CDK code, if we don't pass a role, it creates a role with default permissions AWSLambdaBasicExecutionRole and AWSLambdaVPCAccessExecutionRole
From documentation:
Lambda functions assume an IAM role during execution. In CDK by
default, Lambda functions will use an autogenerated Role if one is not
provided.
The autogenerated Role is automatically given permissions to execute
the Lambda function.
We can always add additional permissions by calling addToRolePolicy on the function. OR by calling grant permissions on other resources like dynamoDb or loggroup, etc.
Lets say our lambda is created like this
const myFun = new lambda.Function(this, 'MyFunction', {
runtime: lambda.Runtime.NODEJS_10_X,
handler: 'index.handler',
code: ...})
We can add permissions like this:
myFun.role.addToRolePolicy(
new iam.PolicyStatement({
resources: ['*'],
actions: [...],
})
);
OR
Lets say we want to grant access to write to log group, we can do this, which appends additional inline policy to lambda role.
const logGroup = new awsLogs.LogGroup(this, `my-fun`, {
retention: 30,
logGroupName: `/aws/lambda/${functionName}`,
removalPolicy: cdk.RemovalPolicy.DESTROY,
});
logGroup.grantWrite(this.myFun);
Similarly in case of DynamoDB,for dynamoTable.grantReadWriteData method, we need to pass function itself, not the role. so,
Instead of
dynamoTable.grantReadWriteData(myFun.role);
We should do
dynamoTable.grantReadWriteData(myFun);