Give the Lambda function a dedicated execution role with only the S3 permissions its upload code needs, scoped to the intended bucket and—where practical—the intended object-key prefix. Keep that role separate from the Lambda resource-based policy that allows S3 to invoke the function. If clients can send file bytes directly to S3, a trusted backend can instead issue a short-lived presigned URL for a specific object key.
Understand the two permission directions
There are two distinct authorization questions in an S3-to-Lambda workflow:
- What can the function do? The Lambda execution role supplies permissions the running function uses when it calls S3, such as writing an object. AWS describes the execution role as the place to define access to other AWS resources and recommends granting only the permissions required for the task. AWS Lambda execution roles
- What may invoke the function? If S3 triggers Lambda, the function’s resource-based policy authorizes S3 to invoke it. This does not give the function permission to write to S3; that access belongs in the execution role. AWS service permissions for Lambda
Keeping these policies conceptually separate makes it easier to grant the function only its needed storage access while limiting which bucket can invoke it.
Choose who should send the file bytes
| Approach | Best fit | Permission boundary | Main trade-off |
|---|---|---|---|
| Lambda uploads to S3 | Lambda must transform, inspect, or control the bytes before storage | The execution role needs the S3 write permissions required by the code | Data passes through Lambda, and permissions must match the API calls the implementation makes |
| Client uploads with a presigned URL | The client can send bytes directly and a trusted backend can authorize a particular object upload | The URL delegates an operation allowed to its signing principal, for a specified key and limited validity | Anyone possessing the URL can use it within its permissions and validity |
The available AWS guidance does not establish a workload-specific size limit or a complete cost or performance comparison. Those depend on the particular workload and service configuration.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Set up a least-privilege execution role for direct uploads
1. Create a role for this function
Give the role a trust relationship that allows the Lambda service to assume it. Attach the logging permissions the function needs for its CloudWatch Logs behavior, then add the S3 permissions required by the upload implementation. AWS notes that Lambda needs CloudWatch access for its default logging behavior. AWS Lambda execution roles
2. Match S3 actions to the code
Do not choose permissions solely from the word “upload.” Confirm which API calls the code actually makes. A straightforward object write, multipart upload, a flow that reads input objects, and a flow using a customer-managed encryption key can require different permissions. Scope object access to the intended bucket and, where the design supports it, a specific key namespace. Avoid bucket-wide listing or unrelated object operations unless the code needs them.
Rank #2
AWS recommends least privilege, but the cited guidance does not define one universal action list for every upload implementation. The correct policy depends on the API calls, object-key design, bucket configuration, encryption choice, and any read or list operations.
3. Separate source and destination access
If the function reads from one bucket and writes to another, design the permissions for each bucket separately. AWS’s file-processing tutorial uses a source bucket and destination bucket, but attaches AmazonS3FullAccess as an instructional example. That broad managed policy is not a least-privilege production recommendation. AWS Lambda file-processing tutorial
4. Add S3 invocation permission separately
For an S3 event trigger, authorize the S3 service through the function’s resource-based policy. Constrain the permission to the expected bucket ARN and include the bucket owner’s AWS account as aws:SourceAccount. AWS’s example uses both conditions to address the risk of a deleted bucket name later being claimed by another account. AWS service permissions for Lambda
AWS recommends using a full JSON resource policy for flexible conditions. If using put-resource-policy, inspect the current policy first: that operation replaces the existing policy statements rather than appending to them. AWS service permissions for Lambda
5. Prevent a self-triggering write loop
If an S3 event invokes the function, do not write its output back into the same triggering path unless the event design prevents that output from matching the trigger. AWS warns that writing to the triggering bucket can cause recursive invocations and unexpected charges. Separate input and output buckets are one clear option in the AWS file-processing example. AWS Lambda file-processing tutorial
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use a presigned URL when the client can upload directly
If Lambda does not need to proxy or transform the file bytes, a trusted backend can create a presigned URL for a specific object key and return it to the client. The principal that signs the URL must have permission for the requested S3 operation. The client does not receive AWS credentials; the URL itself delegates the permitted operation. AWS S3 presigned URLs
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Treat the URL as a bearer token: anyone who obtains it can use it within its permissions and validity. Choose an expiry suited to the upload flow, restrict who receives it, and avoid exposing it in logs or treating it like an ordinary public link. If the URL was signed with temporary credentials, it cannot remain valid beyond those credentials’ expiry, even if a later URL expiry was requested.
For Signature Version 4 presigned requests, S3 bucket or access-point policies can use s3:signatureAge to limit signature age. IAM, bucket, or access-point policies can also impose network restrictions; account for the effect on other access paths before applying them. AWS S3 presigned URLs
Verify the policy against the actual workflow
Before rollout, check the deployed function’s real S3 calls and test the resulting permissions in the target account. Confirm that the role can perform required operations on intended objects, while unrelated buckets, keys, and actions remain outside its access. Also verify the trigger policy’s source bucket and account conditions, and confirm the output path cannot recursively match the input trigger. Exact least-privilege permissions cannot be specified correctly without these implementation details.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




