{"_id":"@emilhdiaz/serverless-iam-roles-per-function","_rev":"1-d08f88f8854aa6388e98fc5826a2e8bc","name":"@emilhdiaz/serverless-iam-roles-per-function","dist-tags":{"latest":"1.0.4"},"versions":{"1.0.4":{"name":"@emilhdiaz/serverless-iam-roles-per-function","private":false,"version":"1.0.4","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/emilhdiaz/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.11"},"devDependencies":{"@types/chai":"^4.1.4","@types/lodash":"^4.14.116","@types/mocha":"^5.2.5","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.2","mocha":"^5.2.0","npm-get-version":"^1.0.2","nyc":"^13.3.0","rimraf":"^2.6.2","serverless":"^1.38.0","source-map-support":"^0.5.9","standard-version":"^4.4.0","ts-node":"^7.0.1","tslint":"^5.11.0","typescript":"^3.0.3"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"70740dedd16c5a7a1852bd216765a935a5bcddf4","bugs":{"url":"https://github.com/emilhdiaz/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/emilhdiaz/serverless-iam-roles-per-function#readme","_id":"@emilhdiaz/serverless-iam-roles-per-function@1.0.4","_nodeVersion":"11.10.0","_npmVersion":"6.7.0","dist":{"integrity":"sha512-C3iirvtH1dZMou8SWhERtzYhs9+lIS3iLZFz1VprvVHNltK7SJZUGQPnmI2GloLZK2qdhVWvdG2aQNcrweMX4Q==","shasum":"066a953b67af72a71e841a64cbd324fcb871cc7f","tarball":"https://registry.npmjs.org/@emilhdiaz/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-1.0.4.tgz","fileCount":11,"unpackedSize":71466,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcbtOkCRA9TVsSAnZWagAAgg4P/3pd6w/SDcxFGNeEd7Bu\ngv7dv2rgPoH29B1zFAvtT1fW/4AYSoGUYSSBXI+WzD+PXgi+QX80xPOqyZuR\nxSDuOTMUgb3HySDs8CUDvusa2r8/A55Anf0J0tSdsfpA+Pg4i37mwFCN81CF\ngL1DtwzgNOzI2WQvjIf41x1dyZ9NI4p2UOaiDTnZsiXccX0cp/oXc3GL1liF\nOR0TzySO5+P6qRxVHjbCYqyQ54795N85neddGropNOSt1UnBgWcniF0D5TKN\nOAgKogSPlRF+RIM44GJutmbNVx8HSkndN73j/HDRS1/A+bwDUtHwwLbIbyV+\nB5X2tjjPbeujnHm3TOEMWbSYEYQqoH3JjIXAtc6fagqa+AnMCzzx5MA/VAhN\n8v9UJnId8xoOazMSuCiXUVtX2vR2ZREYTwtHmuFi1AwqlIFhDHqY2wMx/4Cy\n6YYQGNGoH2w5E05ohOcfbcHZjgznZI+atpmFyxPkF1wlM53krCu6VWBMfJB6\nlA+1wLuqctdtD9afWgBuE5SZYCd2MN0grj2ZDWrE4ffZSddXNzdwSHsm4ad3\nmrm9OLWwFKnUJeRXFnAPM46l5sm1kmkuZkR4a1AiKihCxMLVPFUvmmxDMl3C\ny3RRbI30o3U3jTiPdiSpv7R6MG/3T+mvOy62B6TPn6N5r1OSvOXW2W/iMmmb\nciHn\r\n=EnKt\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFgy3YcIaiYnx60JPF89Vc6bd+OXErJNK0LPp7haCUf+AiBF5eWCOVj5z+1cWWl5ZQ6BWPOkrgV6lAv4wlefCnU++w=="}]},"maintainers":[{"name":"emilhdiaz","email":"emil.h.diaz@gmail.com"}],"_npmUser":{"name":"emilhdiaz","email":"emil.h.diaz@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_1.0.4_1550767011920_0.6230651174293116"},"_hasShrinkwrap":false}},"time":{"created":"2019-02-21T16:36:51.747Z","1.0.4":"2019-02-21T16:36:52.153Z","modified":"2022-04-05T07:33:20.141Z"},"maintainers":[{"name":"emilhdiaz","email":"emil.h.diaz@gmail.com"}],"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","homepage":"https://github.com/emilhdiaz/serverless-iam-roles-per-function#readme","keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"repository":{"type":"git","url":"git+https://github.com/emilhdiaz/serverless-iam-roles-per-function.git"},"author":{"name":"Functional One, Ltd."},"bugs":{"url":"https://github.com/emilhdiaz/serverless-iam-roles-per-function/issues"},"license":"MIT","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md"}