Q: A Lambda function is failing with `Access Denied` when trying to write to DynamoDB. How do you fix it?
Lambda functions use an execution role (IAM role). This role needs dynamodb:PutItem (or broader dynamodb:) permission on the target table.
#AWS #IAM & Security #L2 #Cloud #Infrastructure #IAM
🎙️ Candidate Opening & Architectural Context
""In our AWS cloud environment, we managed high-traffic microservices where this exact scenario occurred. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Lambda functions use an execution role (IAM role). This role needs dynamodb:PutItem (or broader dynamodb:*) permission on the target table.
- Go to Lambda → Configuration → Permissions → click the execution role name.
- In IAM, add an inline policy or attach a managed policy with DynamoDB permissions.
2️⃣
Remediation & Permanent Safeguards
Fix: Example policy: Always scope the Resource to the specific table ARN, not *. Principle of least privilege.
{
"Effect": "Allow",
"Action": ["dynamodb:PutItem", "dynamodb:GetItem"],
"Resource": "arn:aws:dynamodb:us-east-1:123456789:table/MyTable"
}
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Go to Lambda → Configuration → Permissions → click the execution role name.."
⚡ 60-Second Elevator Pitch Talking Points
- Go to Lambda → Configuration → Permissions → click the execution role name.
- In IAM, add an inline policy or attach a managed policy with DynamoDB permissions.
Advertisement