Cross Account Lambda calls from Step Function

Viewed 4814

I have Step Function in Account A and it has lambda which are in Account B. But on running the step function, its giving :

An error occurred while executing the state 'lambdaB' (entered at the event id #2). The resource belongs to a different account from the running execution.

Is there any way this configuration is possible.

5 Answers

AWS Step Functions cannot (directly) invoke an AWS Lambda function in a different account.

A workaround would be to invoke a Lambda function that calls AssumeRole() on an IAM Role in Account B, and then uses the returned credentials to invoke a Lambda function in Account B.

Alternatively, use API Gateway in Account B to allow the Lambda function to be triggered from an external source.

We can do something like this in Step Function:

Parameters": {
                "FunctionName": "FUNCTION_ARN",
                "Payload.$": "$"
            },
            "Resource": "arn:aws:states:::lambda:invoke"

and in Lambda, we need to add permission:

"Version": "2012-10-17",
  "Id": "default",
  "Statement": [
    {
      "Sid": "sid-1",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::ACCOUNT_A:root"
      },
      "Action": "lambda:InvokeFunction",
      "Resource": "FUNCTION_ARN"
    }
  ]
}

I couldn't vote as I don't have enough reputation point. I would say the step function can invoke lambda in a different just as "AWS_Developer" answered. We don't have to invoke lambda using another lambda, just need to give the step function execution role the permission in the lambda function permission setting.

The following setting is copied from AWS_Developer:

"Version": "2012-10-17",
  "Id": "default",
  "Statement": [
    {
      "Sid": "sid-1",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::ACCOUNT_STEP_FUNCTION:root"
      },
      "Action": "lambda:InvokeFunction",
      "Resource": "FUNCTION_ARN"
    }
  ]
}

After a series of workarounds, I found the solution.

At Destination AWS Account

  • Open Lambda Function you need to invoke through step-function, then Open Configuration > Permissions > Resource-based policy.

  • Then click on "Add Permission" > Choose AWS Account

  • Then Give Source Account Arn as below in Principal arn:aws:iam::111111111111:root

  • Choose lambda:InvokeFunction in Action.

Source Account:

Open the Step-Function and then add the following policy in the role of a Step function.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "lambda:InvokeFunction"
            ],
            "Resource": [
                "arn:aws:lambda:ap-south-1:111111111111:function:SampleLambdaForTesting"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "lambda:InvokeFunction"
            ],
            "Resource": [
                "arn:aws:lambda:ap-south-1:111111111111:function:SampleLambdaForTesting"
            ]
        }
    ]
}

Let me know if you're facing any issues.

Yes this is possible. You will need to add a resource-based-policy on the Target lambda you are trying to invoke. The Principal should be your source-account or the role of your Step Function in source-account. Not only invoke, there are whole bunch of other APIs that are supported in this cross-account actions from Step Function. Check official AWS docs here: https://docs.aws.amazon.com/lambda/latest/dg/access-control-resource-based.html

Related