2016-08-23 51 views

回答

1

您可能错过了AssumeRolePolicyDocument,它允许Lambda(lambda.amazonaws.com)承担您的IAM角色。

实施例:

... 
"LambdaRole": { 
    "Type": "AWS::IAM::Role", 
    "Properties": { 
     "AssumeRolePolicyDocument": { 
      "Version": "2012-10-17", 
      "Statement": [{ 
       "Effect": "Allow", 
       "Principal": {"lambda.amazonaws.com"}, 
       "Action": ["sts:AssumeRole"] 
      }] 
     }, 
     "Path": "/", 
     "Policies": [...] 
    } 
} 
...