如何在CloudFormation中配置API Gateway调用所有Lambda函数的权限?
Absolutely, you can set up permissions for API Gateway to invoke your Lambda functions efficiently—no need to manually write a AWS::Lambda::Permission resource for every single function. Let’s break down two solid approaches to do this, plus a complete example template.
Option 1: Batch-Create Lambda Permissions with CloudFormation Loops
The cleanest and most secure approach (since you can scope access to specific functions) is to use CloudFormation's Fn::ForEach-2 (available in modern CloudFormation versions) to generate permissions for a list of Lambda functions automatically.
First, define a list of your Lambda function names/ARNs as a parameter, then loop through it to create each permission:
AWSTemplateFormatVersion: '2010-09-09' Parameters: RestApiName: Type: String Default: MyAppApi # List of Lambda function names (or full ARNs) you want API Gateway to invoke TargetLambdaFunctions: Type: List<String> Description: Names/ARNs of Lambda functions API Gateway needs access to Resources: MyRestApi: Type: AWS::ApiGateway::RestApi Properties: Name: !Ref RestApiName # Auto-generate Lambda permissions for every function in the list Fn::ForEach-2: - FuncName - !Ref TargetLambdaFunctions - ${FuncName}InvokePermission: Type: AWS::Lambda::Permission Properties: FunctionName: !Ref FuncName Action: 'lambda:InvokeFunction' Principal: apigateway.amazonaws.com # Restrict to your specific API Gateway (adjust the wildcard if needed) SourceArn: !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${MyRestApi}/*" Outputs: RestApiId: Value: !Ref MyRestApi Description: ID of your API Gateway instance
Key Notes for Option 1:
- For tighter security, replace the
/*inSourceArnwith a specific stage/path (e.g.,${MyRestApi}/prod/users/*) to limit which API endpoints can invoke the Lambda functions. - If you're using an older CloudFormation version that doesn't support
Fn::ForEach-2, you can use nested stacks or AWS CDK to achieve the same batch creation logic.
Option 2: Use an IAM Role for API Gateway (Broad Permissions)
If you truly want API Gateway to invoke all Lambda functions in your account (use this cautiously—broader permissions mean more risk), you can attach an IAM role to your API Gateway with full Lambda invoke access.
Here's how to set this up:
AWSTemplateFormatVersion: '2010-09-09' Parameters: RestApiName: Type: String Default: MyAppApi Resources: # IAM role for API Gateway to assume ApiGatewayLambdaInvokeRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: apigateway.amazonaws.com Action: sts:AssumeRole Policies: - PolicyName: AllowLambdaInvokeAll PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Action: lambda:InvokeFunction # Grant access to ALL Lambda functions in the account Resource: !Sub "arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:function:*" MyRestApi: Type: AWS::ApiGateway::RestApi Properties: Name: !Ref RestApiName # Example integration using the role (apply this to your API endpoints) ExampleLambdaIntegration: Type: AWS::ApiGateway::Integration Properties: RestApiId: !Ref MyRestApi ResourceId: !GetAtt MyRestApi.RootResourceId HttpMethod: POST Type: AWS_PROXY IntegrationHttpMethod: POST Uri: !Sub "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:function:YourLambdaFunction/invocations" # Attach the IAM role here Credentials: !GetAtt ApiGatewayLambdaInvokeRole.Arn
Key Notes for Option 2:
- This approach gives API Gateway blanket permission to invoke any Lambda function in your account. Only use this if you explicitly need that level of access—otherwise, Option 1 is the safer choice.
- When setting up API integrations, you must specify the role's ARN in the
Credentialsproperty of yourAWS::ApiGateway::Integrationresource.
内容的提问来源于stack exchange,提问作者Damien

