AWS IAM角色策略资源配置疑问:Lambda权限授权失败求助
Hey there! Let's clear up the confusion here—your issue comes from mixing up what the Resource field targets for Lambda operations, and how different Lambda actions interact with resources.
Why Your Original Policy Failed
Your policy set the Resource to the ARN of your deployer IAM role, but Lambda operations don't act on IAM roles—they act on Lambda-specific resources (like functions, layers, event sources) or your AWS account itself.
Operations like lambda:GetAccountSettings are account-level actions: they don't target a specific Lambda resource, instead they retrieve data about your entire AWS account's Lambda configuration. When you restrict the resource to your IAM role's ARN, this operation can't match that resource, so AWS denies the request.
How the Resource Field Works
The Resource field defines which specific resources an IAM policy's actions can affect. For Lambda, actions fall into two categories:
- Resource-level actions: These target specific Lambda resources (e.g.,
lambda:InvokeFunction,lambda:UpdateFunctionCode). For these, you specify the ARN of the Lambda function, layer, or other resource (e.g.,arn:aws:lambda:us-east-1:<account_id>:function:MyAppFunction). - Account-level actions: These operate on your entire AWS account (e.g.,
lambda:GetAccountSettings,lambda:ListFunctions,lambda:ListLayers). These actions don't have a specific resource to target, so they requireResource: "*"(or in some cases, an account-wide Lambda ARN likearn:aws:lambda:<region>:<account_id>:*).
Correct Policy Configuration
To maintain least privilege (avoiding a full * for all actions), split your policy into two statements: one for account-level Lambda actions (using a restricted * with optional conditions), and another for resource-level actions targeting specific Lambda resources.
Here's an example:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowNecessaryAccountLevelLambdaActions", "Effect": "Allow", "Action": [ "lambda:GetAccountSettings", "lambda:ListFunctions", "lambda:ListLayers" // Add other account-level actions you need here ], "Resource": "*", "Condition": { "StringEquals": { "aws:RequestedRegion": "us-east-1" } } }, { "Sid": "AllowResourceLevelLambdaActions", "Effect": "Allow", "Action": "lambda:*", "Resource": "arn:aws:lambda:us-east-1:<account_id>:function:deploy-*" // Target only Lambda functions with a "deploy-" prefix (adjust to your needs) } ] }
Key Notes
- The
Conditionin the first statement adds an extra layer of restriction by limiting account-level actions to a specific region (you can remove this if you need multi-region access). - For resource-level actions, use wildcards (like
*) in the resource ARN to target groups of functions (e.g., all functions in a specific region, or with a naming pattern) instead of all resources.
内容的提问来源于stack exchange,提问作者GreenyMcDuff

