AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeEasy
A software development company is adopting a microservices architecture on AWS. Each microservice is deployed as an AWS Lambda function and requires specific, fine-grained permissions to interact with other AWS services (e.g., read from a specific S3 bucket, publish to a specific SQS queue). The company wants to ensure that these permissions are defined inline with the Lambda function's definition within the AWS Serverless Application Model (SAM) template, following the principle of least privilege and making the permissions easily discoverable and managed alongside the function code. Which SAM template construct should be used to achieve this?
- ADefine a separate IAM Role resource and attach it to the Lambda function.
- BReference a pre-existing managed IAM Policy ARN within the function definition.
- CEmbed a custom resource that creates and attaches an IAM Policy document.
- DUse the `Policies` property within the `AWS::Serverless::Function` resource.
Show answer & explanationAnswer & explanation
Correct answer: D. Use the `Policies` property within the `AWS::Serverless::Function` resource.
The `Policies` property within the `AWS::Serverless::Function` resource in a SAM template is specifically designed for defining inline IAM permissions for the Lambda function. This allows developers to grant least-privilege access directly within the function's definition, making the permissions co-located with the function code and simplifying management and review.
Why the other options are wrong
- A. Defining a separate IAM Role works but is less concise than inline policies within SAM functions and might separate permissions from the function definition.
- B. Referencing a pre-existing managed policy might grant overly broad permissions or make it harder to achieve least privilege, as the policy is not specific to the function's needs.
- C. Embedding a custom resource for IAM policy management adds unnecessary complexity and overhead, as SAM provides a native solution.
SAM Function Policies
The `Policies` property within an `AWS::Serverless::Function` resource in a SAM template allows defining inline IAM permissions directly tied to the Lambda function.
- Grants least-privilege access to Lambda functions.
- Co-locates permissions with the function definition.
- Simplifies IAM management for serverless applications.
Memory trick: Policies directly on the function are like a specific key for a specific lock.