# Generate IAM permissions for invoking lambda from lambda

**URL:** <https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338>\
**Category:** Serverless Framework\
**Tags:** aws\
**Created:** [September 20, 2016, 12:21am UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338 "2016-09-20T00:21:14Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![aarbrown](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/aarbrown/32/145_2.png) [@aarbrown](https://forum.serverless.com/u/aarbrown)\
**Post date:** [September 20, 2016, 12:21am UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/1 "2016-09-20T00:21:14Z")

</div>

Hello,

I am very new to the Serverless framework. I tried to invoke a lambda function created in the serverless framework from another serverless framework lambda function (using the aws sdk) and I received an error along the lines of “… is not authorized to perform: lambda:InvokeFunction on resource: …”.

It seems like this is something I’d setup in the serverless.yml file, but I’m just not sure what I should be doing.

Any help is much appreciated.

---

<div class="post-metadata">

**Author:** ![Adrian](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@Adrian](https://forum.serverless.com/u/Adrian)\
**Post date:** [September 20, 2016, 12:35am UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/2 "2016-09-20T00:35:30Z")

</div>

I just ran into something similar with api-gateway to lambda to dynamodb. So I went into my AWS console and found the role serverless created (in the IAM console) and attached an admin policy to it (just for testing purposes) and cleared it up.  
I too would think this could be configurable but haven’t quite figured it out. Still finding my way around as well. Examples would be great.

---

<div class="post-metadata">

**Author:** ![rowanu](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/rowanu/32/75_2.png) [@rowanu](https://forum.serverless.com/u/rowanu)\
**Post date:** [September 20, 2016, 3:11am UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/3 "2016-09-20T03:11:14Z")

</div>

Just watch out with that Adrian, as you might have issues/errors when removing the service that you’ve modified manually since resources are managed by CloudFormation in the background.

Ideally you would give you functions more IAM permissions. Here’s what I have to allow my functions to call each other:

```auto
provider:
  ...
  iamRoleStatements:
    - Effect: Allow
      Action:
        - lambda:InvokeFunction
        - lambda:InvokeAsync
      Resource: "*"

```

This way the permissions are managed by CFN, and will be cleaned-up for you (and in the right order) so you don’t get any surprises.

---

<div class="post-metadata">

**Author:** ![aarbrown](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/aarbrown/32/145_2.png) [@aarbrown](https://forum.serverless.com/u/aarbrown)\
**Post date:** [September 20, 2016, 12:59pm UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/4 "2016-09-20T12:59:28Z")

</div>

Thank you @rowanu! That worked beautifully. I am very quickly learning that I need to learn a lot more about CFN in order to get the most out of this framework (and AWS, frankly) 😄

---

<div class="post-metadata">

**Author:** ![Adrian](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@Adrian](https://forum.serverless.com/u/Adrian)\
**Post date:** [September 20, 2016, 10:51pm UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/5 "2016-09-20T22:51:05Z")

</div>

I agree. I had not seen the lambda yaml for working with DynamoDB, when I tried some I did find out on the web I was having no luck. So thanks, I’ll refactor.

Is there a good place in the docs to see these examples? Or am I missing it?

---

<div class="post-metadata">

**Author:** ![Adrian](https://avatars.discourse-cdn.com/v4/letter/a/82dd89/32.png) [@Adrian](https://forum.serverless.com/u/Adrian)\
**Post date:** [September 20, 2016, 10:54pm UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/6 "2016-09-20T22:54:26Z")

</div>

NM … I found this [https://serverless.com/blog/serverless-v1-0-beta-release-2/](https://serverless.com/blog/serverless-v1-0-beta-release-2/)  
Sorry, getting there slowly.  
Works great.

---

<div class="post-metadata">

**Author:** ![mattdamon108](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/mattdamon108/32/2977_2.png) [@mattdamon108](https://forum.serverless.com/u/mattdamon108)\
**Post date:** [January 24, 2019, 5:53am UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/7 "2019-01-24T05:53:58Z")

</div>

Thanks! Works like charms.

---

<div class="post-metadata">

**Author:** ![HarryCaveMan](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@HarryCaveMan](https://forum.serverless.com/u/HarryCaveMan)\
**Post date:** [January 8, 2020, 5:37pm UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/8 "2020-01-08T17:37:06Z")

</div>

using `Resource: "*"` in your policies often represents a security risk. You should probably use something more granular and specify a `sourceArn` specific to the lambda you would like to be allowed to invoke.

---

<div class="post-metadata">

**Author:** ![kilgarenone](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/kilgarenone/32/1883_2.png) [@kilgarenone](https://forum.serverless.com/u/kilgarenone)\
**Post date:** [May 29, 2020, 6:35am UTC](https://forum.serverless.com/t/generate-iam-permissions-for-invoking-lambda-from-lambda/338/9 "2020-05-29T06:35:17Z")

</div>

I would like to avoid doing `Resource: "*"`, but I have no idea how to write out the granular role/resource in Cloudformation syntax in my serverless.yml…
