You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Lambda@Edge+CloudFront访问S3对象遇502及LambdaValidationError问题排查

Troubleshooting Lambda@Edge Not Triggering & CloudFront 502 LambdaValidationError with S3 Origin

Let’s break down the possible issues and fixes step by step, based on your setup:

1. Fix Syntax Errors in Your Lambda Function

Looking at the test function you shared, there’s an unclosed string in one of your console.log statements:

console.log("


");

The opening quote " doesn’t have a closing match here! This syntax error will cause the Lambda function to fail validation when CloudFront tries to invoke it, directly leading to the LambdaValidationError and 502 status code.

First, correct this to a valid statement, like:

console.log("\n\n\n"); // Properly closed string with line breaks

Then republish the Lambda function using a published version (e.g., v1) or an alias (never use the mutable $LATEST version for Lambda@Edge), and reattach it to your CloudFront behavior.

2. Verify Lambda@Edge Deployment Requirements

Lambda@Edge has strict rules that are easy to overlook:

  • No $LATEST allowed: CloudFront requires a fixed, published version or alias of your Lambda function. $LATEST is dynamic and will fail validation.
  • Check regional replication: When you associate a Lambda function with CloudFront, AWS replicates it to all edge regions. Wait for the replication confirmation in the Lambda console before testing.
  • Trust policy setup: Ensure your Lambda execution role trusts the edgelambda.amazonaws.com service principal. Your role’s trust policy should include:
    {
      "Effect": "Allow",
      "Principal": {
        "Service": [
          "lambda.amazonaws.com",
          "edgelambda.amazonaws.com"
        ]
      },
      "Action": "sts:AssumeRole"
    }
    

3. Validate CloudFront Behavior Configuration

Double-check that your CloudFront distribution’s behavior is set up to trigger the Lambda function:

  • Path pattern match: The behavior’s path pattern must align with your request URL (e.g., /my_folder/* or /* for all paths). If you created a behavior with a narrow pattern that doesn’t include /my_folder/myimage.jpg, the Lambda won’t trigger.
  • Event type association: Confirm you attached the Lambda function to the correct event type (most likely Viewer Request or Origin Request for your image processing use case). Verify this in the CloudFront behavior’s "Lambda Function Associations" section.
  • Deployment status: Wait for the CloudFront distribution to finish deploying (status shows Deployed). Changes can take 5-15 minutes to propagate to edge locations.

4. Check Lambda Logs in the Correct Region

Lambda@Edge logs aren’t stored in your function’s original region—they live in the edge region that processed your request. To find them:

  1. Open the CloudWatch console.
  2. Switch to the region closest to your test location (e.g., us-east-1 for US East, ap-southeast-1 for Southeast Asia).
  3. Look for a log group named /aws/lambda/us-east-1.<your-function-name> (Lambda@Edge functions are replicated from us-east-1 by default).

5. Confirm S3 Origin Access Configuration

While this might not directly prevent Lambda from triggering, a misconfigured S3 origin can contribute to 502 errors:

  • Use Origin Access Control (OAC) instead of the legacy Origin Access Identity (OAI) for better compatibility with modern CloudFront features.
  • Verify that your S3 bucket policy allows CloudFront (via your OAC) to perform s3:GetObject on bucket objects.

Working through these steps should resolve the LambdaValidationError and get your Lambda@Edge function triggering correctly for image requests.

内容的提问来源于stack exchange,提问作者scagbackbone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:41:56