You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS IAM角色策略资源配置疑问:Lambda权限授权失败求助

Understanding IAM Policy Resources for Lambda Actions

Hey there! Let's clear up the confusion here—your issue comes from mixing up what the Resource field targets for Lambda operations, and how different Lambda actions interact with resources.

Why Your Original Policy Failed

Your policy set the Resource to the ARN of your deployer IAM role, but Lambda operations don't act on IAM roles—they act on Lambda-specific resources (like functions, layers, event sources) or your AWS account itself.

Operations like lambda:GetAccountSettings are account-level actions: they don't target a specific Lambda resource, instead they retrieve data about your entire AWS account's Lambda configuration. When you restrict the resource to your IAM role's ARN, this operation can't match that resource, so AWS denies the request.

How the Resource Field Works

The Resource field defines which specific resources an IAM policy's actions can affect. For Lambda, actions fall into two categories:

  • Resource-level actions: These target specific Lambda resources (e.g., lambda:InvokeFunction, lambda:UpdateFunctionCode). For these, you specify the ARN of the Lambda function, layer, or other resource (e.g., arn:aws:lambda:us-east-1:<account_id>:function:MyAppFunction).
  • Account-level actions: These operate on your entire AWS account (e.g., lambda:GetAccountSettings, lambda:ListFunctions, lambda:ListLayers). These actions don't have a specific resource to target, so they require Resource: "*" (or in some cases, an account-wide Lambda ARN like arn:aws:lambda:<region>:<account_id>:*).

Correct Policy Configuration

To maintain least privilege (avoiding a full * for all actions), split your policy into two statements: one for account-level Lambda actions (using a restricted * with optional conditions), and another for resource-level actions targeting specific Lambda resources.

Here's an example:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowNecessaryAccountLevelLambdaActions",
      "Effect": "Allow",
      "Action": [
        "lambda:GetAccountSettings",
        "lambda:ListFunctions",
        "lambda:ListLayers"
        // Add other account-level actions you need here
      ],
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "aws:RequestedRegion": "us-east-1"
        }
      }
    },
    {
      "Sid": "AllowResourceLevelLambdaActions",
      "Effect": "Allow",
      "Action": "lambda:*",
      "Resource": "arn:aws:lambda:us-east-1:<account_id>:function:deploy-*"
      // Target only Lambda functions with a "deploy-" prefix (adjust to your needs)
    }
  ]
}

Key Notes

  • The Condition in the first statement adds an extra layer of restriction by limiting account-level actions to a specific region (you can remove this if you need multi-region access).
  • For resource-level actions, use wildcards (like *) in the resource ARN to target groups of functions (e.g., all functions in a specific region, or with a naming pattern) instead of all resources.

内容的提问来源于stack exchange,提问作者GreenyMcDuff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:54:37