# \[Solved\] Cannot access SQS queue message through Lambda function

**URL:** <https://forum.serverless.com/t/solved-cannot-access-sqs-queue-message-through-lambda-function/3666>\
**Category:** Serverless Framework\
**Tags:** aws\
**Created:** [February 2, 2018, 12:54am UTC](https://forum.serverless.com/t/solved-cannot-access-sqs-queue-message-through-lambda-function/3666 "2018-02-02T00:54:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdesilva](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@mdesilva](https://forum.serverless.com/u/mdesilva)\
**Post date:** [February 2, 2018, 12:54am UTC](https://forum.serverless.com/t/solved-cannot-access-sqs-queue-message-through-lambda-function/3666/1 "2018-02-02T00:54:15Z")

</div>

I have a lambda function which is suppose to read message from a SQS queue and process. When I deployed everything to AWS and try to call the lambda function getting `"errorMessage":"Access to the resource https://sqs.us-east-1.amazonaws.com/ is denied."`

However, Lambda function can read the messages when it is run locally through Serverless Offline plugin. I have given proper permission as below. And my project is based on node.js.  
Here is the permission block,

```auto
    - Effect: Allow
      Action:
        - sqs:*
      Resource:
        - Fn::GetAtt:
          - NotificationQueue
          - Arn
```

---

<div class="post-metadata">

**Author:** ![DavidWells](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/davidwells/32/201_2.png) [@DavidWells](https://forum.serverless.com/u/DavidWells)\
**Post date:** [February 2, 2018, 1:43am UTC](https://forum.serverless.com/t/solved-cannot-access-sqs-queue-message-through-lambda-function/3666/2 "2018-02-02T01:43:10Z")

</div>

Sounds like you also need IAM permissions set on the lambda pulling from SQS

Locally it works with your creds and sdk invoke under the hood but in AWS the lambda needs permissions as well.

Check out [https://github.com/sbstjn/sqs-worker-serverless/blob/master/serverless.yml#L18](https://github.com/sbstjn/sqs-worker-serverless/blob/master/serverless.yml#L18) for a good SQS example

---

<div class="post-metadata">

**Author:** ![mdesilva](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@mdesilva](https://forum.serverless.com/u/mdesilva)\
**Post date:** [February 2, 2018, 2:20am UTC](https://forum.serverless.com/t/solved-cannot-access-sqs-queue-message-through-lambda-function/3666/3 "2018-02-02T02:20:30Z")

</div>

Thanks for the response. I just figured out Serverless has not created IAM roles while deploying. Not sure why, and I am going to dig into the stack. I manually edited the policy created by Serverles for lambda and it worked.

---

<div class="post-metadata">

**Author:** ![mdesilva](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@mdesilva](https://forum.serverless.com/u/mdesilva)\
**Post date:** [February 2, 2018, 3:27am UTC](https://forum.serverless.com/t/solved-cannot-access-sqs-queue-message-through-lambda-function/3666/4 "2018-02-02T03:27:26Z")

</div>

Figured out the issue. It was due to improper indentation of `iamRoleStatements`.
