AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium
A DevOps team is deploying a serverless application using AWS Lambda and API Gateway. The team needs to ensure that the Lambda functions can only be invoked by the specific API Gateway endpoint and no other source. How can this be achieved with the MOST granular and secure permissions?
- AImplement a custom authorizer Lambda function in API Gateway to validate the incoming requests before invoking the backend Lambda.
- BUse an IAM role for the API Gateway to invoke the Lambda function, and restrict the role to only specific API Gateway resources.
- CConfigure a resource-based policy on the Lambda function to allow invocation only from the API Gateway service principal with a 'sourceArn' condition.
- DSet up AWS WAF on the API Gateway to filter requests, allowing only those originating from trusted IP addresses.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure a resource-based policy on the Lambda function to allow invocation only from the API Gateway service principal with a 'sourceArn' condition.
A resource-based policy on the Lambda function that uses the `SourceArn` condition with the specific API Gateway ARN ensures that only that particular API Gateway endpoint can invoke the function, providing the most granular and secure control over invocation sources.
Why the other options are wrong
- A. A custom authorizer validates the *caller* of the API Gateway, not the source of the *Lambda invocation* itself, which is handled by the API Gateway service principal.
- B. API Gateway does not use IAM roles to invoke Lambda functions; it uses resource-based policies on the Lambda function itself.
- D. AWS WAF filters requests based on various criteria (like IP), but it doesn't directly control the *invocation* permission of the Lambda function from API Gateway.
Lambda Resource Policy for API Gateway
A resource-based policy on an AWS Lambda function allows or denies other AWS services (like API Gateway) from invoking it, using conditions like `SourceArn` for granular control.
- Lambda functions use resource-based policies for invocation permissions.
- API Gateway invokes Lambda as a service principal.
- `SourceArn` condition restricts invocation to a specific API Gateway resource.
Memory trick: Lambda's 'door' has a 'policy' to 'check' the 'caller's' 'ID'.