# Unclear how to reference Lambda Role ARN in serverless.yml

**URL:** <https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147>\
**Category:** Serverless Framework\
**Tags:** aws\
**Created:** [January 19, 2017, 9:24pm UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147 "2017-01-19T21:24:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![brettneese](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/brettneese/32/411_2.png) [@brettneese](https://forum.serverless.com/u/brettneese)\
**Post date:** [January 19, 2017, 9:24pm UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/1 "2017-01-19T21:24:02Z")

</div>

I am trying to use these to make a lifecycle hook SNS notification and run my script based on this.

I have a set of role statements in my serverless.yml (global for the service, under the Provider block):

```auto
 iamRoleStatements: 
    - Effect: "Allow"
      Action:
        - "ec2:DescribeInstances"
        - "ec2:CreateNetworkInterface"
        - "ec2:AttachNetworkInterface"
        - "ec2:DescribeNetworkInterfaces"
        - "autoscaling:CompleteLifecycleAction"

```

and a CloudFormation resource:

```auto
resources:
 Resources:
   NewResource:
     Type: AWS::AutoScaling::LifecycleHook
     Properties:
       AutoScalingGroupName: AutoScalingGroupName
       LifecycleTransition: EC2_INSTANCE_TERMINATING
       NotificationTargetARN:
       RoleARN: 

```

How do I find out what the Role ARN for the Lambda script is inside the serverless.yml file? Is there a way under the ${self} variable to get at the role ARN, or do I need to construct my own ARN from the function name, etc?

---

<div class="post-metadata">

**Author:** ![dkcwd](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/dkcwd/32/185_2.png) [@dkcwd](https://forum.serverless.com/u/dkcwd)\
**Post date:** [January 21, 2017, 12:55am UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/2 "2017-01-21T00:55:02Z")

</div>

Hi @brettneese, this might not be much help to you right now but just want to let you know what I have done with some of my own example projects.

I wanted to have more control of the role used to execute Lambda functions and in my case I decided to set up the role manually using the AWS IAM ui and gave it PowerUserAccess.

I then manually updated my serverless.yml with the `profile` I wanted to use and the `role`.

```
service: some-service

provider:
  name: aws
  runtime: nodejs4.3
  stage: dev
  profile: name-of-my-aws-credentials-profile
  region: ap-southeast-2
  role: arn:aws:iam::707945501234:role/name-of-my-serverless-power-user-role

```

This thread has more information about roles per function: [https://github.com/serverless/serverless/pull/2073](https://github.com/serverless/serverless/pull/2073)

Also there is more on custom roles in the Serverless Framework docs here: [https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles)

---

<div class="post-metadata">

**Author:** ![rowanu](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/rowanu/32/75_2.png) [@rowanu](https://forum.serverless.com/u/rowanu)\
**Post date:** [January 21, 2017, 3:53am UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/3 "2017-01-21T03:53:30Z")

</div>

Because you’re trying to use the ARN in the `resources` section (which is just CloudFormation) you can use the intrinsic function [`GetAtt`](http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/intrinsic-function-reference-getatt.html).

Here’s what you need for your RoleARN:

```auto
RoleARN:
  Fn::GetAtt: [IamRoleLambdaExecution, Arn]

```

---

<div class="post-metadata">

**Author:** ![kiddrew](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/kiddrew/32/3705_2.png) [@kiddrew](https://forum.serverless.com/u/kiddrew)\
**Post date:** [December 4, 2019, 7:02pm UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/4 "2019-12-04T19:02:02Z")

</div>

I realize this is an old thread, but Google leads here and the last proposed solution does not work. It still results in a CF error:

`Error: The CloudFormation template is invalid: Template error: instance of Fn::GetAtt references undefined resource IamRoleLambdaExecution`

---

<div class="post-metadata">

**Author:** ![yadynesh](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/yadynesh/32/3945_2.png) [@yadynesh](https://forum.serverless.com/u/yadynesh)\
**Post date:** [January 31, 2020, 7:45am UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/5 "2020-01-31T07:45:37Z")

</div>

> [@rowanu](#):
>
> IamRoleLambdaExecution

How did you solve this?

---

<div class="post-metadata">

**Author:** ![myalias](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@myalias](https://forum.serverless.com/u/myalias)\
**Post date:** [February 13, 2020, 9:12pm UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/7 "2020-02-13T21:12:51Z")

</div>

Using:

`Role: !GettAtt YourIamRole.Arn`

Worked for me.

---

<div class="post-metadata">

**Author:** ![jkbiggs](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/jkbiggs/32/4665_2.png) [@jkbiggs](https://forum.serverless.com/u/jkbiggs)\
**Post date:** [November 3, 2020, 1:12am UTC](https://forum.serverless.com/t/unclear-how-to-reference-lambda-role-arn-in-serverless-yml/1147/8 "2020-11-03T01:12:03Z")

</div>

`Role: !GetAtt YourIamRole.Arn`
