Skip to content

aws_lambda example fails due to missing role #632

Description

@cp2423

Following the aws_lambda readme (see link below) the app does not work. In slack I got a an error message, and the CloudWatch logs reported found [user id redacted]:

b'{
    "Message": "User: arn:aws:sts::************:assumed-role/bolt_python_lambda_invocation/bolt_py_function is not authorized to perform: lambda:InvokeFunction on resource: arn:aws:lambda:eu-west-2:************:function:bolt_py_function because no identity-based policy allows the lambda:InvokeFunction action"
}'

I resolved this by adding the "AWSLambdaRole" to the user. So I suggest the following line in the docs needs to be updated, from:

  • Check the "AWSLambdaBasicExecutionRole" and "AWSLambdaExecute" policies

to:

  • Check the "AWSLambdaBasicExecutionRole", "AWSLambdaExecute" and "AWSLambdaRole" policies

Please note I am no AWS expert, it might be that this extra role renders one of the others redundant, I do not know! But I know this change is sufficient to make the example work :)

The page URLs

Activity

  1. self-assigned this
    on Apr 13, 2022
  2. added
    docsImprovements or additions to documentation
    on Apr 13, 2022
  3. added this to the 1.14.0 milestone on Apr 13, 2022
  4. filmaj commented on Apr 13, 2022

    @filmaj
    Contributor

    Hey @cp2423, thanks for pointing this out! Indeed you are right, Invoke is a requirement. I will update the docs shortly!

  5. added a commit that references this issue on Apr 13, 2022
    a1239d2
  6. added a commit that references this issue on Apr 13, 2022
    02c3520
  7. modified the milestones: 1.14.0, 1.13.1 on Apr 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

docsImprovements or additions to documentation

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions