IAM Policy setting (suggestion: improve permission error reporting)
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- aws, javascript, node.js
调研方向
Start in lib/main.js at line 889, where the issue identifies permission errors being treated as a nonexistent function. Reproduce the deployment with the IAM policy described in the issue and trace the AWS Lambda error handling; done means permission failures report the actual permission problem instead of “Function already exist.”
由索引模型根据 Issue 内容生成。
描述
If this is already somewhere please point it out.
I started with this policy from travis, but node-lambda required a lot more permissions then this:
https://docs.travis-ci.com/user/deployment/lambda/
I was getting this error ResourceConflictException: Function already exist, incorrectly.
Eventually I figured out the error reporting for permissions is very bad in node-lambda. It assumes any permission error is just a non existent function. https://github.com/motdotla/node-lambda/blob/master/lib/main.js#L889
This is the latest version of my IAM policy to get a deploy without errors:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ListExistingRolesAndPolicies",
"Effect": "Allow",
"Action": [
"iam:ListRolePolicies",
"iam:ListRoles"
],
"Resource": "*"
},
{
"Sid": "CreateAndListFunctions",
"Effect": "Allow",
"Action": [
"lambda:CreateFunction",
"lambda:ListFunctions",
"lambda:ListEventSourceMappings"
],
"Resource": "*"
},
{
"Sid": "DeployCode",
"Effect": "Allow",
"Action": [
"lambda:GetFunction",
"lambda:UpdateFunctionCode",
"lambda:UpdateFunctionConfiguration"
],
"Resource": [
"arn:aws:lambda:us-east-1:12345:function:abc",
"arn:aws:lambda:us-east-1:12345:function:abcdef",
"arn:aws:lambda:us-east-1:12345:function:whatever"
]
},
{
"Sid": "SetRole",
"Effect": "Allow",
"Action": [
"iam:PassRole"
],
"Resource": "arn:aws:iam::12345:role/exec_role"
},
{
"Sid": "S3Uploads",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject"
],
"Resource": "arn:aws:s3:::mybucket/test/lambdas/*"
},
{
"Sid": "LogsPermission",
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:PutRetentionPolicy"
],
"Resource": "*"
}
]
}
From travis's doc: It does not appear to be possible to wildcard the DeployCode statement
- 主要语言
- JavaScript
- 星标
- 1.4k
- 派生
- 185
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
motdotla/node-lambda 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 35/100
motdotla/node-lambda#840 · 1 条评论 ·
-
难度 4/5 3-5 天 新手友好度 35/100
motdotla/node-lambda#641 · 6 条评论 · 2 个 reaction ·
-
难度 5/5 一周以上 新手友好度 15/100
motdotla/node-lambda#618 ·
-
enhancement
难度 4/5 3-5 天 新手友好度 30/100
motdotla/node-lambda#544 · 1 个 reaction ·
-
question
难度 4/5 3-5 天 新手友好度 25/100
motdotla/node-lambda#537 · 2 条评论 · 1 个 reaction ·
查看 motdotla/node-lambda 的全部 Issue
相似的 Issue
-
curation good first issue
难度 2/5 1-3 小时 新手友好度 88/100
amponce/archive-movie-browser#186 ·
-
难度 2/5 1-3 小时 新手友好度 86/100
clerk/javascript#9852 ·
-
bug p1 tools
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 2/5 1-3 小时 新手友好度 88/100
HarperFast/skills#96 ·
-
factory-active factory-automatic task-bug-reproduction-cannot-reproduce task-identify-harness-labels-done task-identify-issue-type-done
难度 2/5 1-3 小时 新手友好度 84/100