet if you want to tighten things up later:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "lambda:InvokeFunction", "Resource": "arn:aws:lambda:YOUR_REGION:193693970645:function:YOUR_LAMBDA_FUNCTION_NAME" } ] }
Step 3: Redeploy Your API
After updating the IAM role, don't forget to redeploy your API Gateway stage. Sometimes changes to IAM permissions take a minute to propagate, but redeploying ensures API Gateway picks up the updated role settings.
That should resolve the "does not have permission to assume the provided role" error. Even though sharing the same role between Lambda and API Gateway isn't ideal for production, it should work once the trust relationship is fixed.
内容的提问来源于stack exchange,提问作者Michael Durrant

