{"_id":"serverless-granular-iam","_rev":"54-4aeedf68bdb6dc60f105e261765fbf74","name":"serverless-granular-iam","dist-tags":{"latest":"2.1.0"},"versions":{"2.0.2":{"name":"serverless-granular-iam","version":"2.0.2","keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"author":{"name":"Functional One, Ltd."},"license":"MIT","_id":"serverless-granular-iam@2.0.2","maintainers":[{"name":"adriean.khisbe","email":"adriean.khisbe@live.fr"}],"homepage":"https://github.com/CoorpAcademy/serverless-granular-iam#readme","bugs":{"url":"https://github.com/CoorpAcademy/serverless-granular-iam/issues"},"nyc":{"all":true,"exclude":["**/*.d.ts"],"include":["src/lib/**"],"reporter":["html","text"],"extension":[".ts",".tsx"]},"dist":{"shasum":"b23c7d5e8274b96d7248bbd3534203e61acba327","tarball":"https://registry.npmjs.org/serverless-granular-iam/-/serverless-granular-iam-2.0.2.tgz","fileCount":11,"integrity":"sha512-Qw3tu7lnAm7pNxNo06teBCnsFI/S1lgWsJrLxfw2IygHZ/rH887Jy6rTHb1GTaoNExE/gNglernzz34Er8xCjA==","signatures":[{"sig":"MEQCIBH3Zm46BVHv4TXY/RrXiiy5FLAIVnM+GVStcfYSIysdAiBgQOCW2VQWIgM5O102tJRFZnlFriPLUw+6ortCLX0rEA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":73580,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe18nqCRA9TVsSAnZWagAAghgP/0+2M1A0YX0UjvYaLeAc\nKpCofX4aUhAaAySREI6o1Cnc1DP2t1VBt52/VB1VxItfGD/Z0JA2D0EsK4Ys\nO7OaYplpAY8wjaybxBatutjyp3apOG6Xm+XAwXZatUc9pp7ZZ02hxW+cHV67\nBZBNsgVZzI9OlIatlYSsx0qtTr9r3tcIhZefMOGH+MY18+TFA5ErJLtfj4HX\n3oLceICjvJ2/sYZDaL8PsJ+JQJ7yado82CwYGUf6siBYYqbas5QUqZ+Tvatf\nqPhkJbG2SCOFSPpMcpJ/PHkJYASj9MAGFl+9ZL4EDuj9sroJBEvy528XYL9I\nNh8urApMCqGdaOIo7l60/5U2ik/S5hLVYjC84L8MqeMuDlIWMxDNt8e4+qiQ\nRM9yShBakOIvD5Tgv2ESYl9oOC4iBf8T5pERkaCnndbsUOsTai4INgLM4SwE\nTu6gbUHBjpXCJawkhVE/UzSVUSc16vNX0C+20A2hRl3OiW0+y5JeWYLrg1Mj\nAW8wDOAizsxghJGI2sUDxfAukm9vOFltajgGuwUcE9cHWsFO/s5XgvsYGHDr\nXIxh9kNO9VBlN3HPzF0MWgi7+UdKlgQLKHCc3C0zlbR3CJOeWM9WEBpnHCYT\n9dULqMJm4pwC16sNm5d4WNofFl98uTOKeLIKAwUdE+/RsTLuzPnOzG/kArJK\nh6um\r\n=BcFa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"dist/lib/index.js","engines":{"node":">=6.10.0"},"gitHead":"242ddebaafd0064f9f5abf4bfd2a5694a628cae4","private":false,"scripts":{"test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","clean":"rimraf dist","watch":"tsc -w","compile":"tsc","release":"standard-version","coverage":"nyc report --reporter=text-lcov | coveralls","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","prepublishOnly":"npm run clean && npm run compile"},"_npmUser":{"name":"adriean.khisbe","email":"adriean.khisbe@live.fr"},"repository":{"url":"git+https://github.com/CoorpAcademy/serverless-granular-iam.git","type":"git"},"_npmVersion":"6.14.4","description":"A Serverless plugin to define IAM Role statements as part of the function definition block [serverless-iam-roles-per-function temporary fork]","directories":{},"_nodeVersion":"10.20.1","dependencies":{"lodash":"^4.17.15"},"_hasShrinkwrap":false,"devDependencies":{"nyc":"^14.1.1","chai":"^4.2.0","mocha":"^6.2.0","rimraf":"^3.0.0","tslint":"^5.19.0","ts-node":"^8.3.0","coveralls":"^3.0.6","serverless":"^1.51.0","typescript":"^3.6.2","@types/chai":"^4.2.0","@types/node":"^6.14.7","@types/mocha":"^5.2.7","@types/lodash":"^4.14.138","npm-get-version":"^1.0.2","standard-version":"^7.0.0","source-map-support":"^0.5.13","@serverless/enterprise-plugin":"^1.3.10"},"_npmOperationalInternal":{"tmp":"tmp/serverless-granular-iam_2.0.2_1591200234292_0.7165505271428334","host":"s3://npm-registry-packages"}},"2.1.0":{"name":"serverless-granular-iam","version":"2.1.0","keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"author":{"name":"Functional One, Ltd."},"license":"MIT","_id":"serverless-granular-iam@2.1.0","maintainers":[{"name":"adamska27","email":"adams.roy27@gmail.com"},{"name":"adriean.khisbe","email":"adriean.khisbe@live.fr"},{"name":"alanlanglois","email":"alan@etaminstudio.com"},{"name":"audric-coorp","email":"ad@coorpacademy.com"},{"name":"bybrunobarros","email":"bybrunobarros@gmail.com"},{"name":"coorpadmin","email":"system@coorpacademy.com"},{"name":"djamelsoualmi","email":"djamel.soualmi@coorpacademy.com"},{"name":"esa-coorp","email":"eric.sampaio@coorpacademy.com"},{"name":"fausto95","email":"faustokial95@outlook.pt"},{"name":"godu","email":"arthur.weber@viacesi.fr"},{"name":"jomaora","email":"jomaora@gmail.com"},{"name":"louistr11","email":"louis.trouve@coorpacademy.com"},{"name":"monial","email":"monia.laoufi@coorpacademy.com"},{"name":"silou","email":"silouane.galinou@efrei.net"}],"homepage":"https://github.com/CoorpAcademy/serverless-granular-iam#readme","bugs":{"url":"https://github.com/CoorpAcademy/serverless-granular-iam/issues"},"nyc":{"all":true,"exclude":["**/*.d.ts"],"include":["src/lib/**"],"reporter":["html","text"],"extension":[".ts",".tsx"]},"dist":{"shasum":"ab36d3ddde69c9e23760a1fe547d760a0f49951d","tarball":"https://registry.npmjs.org/serverless-granular-iam/-/serverless-granular-iam-2.1.0.tgz","fileCount":12,"integrity":"sha512-nEBfO5GgtzEJ/JGUpKuHG6NAsbWhirdnO4QidoE+V7DcgQt/vSFbSNYWBVKvOs64XjUzkN4T5hNVXQgu42pnug==","signatures":[{"sig":"MEUCIFsWqL/CtZ+MkB5tY0DsLtBlPrsREslOQmoHm76YKfdmAiEAu4L5CLdYXCfr53DrVJL6/VghCXEhFc8NFz4PiBxfF98=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":89251,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe3ijdCRA9TVsSAnZWagAAHY4QAJtLHwvvGdVHAbLPsIJv\nBGB3rnMNhIdYTYau7jUudHHrxC7Ov9tr/kmEK7xiaX+sSCf4HLv2Cc8NWT5m\nhG/5EUTwTQFpA05mYwjmwkk30nVhPGeIRFK+RjNF2ufLiA1GifxAssz58ZV4\nnib82VWt/D9VpGaF5c0y9OuF2wwpIJBq3sEE/2buL9R7Mlzwj8Ztv+l8PChw\nXMgi6K3x5PiHcXM5S/d1N1+arlrKh/4K15jtj9onxzpKDWCOz8/PYemUxedV\nXElZiRuPSSmE/mDcObaLmAWPtING1/WXfrR2Sw7TjZcIlo22Y+qEH5C/r0jp\ndGobJ0N2OZGvLt2p6lyJ4qW1BYXD43Y5M5CO+Ov4yS6uTerFvyuM47nu+IF/\nh5iDgCMV2W0tvgz+haMbrVMSODaHoICwXfv4aTiRpZWU1iPCREK6fiB3C8Th\ntte+ETWxglNm3QDJOzw08zf/B9r5c2orB6SwAZsiiJLvBWOmdYVLn9/8XRyP\nOaZM5snxd+NtkcisS3BIpcr95fiDHX/Nf8Bm5ATGeiv2Dr3OBixAZ2yePmg0\nZBxYblHqu26N+4kjkVxRs9oW0Oii1RowNbtvuCE1i1A+1fTpEPMQ1uIG9Spq\nvrcG1Mj9PMb5Msxrz7mUtVvvsg3oOWBrdWjfduFKnJdL/3dKx5bNTY2hWwP2\n5wPS\r\n=nT1A\r\n-----END PGP SIGNATURE-----\r\n"},"main":"dist/lib/index.js","engines":{"node":">=6.10.0"},"gitHead":"6d1a40d006e32f64f3212d1963549fa0c1dafe58","private":false,"scripts":{"test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","clean":"rimraf dist","watch":"tsc -w","compile":"tsc","prepare":"npm run clean && npm run compile","release":"standard-version","coverage":"nyc report --reporter=text-lcov | coveralls","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js"},"_npmUser":{"name":"adriean.khisbe","email":"adriean.khisbe@live.fr"},"repository":{"url":"git+https://github.com/CoorpAcademy/serverless-granular-iam.git","type":"git"},"_npmVersion":"6.14.4","description":"A Serverless plugin to define IAM Role statements as part of the function definition block [serverless-iam-roles-per-function temporary fork]","directories":{},"_nodeVersion":"10.20.1","dependencies":{"lodash":"^4.17.15"},"_hasShrinkwrap":false,"devDependencies":{"nyc":"^14.1.1","chai":"^4.2.0","mocha":"^6.2.0","rimraf":"^3.0.0","tslint":"^5.19.0","ts-node":"^8.3.0","coveralls":"^3.0.6","serverless":"^1.51.0","typescript":"^3.7.5","@types/chai":"^4.2.0","@types/node":"^6.14.7","@types/mocha":"^5.2.7","@types/lodash":"^4.14.138","npm-get-version":"^1.0.2","standard-version":"^7.0.0","source-map-support":"^0.5.13","@serverless/enterprise-plugin":"^1.3.10"},"_npmOperationalInternal":{"tmp":"tmp/serverless-granular-iam_2.1.0_1591617756961_0.09750804898771848","host":"s3://npm-registry-packages"}}},"time":{"created":"2020-06-03T16:03:54.291Z","modified":"2026-08-03T13:27:21.272Z","2.0.2":"2020-06-03T16:03:54.422Z","2.1.0":"2020-06-08T12:02:37.111Z"},"bugs":{"url":"https://github.com/CoorpAcademy/serverless-granular-iam/issues"},"author":{"name":"Functional One, Ltd."},"license":"MIT","homepage":"https://github.com/CoorpAcademy/serverless-granular-iam#readme","keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"repository":{"url":"git+https://github.com/CoorpAcademy/serverless-granular-iam.git","type":"git"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block [serverless-iam-roles-per-function temporary fork]","maintainers":[{"email":"silouane.galinou.dev@gmail.com","name":"silou"},{"email":"system@coorpacademy.com","name":"coorpadmin"},{"email":"eric.sampaio@coorpacademy.com","name":"esa-coorp"},{"email":"adriean.khisbe@live.fr","name":"adriean.khisbe"},{"email":"adams.roy27@gmail.com","name":"adamska27"},{"email":"djamel.soualmi@coorpacademy.com","name":"djamelsoualmi"},{"email":"elena.morana@coorpacademy.com","name":"emorana"},{"email":"emeline.leduc@coorpacademy.com","name":"emeline75"},{"email":"phuoc.tran@go1.com","name":"phuoctran8801"},{"email":"aung.maw@go1.com","name":"aung-go1"},{"email":"adams.roy@go1.com","name":"adamska28"},{"email":"chris.dugne@uralys.com","name":"chrisdugne"}],"readme":"# serverless-granular-iam [*Serverless IAM Roles Per Function Plugin* **Fork**]\n\n[![serverless][sls-image]][sls-url]\n[![npm package][npm-image]][npm-url]\n[![Build Status][travis-image]][travis-url]\n[![Coverage Status][coveralls-image]][coveralls-url]\n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url]\n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block.\n\n:rotating_light: This is a fork from [functionalone/serverless-granular-iam](https://github.com/functionalone/serverless-granular-iam)\nThis is meant to be temporary until _iamManagedPolicies_ are supported with [#19](https://github.com/functionalone/serverless-granular-iam/pull/19) landing.\n\n## Installation\n```\nnpm install --save-dev serverless-granular-iam\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-granular-iam\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"\n        Action:\n          - dynamodb:GetItem\n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put\n    iamRoleStatements:\n      - Effect: \"Allow\"\n        Action:\n          - dynamodb:PutItem\n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"\n        Action:\n          - dynamodb:GetItem\n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-granular-iam:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n```\nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name\n    iamRoleStatements:\n      - Effect: \"Allow\"\n        Action:\n          - dynamodb:GetItem\n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-granular-iam.svg\n[npm-url]:http://npmjs.org/package/serverless-granular-iam\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/CoorpAcademy/serverless-granular-iam.svg?branch=master\n[travis-url]:https://travis-ci.org/CoorpAcademy/serverless-granular-iam\n[david-image]:https://david-dm.org/CoorpAcademy/serverless-granular-iam/status.svg\n[david-url]:https://david-dm.org/CoorpAcademy/serverless-granular-iam\n[coveralls-image]:https://coveralls.io/repos/github/CoorpAcademy/serverless-granular-iam/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/CoorpAcademy/serverless-granular-iam?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-granular-iam.svg\n\n","readmeFilename":"README.md"}