You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As mentioned in #5, the Resource attribute of the default IAM role could be restricted so that the state machine can only interact with the configured Lambda Function(s).
Resource is set to * by default because the original goal was to provide any lambdaARN at runtime.
We should document how to update such configuration manually, or eventually implement an additional parameter at generation-time.
The new parameter could look like this:
$ npm run generate -- -A ACCOUNT_ID -L arn:aws:lambda:*:*:function:MyFunctionName
The text was updated successfully, but these errors were encountered:
Won't fix for now. I think #5 will solve most concerns.
The specific Lambda ARN(s) can always be forced by editing the yaml file, although it wouls also restrict the state machine to operate on only one (or more) pre-defined functions.
As mentioned in #5, the
Resource
attribute of the default IAM role could be restricted so that the state machine can only interact with the configured Lambda Function(s).Resource
is set to*
by default because the original goal was to provide anylambdaARN
at runtime.We should document how to update such configuration manually, or eventually implement an additional parameter at generation-time.
The new parameter could look like this:
The text was updated successfully, but these errors were encountered: