AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium
A development team is implementing a new microservice architecture on AWS. Each microservice needs its own AWS Lambda function, and these functions require specific, fine-grained access permissions to other AWS services (e.g., S3, DynamoDB, SQS). The team uses AWS Serverless Application Model (AWS SAM) to define their serverless applications. They want to define the IAM policies for each Lambda function directly within their SAM templates, ensuring that permissions are automatically deployed and updated with the function, adhering to the principle of least privilege. Which SAM template property should they use to achieve this?
- AProperties.Role
- BProperties.PermissionsBoundary
- CProperties.Policies
- DProperties.Policy
Show answer & explanationAnswer & explanation
Correct answer: C. Properties.Policies
In AWS SAM, the `Properties.Policies` property for an `AWS::Serverless::Function` resource allows you to define inline IAM policies or reference managed policies, ensuring fine-grained access permissions are directly associated with the Lambda function.
Why the other options are wrong
- A. The `Properties.Role` property is used to attach an existing IAM role ARN, not define new inline policies within the SAM template.
- B. The `Properties.PermissionsBoundary` property is used to set a permissions boundary for the function's execution role, not to define the function's specific access permissions.
- D. There is no `Properties.Policy` property directly for defining inline policies in AWS SAM functions.
SAM Function Policies
In AWS SAM, the `Policies` property under an `AWS::Serverless::Function` resource defines the IAM permissions for the Lambda function's execution role, enabling fine-grained control over its access.
- Applied to `AWS::Serverless::Function` resources.
- Supports various policy types (inline, managed, SAM policy templates).
- Automates creation/updates of the Lambda execution role.
- Facilitates least privilege for serverless functions.
Memory trick: SAM's Policies are the rules written directly on the function's badge, granting its access.