You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CloudFormation中配置API Gateway调用所有Lambda函数的权限?

Absolutely, you can set up permissions for API Gateway to invoke your Lambda functions efficiently—no need to manually write a AWS::Lambda::Permission resource for every single function. Let’s break down two solid approaches to do this, plus a complete example template.

Option 1: Batch-Create Lambda Permissions with CloudFormation Loops

The cleanest and most secure approach (since you can scope access to specific functions) is to use CloudFormation's Fn::ForEach-2 (available in modern CloudFormation versions) to generate permissions for a list of Lambda functions automatically.

First, define a list of your Lambda function names/ARNs as a parameter, then loop through it to create each permission:

AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RestApiName:
    Type: String
    Default: MyAppApi
  # List of Lambda function names (or full ARNs) you want API Gateway to invoke
  TargetLambdaFunctions:
    Type: List<String>
    Description: Names/ARNs of Lambda functions API Gateway needs access to
Resources:
  MyRestApi:
    Type: AWS::ApiGateway::RestApi
    Properties:
      Name: !Ref RestApiName
  # Auto-generate Lambda permissions for every function in the list
  Fn::ForEach-2:
    - FuncName
    - !Ref TargetLambdaFunctions
    - ${FuncName}InvokePermission:
        Type: AWS::Lambda::Permission
        Properties:
          FunctionName: !Ref FuncName
          Action: 'lambda:InvokeFunction'
          Principal: apigateway.amazonaws.com
          # Restrict to your specific API Gateway (adjust the wildcard if needed)
          SourceArn: !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${MyRestApi}/*"
Outputs:
  RestApiId:
    Value: !Ref MyRestApi
    Description: ID of your API Gateway instance

Key Notes for Option 1:

  • For tighter security, replace the /* in SourceArn with a specific stage/path (e.g., ${MyRestApi}/prod/users/*) to limit which API endpoints can invoke the Lambda functions.
  • If you're using an older CloudFormation version that doesn't support Fn::ForEach-2, you can use nested stacks or AWS CDK to achieve the same batch creation logic.

Option 2: Use an IAM Role for API Gateway (Broad Permissions)

If you truly want API Gateway to invoke all Lambda functions in your account (use this cautiously—broader permissions mean more risk), you can attach an IAM role to your API Gateway with full Lambda invoke access.

Here's how to set this up:

AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RestApiName:
    Type: String
    Default: MyAppApi
Resources:
  # IAM role for API Gateway to assume
  ApiGatewayLambdaInvokeRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: apigateway.amazonaws.com
            Action: sts:AssumeRole
      Policies:
        - PolicyName: AllowLambdaInvokeAll
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action: lambda:InvokeFunction
                # Grant access to ALL Lambda functions in the account
                Resource: !Sub "arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:function:*"
  MyRestApi:
    Type: AWS::ApiGateway::RestApi
    Properties:
      Name: !Ref RestApiName
  # Example integration using the role (apply this to your API endpoints)
  ExampleLambdaIntegration:
    Type: AWS::ApiGateway::Integration
    Properties:
      RestApiId: !Ref MyRestApi
      ResourceId: !GetAtt MyRestApi.RootResourceId
      HttpMethod: POST
      Type: AWS_PROXY
      IntegrationHttpMethod: POST
      Uri: !Sub "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:function:YourLambdaFunction/invocations"
      # Attach the IAM role here
      Credentials: !GetAtt ApiGatewayLambdaInvokeRole.Arn

Key Notes for Option 2:

  • This approach gives API Gateway blanket permission to invoke any Lambda function in your account. Only use this if you explicitly need that level of access—otherwise, Option 1 is the safer choice.
  • When setting up API integrations, you must specify the role's ARN in the Credentials property of your AWS::ApiGateway::Integration resource.

内容的提问来源于stack exchange,提问作者Damien

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 06:28:15