{"_id":"serverless-iam-roles-per-function","_rev":"36-c9aa7cd3b4285964e664ff0e41052e27","name":"serverless-iam-roles-per-function","description":"A Serverless plugin to define IAM Role statements as part of the function definition block","dist-tags":{"latest":"3.2.0","next":"3.2.0-e97ab49"},"versions":{"0.1.0":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.0","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.4"},"devDependencies":{"@types/chai":"^4.0.3","@types/core-js":"^0.9.42","@types/lodash":"^4.14.99","@types/mocha":"^2.2.48","@types/node":"^9.4.0","chai":"^4.1.2","mocha":"^5.0.0","rimraf":"^2.6.2","serverless":"^1.26.0","standard-version":"^4.3.0","tslint":"^5.6.0","typescript":"^2.6.1"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"b74700eaf521a8ccb02f61bd41c9ef533f31a382","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.0","_npmVersion":"5.5.1","_nodeVersion":"6.11.1","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-uaMq50EMO/yD7kN39gTlNVlQlh2y6veaTSGcXjiOUY33DE6kSa2zul3qEZkCYS66cx68CBlNHOwzdePtmdXi4Q==","shasum":"e788dbd8c337afd67b7826be559bb0929e186b27","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.0.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAS4SW8duL5M1Hxc6FQ86ugng0QMySX9u275Wy+ywmELAiBQyRcp7XL5Tm/sl2axw8/YW8a7PNqpAa2kX2t4nEx+vg=="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function-0.1.0.tgz_1517440943528_0.9071670745033771"},"directories":{}},"0.1.1":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.1","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.4"},"devDependencies":{"@types/chai":"^4.0.3","@types/core-js":"^0.9.42","@types/lodash":"^4.14.99","@types/mocha":"^2.2.48","@types/node":"^9.4.0","chai":"^4.1.2","mocha":"^5.0.0","rimraf":"^2.6.2","serverless":"^1.26.0","standard-version":"^4.3.0","tslint":"^5.6.0","typescript":"^2.6.1"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"799aebbe252d3c1b8b07aa131f067d625a1352bc","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.1","_npmVersion":"5.5.1","_nodeVersion":"6.11.1","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-kswYeFqAbzdFP+tlHnprS7Rpf/bgENs9uf8xfLAKreGrAAzDQiTunqsXcwLfuN5P0WnFsQRCaG7KEHiR7dKP0g==","shasum":"d0ceb64fdfa030d83df32631db260b38870d91ba","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.1.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCO+vOu2CSsOGQgWCdEtzwnMem+75430fq3tVqWVJuIJAIhAIgX/js4lIY6kI4W4mHIQ0KOvX3TQubaXuhnSjp2kZey"}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function-0.1.1.tgz_1517504708500_0.24320348375476897"},"directories":{}},"0.1.2":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.2","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.4"},"devDependencies":{"@types/chai":"^4.0.3","@types/lodash":"^4.14.99","@types/mocha":"^2.2.48","@types/node":"^9.4.0","chai":"^4.1.2","mocha":"^5.0.0","rimraf":"^2.6.2","serverless":"^1.26.0","standard-version":"^4.3.0","tslint":"^5.6.0","typescript":"^2.6.1"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"16c7127e58886d7723bce3c9a70fba9d6fa27905","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.2","_npmVersion":"5.5.1","_nodeVersion":"6.11.1","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-5+s5n24iDzgdnI7FP0PoleaVCaiTBRaEAFrgJYkSfGqrOOwNI/K5rY7xkjNqkuCc49hPtCpLWAjxHWyNtZkmBQ==","shasum":"9d06e946ebb61029a504b50e4235c6ea5641005a","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.2.tgz","fileCount":11,"unpackedSize":33601,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCwfI0eJMWixphuFBz6KhO6NH3Qvf2IFAb9VE7dFhr6bwIgIzcB71re0jbiCnyk66ORw2kW+F/lHwo0pEWKMU1I0Uw="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.2_1518030086493_0.060547356799756535"},"_hasShrinkwrap":false},"0.1.3":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.3","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.5"},"devDependencies":{"@types/chai":"^4.0.3","@types/lodash":"^4.14.99","@types/mocha":"^2.2.48","@types/node":"^9.4.0","chai":"^4.1.2","mocha":"^5.0.1","rimraf":"^2.6.2","serverless":"^1.26.0","standard-version":"^4.3.0","tslint":"^5.6.0","typescript":"^2.7.2"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"0a3134466c56bf6fef7da1edcd37c129539420d0","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.3","_npmVersion":"5.5.1","_nodeVersion":"6.11.1","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-JSaXjiTHRFtaSAFb7NtB42HUJuGEKFSvb0jk/mabLYTsaU+6YdIrlqCeCawF36sMX4aXdH29tSeFWHa/xyJ9yg==","shasum":"f6613eb16c709a4b4a52aa2490c792781fe45865","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.3.tgz","fileCount":11,"unpackedSize":40394,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDgoWEeoueJboGuhQtfMZLCYoabGHQp+0sQ2MZnXbzUOQIgU5/2fEQUgE6ukviZnWFg1yKiEQwvkMaDY6ldhlhN5U4="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.3_1519120048539_0.893553076058687"},"_hasShrinkwrap":false},"0.1.4":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.4","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.5"},"devDependencies":{"@types/chai":"^4.0.3","@types/lodash":"^4.14.99","@types/mocha":"^2.2.48","@types/node":"^9.4.0","chai":"^4.1.2","mocha":"^5.0.1","rimraf":"^2.6.2","serverless":"^1.26.0","standard-version":"^4.3.0","tslint":"^5.6.0","typescript":"^2.7.2"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"4fbd4e70fbbf84de0b9e5a4b05d129d7093f0e11","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.4","_npmVersion":"5.5.1","_nodeVersion":"6.11.1","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-vUGzaH3Jf/3OYfNo9zdatqE0grIdhfLp6Kq3kiVBsoioWCGGImAypSZbOg8UOKsc/kMqnQjACyp0GGWAH2oPOQ==","shasum":"8fbccac7cf52c0295e181f3ac468a62e5dcf5dcc","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.4.tgz","fileCount":11,"unpackedSize":53911,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDx4UC09VWjbnRGMqBxLnS2aJnRLmd9H6w1vSspPagQ+QIhAKpdEjtHh5wU9UK9vumccd+ebzQ5doH+iGQQ98yssJqP"}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.4_1519407022466_0.0795942310277189"},"_hasShrinkwrap":false},"0.1.5":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.5","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.5"},"devDependencies":{"@types/chai":"^4.0.3","@types/lodash":"^4.14.99","@types/mocha":"^2.2.48","@types/node":"^9.4.0","chai":"^4.1.2","mocha":"^5.0.1","rimraf":"^2.6.2","serverless":"^1.26.0","standard-version":"^4.3.0","tslint":"^5.6.0","typescript":"^2.7.2"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"49bfdd6fad107de4bff67c5056e35b3d11144533","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.5","_npmVersion":"5.5.1","_nodeVersion":"6.11.1","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-9JTFaa9eGqyYSrb41CtmgJyX7vVX78UBgNvZFhrUUECkRcT/n14ScHCOJkz3KszrPODEorXk2fEj9Eja0tBBBA==","shasum":"75f71a4d21ed4f80e4c788db0f83eef8a996d133","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.5.tgz","fileCount":11,"unpackedSize":55603,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDX8D7PvTUG3E75bTaXQxQSoed0SodfAsT3Se3CwZtgQAIhANo1N/y5lTBVRS0nnrrje9Z9dzvk6k2OHY/Gu1ss+Ot7"}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.5_1519558055865_0.8206345494965619"},"_hasShrinkwrap":false},"0.1.6":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.6","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.3","@types/lodash":"^4.14.108","@types/mocha":"^5.2.0","@types/node":"^6.0.110","chai":"^4.1.2","mocha":"^5.1.1","rimraf":"^2.6.2","serverless":"^1.27.2","standard-version":"^4.3.0","tslint":"^5.10.0","typescript":"^2.8.3"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"e44fed0b8e35e114758d68849d2f9347fa22b1af","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.6","_npmVersion":"6.0.1","_nodeVersion":"6.10.3","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-48Am3xChlQO1n9/+9vHSA8xzngK5FFnDzFqelGSyVaUne/94p0k78ijfH2mYJlv55Gl89z2jfIWUdxLYmmGa3g==","shasum":"08850d036bde14c91f34de6742a1c5cc2886b0c6","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.6.tgz","fileCount":11,"unpackedSize":55526,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJa+0VoCRA9TVsSAnZWagAAw8YP/2eT7C8ltUkLN4ma7mgo\nyD4axQcTtbCm2SO0HaBHfAaotH7eZ1PzdA1eOV2FjYoeUnzpD6r1IdzK/Ann\n9l+298y72+E8AY5l6WVBoOwPaNQnZFPl4dIBtFyHQEda35r3sOUafTC7q3o2\nMkn+rv3A5Qbeeo3CjKa6el1phsLLwBgarP36OJmOUdTRD8DVXkoOwjlU/SpZ\nThuEssdwj2K+z/5CNmhQ2EvdSZLlPC/6PBILI2lHtaEZJCQJd/5kkP/GZt6W\nI+ruYFUyrwMeAOKpPE6n1dPKs9C9ybPu40EDnmsZOg54rkibrkmCWVAXfB7S\ndc5vbQWs2412DZoMsHtwzjCwOflR10KzS+Cry46G0IVMQ4Jxxlelz8jMJdmn\nA+Cfh1+pVPwvf1iuW9AIzyzemVQaShzgZEJpeU9OZYzuMyX4dmIBS3q4mf8O\nOL5UoehaUTWuTzgzaLkzlfEDAH4NLVkjAt2oy0CZ5WE3LLfqzrbxr5HncXME\nVZ9vEkXmvRzCG3vel7dpWPv5jLq0JOgpyzIfDUbBt99ESHLHnv8d46JzQUYA\nSbZeys1eDSGg6LXsf9SaDa/JMnHlySufAV7JJ5hxiR4vSwU6jdwdZPgkm+HJ\nWpQfjf0ea0tnbvQFv6SzyWe15Q/wWFTycjnOJtXYonwLxu6ZiP9/Shls7cZl\niNRw\r\n=5JcH\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDVwZ/c8tFWXPTHrWpZWjUt+ME4GM8tZyABLUj8VDL5vgIgCIRb0tSpNEBYQinXFIUtp0EZURvQiqApRy4Ijw5XEeo="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.6_1526416743506_0.06783142540105414"},"_hasShrinkwrap":false},"0.1.7":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.7","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.3","@types/lodash":"^4.14.108","@types/mocha":"^5.2.0","@types/node":"^6.0.110","chai":"^4.1.2","mocha":"^5.1.1","rimraf":"^2.6.2","serverless":"^1.27.2","standard-version":"^4.3.0","tslint":"^5.10.0","typescript":"^2.8.3"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"50a405b314938554d459754dac6bdb3805696489","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.7","_npmVersion":"6.0.1","_nodeVersion":"6.10.3","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-Fj/FDgDGUHW6tOH8VkWbpWUL+SFInLGN5+pJHlC/q3r1O68qxENX7y1B7ti1IlZf8mJR6nwF2MIVS2B7PMnMkA==","shasum":"31b6a1774c7e2a5410d96c23443ac4626be30cb1","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.7.tgz","fileCount":11,"unpackedSize":56037,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJa/J96CRA9TVsSAnZWagAAACcP/36msbpD484Ak3wT7/19\ntaqgcOwz+gUwxcZRQMa9vFgUUfKg5ZvEaZ3zQRKRKZTMBqT6GU3+ZF2OTASH\navrIt3ODcOwHVhb9+IX8rn4BaxNVOZFpttqLpoTHOCtMgk0cI0em6c7yLjrz\nvgZDLICorirODesvLe3xzy+FeC9LRgcDj0Meoroq5H4mwKscKy2A6szIB0CN\n2LQ0zbyufKg3X45F25l+3CTuzqbbBcDVRI6IS3sqZLLBCkDiiartuTZKcVo+\ny4QKGLweKwdlAFe4O4n1MWXCuOQaoIAmWO93R6JKtiU4gxhhuRl8SxP1qUg+\nokXpDlR47EXQEsM+Jn+LAza9yHojzZ7nQYKISMWzBKWfBZWqujrHdw463vTA\nwO0ZQGw/0TXcYnxKj+soRciacmP5rQD/sTI+GwVIoafUn8AL9fL9xO+5CA9S\n3ea8mu6d9yRulbUZPwnIJWXi1vMu260q+IEJRbiFtXrp5SEkwMsM4U3OxLfq\nBduWOjk1hesMYArEg2YGjgskj5eKCzsPh69bUcK9YGy/3rYE3WpeHrz8Ho6k\n7vWz5f5GevFIyM22Td0mocii+Eszset2ZnZrH3mAVhxjH7arbZ/CgcIo77ce\nWKfW3oEs5JzohfMIBTgLYRO7gbvPTI+Vz8eMeO6bpBYk1tqBSKVxJMzT2c9y\nptfD\r\n=/xlY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCMsYl1hGpXuuAfe/MDxOJRhJv9DlU75sngNezZC72kqwIhAK8SERcaMB1DbE4L8V7sGvnK1hsKZLWU7japNPgvZND1"}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.7_1526505330276_0.34840820302269626"},"_hasShrinkwrap":false},"0.1.8":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.8","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test":"mocha   ./dist/test/**/*.test.js","pretest":"npm run compile","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.3","@types/lodash":"^4.14.108","@types/mocha":"^5.2.0","@types/node":"^6.0.110","chai":"^4.1.2","mocha":"^5.1.1","rimraf":"^2.6.2","serverless":"^1.27.2","standard-version":"^4.3.0","tslint":"^5.10.0","typescript":"^2.8.3"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"gitHead":"b98b91fc5ed985a1bf1cbcefb6792bdca4cbf248","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.8","_npmVersion":"6.0.1","_nodeVersion":"6.10.3","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-Y5TAYDvW9RT02MaEXB3xllr6ATuPntnxebpu2loEB49kHcrO+KY3mxQiqT+jeV0LUtEYa1ZvXuFu4XiWf6NEbw==","shasum":"ea314b643ca93c4eb09f6e253d5a61326e0ac4bb","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.8.tgz","fileCount":11,"unpackedSize":56374,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJa/ZPbCRA9TVsSAnZWagAAkxoP/0+bDH3KC9V9JTmtigxi\nYrr2VFvMeW5EffFaqUif+TA7y5FFtSwfRSa8kUDLBFhKPSayMrUpFkBBGyVg\n5U79apt2LWttknYxPnzL4LYrjwuNTLi5rkQCgsQxkVaSr0BGAdg7HO7lTB4i\nqEyV3ZB8rCAAX1P4YrFehb0K67S7kIvvguXsSMW4y1ZbxMSfnaUYrhHXimO8\npnCeHVf9h70w94bO9WE2brAisrHt6Xm67j4czcUYL/0Gryd4zALr4YqLIpXT\nID5WI2cgAs3pUupCFEAOQwJoA2odD6bYLre5grpmVkyYIzS3SvVmZC8jaQ5K\nQBmxVBJG877hTH+PZchiFS0bZXGLVL/xl8yhZnRYmwWE5+URkMWDreTou5cG\nfi1W59eEIHUfXi0kZKDVyYfgi+ydgXg3jQVdeF5EaYWstOK/HqQH2tJ4TANp\nIEtOXj3/CbTCOAGRrQ7Nxi6Au8s2tfycUKHULdTPvTzxPzJTJje08RFsLjVn\ngkskTzmwuBtShdcRTSJBkTwWtmRXFczZNXeOIUaY5gwNB9h/6/TfjG0tXhZD\nFNU5nVUkKmu7gRAOJEKOgnqQmsdfxUE0qq9a2kmKYuhJWwVoba++ibKPZGTm\neDlPmXMXWnJzUWg1kxNGMmdw9L08XbhhFJZpqP3RvAZL7dOmfRLIFTFy7olo\nvDrZ\r\n=O1BT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCyC4wdot+cLv9nGZ20RNBS9TRLXvkBRqYw/qyyyKLarwIgRckV1Zjc934B3tg3djMlrLIVTN0ZoiToXkwh/GxE/VE="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.8_1526567898750_0.9582408440258257"},"_hasShrinkwrap":false},"0.1.9":{"name":"serverless-iam-roles-per-function","private":false,"version":"0.1.9","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.3","@types/lodash":"^4.14.108","@types/mocha":"^5.2.0","@types/node":"^6.0.110","chai":"^4.1.2","coveralls":"^3.0.1","mocha":"^5.1.1","nyc":"^11.8.0","rimraf":"^2.6.2","serverless":"^1.27.2","source-map-support":"^0.5.6","standard-version":"^4.3.0","ts-node":"^6.0.3","tslint":"^5.10.0","typescript":"^2.8.3"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"e28d3810b18672a30818814aa2c290f9d3f558e2","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@0.1.9","_npmVersion":"6.0.1","_nodeVersion":"6.10.3","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-UFkcexhwniTkV/CU4pX36zH/wqbwZlAw5R9F4dLkX9BIOZJPdNno1TQf2FPVJv4NQ9d39IeDhLZe+VhjRb68SQ==","shasum":"0726e93c054079a86e41bafd1098096976628e3e","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-0.1.9.tgz","fileCount":11,"unpackedSize":58590,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbCTXOCRA9TVsSAnZWagAAnpcP/0/XXHxh2hJlXP6F4V5y\n2soelj3C5QgOeVwJb4cTJ3Gf/2iM7dlRnTT808NQFNWs3w1WUAW9NB+1lt14\n7u2w+RPz9+b0wwfIok5DiJqIyFFpcO4rN52QLqqoSUcEFgvANjOai+SRJuDh\n22IGuHT5YoCPzx+rej3285dqpNqSTijD24vyD/SNVlR+HtZXIN1h/Uxt7t+N\npEK6tlwxil61x8M7stc3rH11ErFAOZZE26ZA++f+KLV1euEQVPXuKnbmF0HH\niMP/SEyY222VlEQifPRDs8V1o1sd0qQxeX5BQfnNyeYASuzuqoxRzHs0Cgjc\nNrtpOJsisN8C23ca+wjb60+XUu98nk1HBoC/nfsC/Ev0GiZBlHu8SXKBOMfF\ngWMzwFQpNqqp++2QPFyvIU0CtkJ5crNPZVhQRXOMhNidqnjNaho1B66KePkb\nQ1+m2T+J7vnscz3nsU+F8bG+traEjzxksolgraqBVBfFAeAf9JpAdrG5heLV\ncw/gXvK4sZ/STfBWjuElDNh4d20UGy2IPWqa+93sCuVtrO1gfefyA1oN3d4s\nLRQ3EeBs1jGAexmXVBhVGk6UurlmSdTcY49f3z0Qe2zxV33bhJ04E9t4Bw2r\n/SJaGzpwdBNflrTCuA1llzBUyXO82skOxU/W7LHTU38DqToFao/5IgbYot3L\nxbSN\r\n=ok/W\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHYTzojInCPH3cK4FwYTYPU3B27200cUCGGjDC884RCeAiBZctUy4eVGajCTZMGS2r1yUSsulpnhg8G2RIwnwu1Q0A=="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_0.1.9_1527330253341_0.2645940454456215"},"_hasShrinkwrap":false},"1.0.0":{"name":"serverless-iam-roles-per-function","private":false,"version":"1.0.0","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.3","@types/lodash":"^4.14.109","@types/mocha":"^5.2.0","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.1","mocha":"^5.2.0","npm-get-version":"^0.1.0","nyc":"^11.8.0","rimraf":"^2.6.2","serverless":"^1.27.3","source-map-support":"^0.5.6","standard-version":"^4.4.0","ts-node":"^6.0.5","tslint":"^5.10.0","typescript":"^2.8.3"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"2d790e99c71489918ee3ebfe9521e6cf7b79d645","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@1.0.0","_npmVersion":"6.0.1","_nodeVersion":"8.10.0","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-9fxwYqF4UB3QrUzK0D26A/JNGVBrKBUszPTAQL0MT0rOxyrzRgR89xUqtm8SciJp1f0i/p2f+J3fp4ge5XYCSg==","shasum":"30ddeee7a5c5f4c5e45ed87ed3a232d91d2ecdcf","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-1.0.0.tgz","fileCount":11,"unpackedSize":56534,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbDY4gCRA9TVsSAnZWagAAIIAQAIq7nYgzgOeM8xKgg5/f\nzSOlp3YmAgU4X6ad808uWp1FXAAadlO7TFBeh1Zqyws8YKUSr+8P3kcCA6iG\nSZqEtKfmedqgus/BXw7lIcKo7yOacvBRpiRr98ZXX5k0C+2pIyaInqI03PDV\ngRBywQqKgKiJwpAOWkdUpyjdPOzpjtQGnPQlIFNafsFboTDlh4i76tcZ9uSC\nP7ALEYQtOSDcmcDBNIfZfpH2JWstaeNDsZ+bp596bcwkwlejQulAClUSyOOm\njPlskpf95Ex3oGJYm3wfnyoYpUx2wbjrzB1MSmkj5sO0nwMePLjwlFN0AXS/\nr9eiEQilOxz2LaufN6MmkO6+el0U6yP1SgyRwNZ+MXRHp+7byXyyY2EaMTPX\ny8yrrwa21bGRNbG12hVI+rlshB1N77mNjxxeQ9lZa69D63BVLM2G7LzmVDk3\nX8NH3PyhjSM84GW+8r5YVPasv1V65kBe1p7GWGYGPn9wh4tcpDhAX+VUNvnG\njBpt2SHI8dVMDXUwEPT4mk6yYJ7N0Qro9vHNxROSivjfRWjMpf3vGpCv9PAa\nfa9butbmCPQdSGXv24u82RKqSrYGE+g0RDprfn/6VWFS+ntkaqeQ+Ygu6eW0\nMAy42Dc2bhvf2fC8BwMryozl+lBZxNSnpA7L0qjk+tz0ejH0IhIKqv/f45UW\nYTai\r\n=Jue7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDEkkKH3oFDxVe1yMDV2TDU/LYMlKFqm1OAxW0Ma+maxwIgGKtf0YuqaoHW9xly8jALqTrE2AMOYaitqLBPTQWKKJs="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_1.0.0_1527615008057_0.44073752960019563"},"_hasShrinkwrap":false},"1.0.1":{"name":"serverless-iam-roles-per-function","private":false,"version":"1.0.1","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.3","@types/lodash":"^4.14.109","@types/mocha":"^5.2.0","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.1","mocha":"^5.2.0","npm-get-version":"^0.1.0","nyc":"^11.8.0","rimraf":"^2.6.2","serverless":"^1.27.3","source-map-support":"^0.5.6","standard-version":"^4.4.0","ts-node":"^6.0.5","tslint":"^5.10.0","typescript":"^2.8.3"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"a030e77b1b317f79327ee0e34852e8744e18032e","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@1.0.1","_npmVersion":"6.0.1","_nodeVersion":"8.10.0","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-UMbsQ7CG6T9u0EmJZ5sb43+Eue64MeyBonrfMGp/hUq4pmhoG5EwLH6yDY41dBtvrA7vhN5oL0lU28xbjFoh9A==","shasum":"a0e960bbdd553a25e31689b51b5d4261f664ead4","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-1.0.1.tgz","fileCount":11,"unpackedSize":56836,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbD8gXCRA9TVsSAnZWagAABHQP/RnUnm4OhlCQe377po+c\nvkWLqrpTlwnQDqiuEbRtdQKUftCHJaXIIOM/K0F06w4S4/DhJ2+nZblnuztM\nSB71KfY4rZRxeLWN3/Qlz2H3MFsK7NYeiyzBg5fWLNWNkemXBTmsW73+o7ro\nzJQoebudQuTdVchdNvuN/sswI0G0m8TV9teltc1t/Gt9+TpAq4RIHPXNu+ur\nbsltMjFlWBlkcWVAMvDikw9YJ0t9SwOnoigheUla4Kbft2Gl0vsU1vuQBH1e\npWfwPQRPBfcnAmxgsO+B0nm9MNl1QVAto41rzWpFvu698k/GaVtgRzMneuGa\nEbxy7JMQpifq5N3io8GTSnxwpKfzUHM8Sco2jCqcjVSeibpCxYrGXHUmsagK\nUNAkJzDHgVEyhXVq3EDFBj03wK6BpYRLdTb24wP6pElcDDoSBghVGBrMX9Zj\nejTcwzdkvoQLSVow/QCsnWLiVfN8uPfJcY/rNqpOphwbacVSA5KkvUgbGh7D\nudgi1LwOMH4Z2DVZbv5N4oXSsnhfOox/V6ydYRq+Lpg/d/6UmrXlfBwddLTo\nnuPoINX/wGc1Fgrr8kG0ifl6W2wJ6V931UuaIz7iQSxPjt1EPpcKe6AwEJST\nHGvC0C+h95UmokgxW9koFviMogKX34DSc5pfLnhFDcH2jYcsimRY2xjAJ4+7\nMQ/d\r\n=xraK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD49dSNXUpxPz6ALvk4sMuCtycrPMjW81r7jjBjPkrWAQIgM5KEXVXKj3uv0YQP7dKcpaMRd4Nvv9/DwxuSSReLMsY="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_1.0.1_1527760918727_0.7593467542447689"},"_hasShrinkwrap":false},"1.0.2":{"name":"serverless-iam-roles-per-function","private":false,"version":"1.0.2","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.4","@types/lodash":"^4.14.115","@types/mocha":"^5.2.5","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.2","mocha":"^5.2.0","npm-get-version":"^0.1.2","nyc":"^11.9.0","rimraf":"^2.6.2","serverless":"^1.29.1","source-map-support":"^0.5.6","standard-version":"^4.4.0","ts-node":"^6.2.0","tslint":"^5.11.0","typescript":"^2.9.2"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"d6a5e81e3c8c58b5058262953f1ed3f9a87808d7","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@1.0.2","_npmVersion":"6.0.1","_nodeVersion":"8.10.0","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-fO8d9vkNez7SJvsKwmAOe5vrWDG1bmHQi9OSoFdOHNprspcW61adJuTxW+rgNrMLQj8TPifJza+5K0FT1zfFJg==","shasum":"4199552efc6bd44568858ec2e3a662448e062d91","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-1.0.2.tgz","fileCount":11,"unpackedSize":57109,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbXL45CRA9TVsSAnZWagAApJ4P/RIm/xX1EfVhjFmTpfMV\nZm/OE4uIRB+cyXTCLYzYBPaOTyM7w/lLAhMDs5ASKKAi6ll9OJQeJSe93AI8\no+Wbsf3sT/cogapkWfskhzR7LjXhYJ22f0T9SlVdmxLpflx15ULRbS1tDth2\niGIdfUgjnn+xPMJVd84Xm+m/6FC3c0k0DIQKZJvOKiHGnZbHvv7BL6Rp0Jd5\naxyZxof1aWSR1Chs3H/nVbZp61i8YT0QghAs6UdGaIsuoD6DynG+oGlOU8xU\nSj2vTjn+ePQjFk823lza9ehQfwS/yoseVcVzni3r+r1kOS3IQTPlyPe9EGmU\nIK7iiQSdHhbaOrJNR3O6txVi6s1BVpfRJ11Y1nn5qGhN1MteA6l7wE59vlcJ\nJ+W4/Qbgvdbxue0N/wEfedX7gldLd97ea08US605hn5c6driWJDYbJ9vMlSD\n+PpfHUb0PK4uDBfxVXk3schhFGNZVp2AHy/vDM0DLSWBN0S3o7cja1FecXlc\nS3fBY2Bgoa2CrO5qFunDsGfvZuGLD3Pga8hkm/nMhV/5pHqON9/nsBu119Oh\nH3jMIaAPwcYsVooBVj06kh24BEtNvzX1Hfz6AhTb4qKaXSIRDwoaoarHOhj3\nUgv73HASTH2O8gDnWTOHSbtVRn0dZxSVImFw98AjGvh9ivOPLo9vC3qTIVVL\njZTj\r\n=DlDf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDiGhRhiqF/lhMF1XAhUwZwaJxgarybpesnr7NWIxA/gAIgUyVoCm/Ucx09CGKLdc6Jlqf3Hl65v0ktZ4OC8xOrfKk="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_1.0.2_1532804664897_0.7600652988270378"},"_hasShrinkwrap":false},"1.0.3":{"name":"serverless-iam-roles-per-function","private":false,"version":"1.0.3","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.4","@types/lodash":"^4.14.115","@types/mocha":"^5.2.5","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.2","mocha":"^5.2.0","npm-get-version":"^0.1.2","nyc":"^11.9.0","rimraf":"^2.6.2","serverless":"^1.30.1","source-map-support":"^0.5.9","standard-version":"^4.4.0","ts-node":"^6.2.0","tslint":"^5.11.0","typescript":"^2.9.2"},"files":["dist/index.*","dist/lib/**","src/","*.md"],"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"dd50ba7edf4edd70ddfa12a24738f34a30fb19bd","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@1.0.3","_npmVersion":"6.0.1","_nodeVersion":"8.10.0","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-CNgFiVqIZJFU+AugpIH/r1Ciz8+lAxzDf8Fy94luOisgXocL3t9LJ8FZZ4q39GJMGa+F9YlbtZntNMr2hUZw3A==","shasum":"73e23e483e342b6a46c5a06971a929bf634407b5","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-1.0.3.tgz","fileCount":11,"unpackedSize":60435,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbgsI3CRA9TVsSAnZWagAAj3QP/1WfscliiqGAq0cWQbII\n8e0H+FAylblCkNB7WWaxIU0RjzzI7DNYRbqN+6MJG0USDCnIt6449VXOh8Hl\nl87ZnPcjPbsXKi3wPN0BhHvvDLx4yOyaQ3nQOXFr0uefUR/gJSNDNX9SEGRG\nnHTHf4fPbGIYVBS82sEOfEk+M2UtFXy+cQIlo0JYz9n3p5+WcjfMLDgsZj71\nchjBJOVj5swZxWO8bdmZ9Ik/xZh2PQc0vU3yUkWjDbP15CusFbcY7XO1HsIa\n3fVuZZcrsBptrJzKeENEOHyYQYFaWK+3lPnqmdBoUb7/svkfCa87aqhaLh0j\nHn4/1zxv2v3Mp16as7fMt/g4Kd+aFng8amAS6DND0D6trMc47L6chZ5GNnex\noj/wC2A+owGnybzdJIKuuuJ5RHHdEFlIexQsz/4alybAQOUqvWaqv1kOZVsU\nz9tJnCiGPZMdOP5qe8yPyGPmmv+u4GM6m+YZa9hNxRfXI+2JjCZ6vocLtkNZ\ndKNA3rugfgAPBPC/nu9wexjtUERGcpUHvrekSnEOtIQrbLKvcUpQkiOVkKyG\nP5jDWp3Ax85m4UZINlHw8BcOozVp4mqa2+l+tJpRxF1/HkaQ6sChyeM7JvUT\nwBCl3bwgvUvAyIy5yYcHpPRLJT+3YHGwURnXPEtaGufleEWE+WdX/MfGNkT3\n3DPc\r\n=FZeV\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFESIpaj7roqDsSDRaGgBh4Ibv3vaa8eX8TDltlUKCYwAiA5/lmbQ+16RjS3iGridRCmDTMn8Jg0U4YG7xA34NQ17Q=="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_1.0.3_1535296054650_0.5211670168488918"},"_hasShrinkwrap":false},"1.0.4":{"name":"serverless-iam-roles-per-function","private":false,"version":"1.0.4","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.4","@types/lodash":"^4.14.116","@types/mocha":"^5.2.5","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.2","mocha":"^5.2.0","npm-get-version":"^1.0.2","nyc":"^13.0.1","rimraf":"^2.6.2","serverless":"^1.30.3","source-map-support":"^0.5.9","standard-version":"^4.4.0","ts-node":"^7.0.1","tslint":"^5.11.0","typescript":"^3.0.3"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"35b7ac43e8e7b54377933598913bb2c03be6c446","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@1.0.4","_npmVersion":"6.0.1","_nodeVersion":"8.10.0","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-hmOYeVZeWfE4r7NrTBdKpkmhPt/EhN9WZt6H3iDCOli+nHituvUlDZTkEK/qbCpp9Z7nNJYNaQW2K/3OkaLMXw==","shasum":"7a182c5e148bee4b67b64a96b4f09f7cf86fb0b4","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-1.0.4.tgz","fileCount":11,"unpackedSize":63222,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbi96QCRA9TVsSAnZWagAA6aAP/jQ972le1iNt1yZ8Lb/C\nqXxpc77pwY3+i/VHN7C2Kfx/w60E3hRjbv3KhUeG09kKB316DxsOy+7/1cft\nsqCLkjGKyILhddM1Kl0DACV4uKnJh7J3gpuvSELTrWWa9MpUZTol9JFnNP6u\nECMH81ICjX2k/x/nZyUHAh4rKkAbPuK1DrVWRVvSz4QcVo3d5q+hBxPr0tfK\n/IYCqPwum8aoVdCW+n1Cdl0x9ptOuW6Aw5G3Aw/MiFvyLkjBaLHFTrSUV91S\nsG91vSXloJWB9vBBlBOXuNQ97QxTW389qhDvixaTvmNOApcQoe5w5uLheBUr\nedKAIvvZGv2IffBP23sP3vZyAVIGuerRK6KFUgO8+6VoVatRuCq2ewN/GEMr\nyk49hb1NmISEyWAQf5yFi3rDM+1r5f/6V+hLA7hxtfZjr1zUkU36D46QujUK\nJDnmH+FVIJy+ZGc2ATFIgJCeig4im9mxs0PDOL0v5Gm1l0pTSRWq4Cn7LkwN\nbzYYTHvO84oXstcVyOQquCp1cheZwH95FHsX3p4m1u8hGaGmUlpRZGT7UOJt\ngs/7FQsd9RVgrx7YyBOMn3v7AolWdSB77myP2M436yQTuGmg4ZiI3heWGpT6\nXA9mVyFmYDTaJ6odYaYAIQ4gvRk70Sb65pNrq04yKbDMk2RHzRntHWgx7wRT\nPb3G\r\n=Db4u\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCZbXJaBKyg0wHGFFwEYbzyXr6eVCBrN6RS+4rTqruL9gIhAJWUwqn9ZRqAio7JJvMw8OL63TUdCbAhKT2ybNZYKvQB"}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_1.0.4_1535893135955_0.8397113390656097"},"_hasShrinkwrap":false},"2.0.0":{"name":"serverless-iam-roles-per-function","private":false,"version":"2.0.0","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.4","@types/lodash":"^4.14.116","@types/mocha":"^5.2.5","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.2","mocha":"^5.2.0","npm-get-version":"^1.0.2","nyc":"^13.0.1","rimraf":"^2.6.2","serverless":"^1.30.3","source-map-support":"^0.5.9","standard-version":"^4.4.0","ts-node":"^7.0.1","tslint":"^5.11.0","typescript":"^3.0.3"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"50ea78f9976af58921ff3d9a3f73f279b386727d","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@2.0.0","_npmVersion":"6.4.1","_nodeVersion":"10.13.0","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-I5daJcd0QbrHYibRnRiO+SuJyapNrWIKj2GaJP68SSz1BZg8QqxyEw1lBR86YSSSm0gJsjPH3T0xHSOcXv9Paw==","shasum":"62f83bdde866b0011818bc797465fe93e53e6acb","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-2.0.0.tgz","fileCount":11,"unpackedSize":68531,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcyM2GCRA9TVsSAnZWagAAzJYP/0xbWYignXkx1EzdWztg\n0O+TxVgwe3wg4v50sHczxMjORxFQ29fkUbTaCVqVWLvi01Nv73rUH4L90yI3\nyTJSAT9NTpcZeWtr2Cmn0s29E7qX4NLLH86F5z6mBcRKeD/9OT5DgF+m6EXs\nCgGkD0CCfkvZzzLXcI1LmCLPCxRvZDrIzK8iJmWo75Gvxlp3u9oDOUFFlAQC\n2DXCJKidN7dvMQuEHw8tGUB6FktfJRdjmjQ9LZiYrBf0wb5PhXP/xFPdfhkK\ng8JZye1Ld2mG/hCo+2BPZFY6oJXlfbCg1HTqtwjKUOOEvKe3jfbCklbLi8Gc\nba7g5ADUVqdKwt47Y9/PXNBXFza7lKZ7/PujGbiKcHzqGQeMi3cHBLpQ4X03\ngTgl1moii/uMgcEHcDhcjFTe61SxpDjKKBbjvDQTOxS/BfnAyg0APH3KtNr0\njdTNbxz2nQ5RMp8BSmL+xU5v1gibgaGusAAPlobPitOFF7m90gpItdLANLTG\nklJ/rTnd3B28dA/eVwQfXFoLpDv1LE64dee+M6urHzUxlQ5m4nap//AuKgll\nBZB6j/FScvNypX0sJ9tSvBl88rLV+tr5MSmiNHu9IO1QDUMZinWQvfqL0pP3\nLoE6iEZB9XtDfCc8BCC6VbokL+u8Gzd9gXttaipw6CVXjbvEN+sTqJGzOTbJ\n+A+6\r\n=TZjs\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDGax8ijNqdZ70qAWPTm0WnIYxARSgw+doA+uLptqruGAiEA3pn1DrfF4ryf9H5xqkX6qB+p9Vusw6fAsBkH4JDuZ3U="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_2.0.0_1556663686167_0.9740985606371284"},"_hasShrinkwrap":false},"2.0.1":{"name":"serverless-iam-roles-per-function","private":false,"version":"2.0.1","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.10"},"devDependencies":{"@types/chai":"^4.1.4","@types/lodash":"^4.14.116","@types/mocha":"^5.2.5","@types/node":"^6.0.111","chai":"^4.1.2","coveralls":"^3.0.2","mocha":"^5.2.0","npm-get-version":"^1.0.2","nyc":"^13.0.1","rimraf":"^2.6.2","serverless":"^1.30.3","source-map-support":"^0.5.9","standard-version":"^4.4.0","ts-node":"^7.0.1","tslint":"^5.11.0","typescript":"^3.0.3"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"3410edae5189001d76c71f12e5b32be237034674","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@2.0.1","_npmVersion":"6.0.1","_nodeVersion":"9.11.2","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-3t8BsC4CxsXfBtL80xaz5vcRiAe6x4tKfDByGtmMj8fr5q3AvH4PHlhnPPtSYVYgleY02K9Bfh8kf4UrkgshFQ==","shasum":"542ad4e3c1473785b7f66a5f692ddaebf4cc7f67","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-2.0.1.tgz","fileCount":11,"unpackedSize":69141,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc1Z4SCRA9TVsSAnZWagAA7u8P+gKAgVfg7ZYs1yMBdZJL\nm6OBsVgdzM+eGj63HRf+q/61Sj6dfz6lWEY41kwCSGTOHPPY92fFCzChDny6\nO8kK5FB9H+LMZ7MENwK33J36ckh4LU3r2NeYE43U0vnJNnJCHmXNDLWjiDpU\nECMhDde9L65AIGoRGN/J/Dpwqs3qEkM2QNRHjewG2wfGiHWUrRHn0oCxKxYr\nSSjmFvo0Co8lhNEtHuOpxyL7EmGEDyppCsESCDCDlh1GDApwcEoMx7M6IEt0\naDV2T+GS9ZixxXhqaXCjKEVwmP6vNNHx/9Q27gZLZNaT8a5TCfyWXs17nyeI\nFSwf5cU6ENPtkEurK92ID8KznP0q3NzsT6LNpfKLK/Tj4oPpCN1HMj9hgEmA\nMO651Sn6GKJrtlHxxtMonbMRzJOHzSE6eUTbiN8fr7IG1JZBdvDuy86y1/Yw\n1pXi4t6fnyl2g+TuKI8S7ytODxXNqCeHU+68+qfZ31i8X4sQtJdx/Ui2SEQQ\ntMiCtItqq77O8zoBVSThaBN8OHZNIKycNq91dvV1O9iJwsKMjkPnyENu6nAI\nkwSRAiu3hxFsvIxrgPVDoPdeo0dASX2CPvF+kvW5OI3P1ht+3AlJRKSBE/+U\n8Jr0WuAuH42LpXneSgRazhnGAc1D4IJn89+W0+tMrFBvdKQr6J8921S9jFH+\n2L3f\r\n=KIV4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDGXtFhVGHFVC8VJj+5GBXxScFBFqHMS/DjlPKRNouhxgIgJ2Jz9VncDhsu34pKj96HyDFdwUQYtZI4QSqfnf1gNfY="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_2.0.1_1557503505955_0.5650552876764692"},"_hasShrinkwrap":false},"2.0.2":{"name":"serverless-iam-roles-per-function","private":false,"version":"2.0.2","engines":{"node":">=6.10.0"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.15"},"devDependencies":{"@serverless/enterprise-plugin":"^1.3.10","@types/chai":"^4.2.0","@types/lodash":"^4.14.138","@types/mocha":"^5.2.7","@types/node":"^6.14.7","chai":"^4.2.0","coveralls":"^3.0.6","mocha":"^6.2.0","npm-get-version":"^1.0.2","nyc":"^14.1.1","rimraf":"^3.0.0","serverless":"^1.51.0","source-map-support":"^0.5.13","standard-version":"^7.0.0","ts-node":"^8.3.0","tslint":"^5.19.0","typescript":"^3.6.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"gitHead":"5bebde915ba1173a24df6f446022b2b6705bcde9","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@2.0.2","_npmVersion":"6.4.1","_nodeVersion":"10.15.3","_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"dist":{"integrity":"sha512-3zv4Af3x7KJHC4fuJMHniEEstCljMghReaYIg94Spdsqkhiy8GJ3yfJ5Jy+wiG/DvyObK91JJNMjLhDnDc+vCQ==","shasum":"c64eb2f34552e59d5fb8cb2169ebbd27734a6774","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-2.0.2.tgz","fileCount":11,"unpackedSize":70312,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdaYHxCRA9TVsSAnZWagAA5xsP/iGrPstFXuobekEezS1W\nxDNhsdgVt3e0MuzqYr/IZlXO3ZpzVnMzE9gEsAFK7o8S4Vm96ARxe1MJiv2V\nWTQnOjIBxg2HwcwuQElqy97we7FzjDtyjfnNaYzCem5VQvVlOum545TUyjFR\nkejRSwB1BQCEWWPDIkBUyO5K5UpIW6wYqbU07kBl3ssmHJIdcKqaW/3sprJN\n3BkhMqKHdBiCFa6Rq0BZTmYlDI5teLDMGyzgwEfaENoekK3GN8jamDj+H37y\nOzDc/DF+R59lQjZDm1AFUUj3+3pTJOKBLBkgAHOjK/eei+ZfpOM9mosJM/Mr\noDpaNPig8gB4Vfy5dXQ41pZM91qzh6h8WJDj+CUWrzxkTa3bNyXBbfDJyA9D\nCNSzOi8kjVDjXoRVv76fs8yKUZEVxnSqNrPPa8SkeqRBpUlrn7sIGNjNTqLN\nZogOSpw7cnw6ReP3ur3tpMyG40kCzUExqkRT8oZvmwkpu7Xjq5MHlIaDnTQ4\nBaoivBgitfk+rmkt5ZmEMXU/DfDnBvWRJdxK5zyctBJZcrh8fLvfJ3/K/yQL\n1PHHkPgMUaZb3Dds7T62vMUKi6HZ9wtJTxDfUBp8sbrsHnU5FC1AQN41Xm9U\nrWIICOztOSvGMr0n8XwI/xlpyCLuzte7MTx+2KDDigw5vTkM035jwUVdzIP2\nFT4b\r\n=DUJF\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC6H6G4/aw8FzVQIDPLjwoYNV50so1INbs4UUFyp1Y4cAIgcPcRE4Ewp8BYzzs0qwZhPpEZM9hTnVJOcBADchexGSk="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_2.0.2_1567195632715_0.4714152559047031"},"_hasShrinkwrap":false},"3.0.0-354af97":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.0-354af97","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.15"},"devDependencies":{"@serverless/enterprise-plugin":"^1.3.10","@types/chai":"^4.2.0","@types/lodash":"^4.14.138","@types/mocha":"^5.2.7","@types/node":"^6.14.7","chai":"^4.2.0","coveralls":"^3.0.6","mocha":"^6.2.0","npm-get-version":"^1.0.2","nyc":"^14.1.1","rimraf":"^3.0.0","serverless":"^1.51.0","source-map-support":"^0.5.13","standard-version":"^7.0.0","ts-node":"^8.3.0","tslint":"^5.19.0","typescript":"^3.6.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true}},"readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","gitHead":"354af97d99d60b96077a7b68b25c911e85686370","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.0-354af97","_nodeVersion":"12.18.3","_npmVersion":"6.14.6","dist":{"integrity":"sha512-emfqJCVv60YqJwzawbFHK5gg8Vy1WXohrzMoWi0znUROts3nzEiXlXY9VvG5+gb30Zb46218pMpG2JEyXs6sRQ==","shasum":"281029e7f2b035009da6f1ed549ff55063887e60","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.0-354af97.tgz","fileCount":11,"unpackedSize":75680,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfoEFsCRA9TVsSAnZWagAAJTEP/3lOfbF9EvMLgGkqadUR\nnrPO3aN70abpQ8785hiMLTXG5wDftSCXZY/gc5E+iR6Q0+wwxw9uHZ9gNlX1\nND7QakSDuA+KvKvsEWDZ2Jc9MIXMWL9SivLVxRIWYosS+iTfUlLE6PCieF5F\neqHyj7b2kBiWsXPt7vHAFvx5LM6+xDFYMWLbsMSkQpj1kqm8I8y3xk4Xk8qR\nP8WTxh72ssXBrPtDIRQIan8F8wpQv2nmacynsUKDhEMwNA/fsS3+q79Wh/wT\nKmpe/BpNhB9c1hmMB/1HRu3Rh4vTDEikufyXvsEA9qMcrL1utBSRXjXLI/fR\nxClFMU1osmo/lt1xVS39xHhvDo8fbJQXg8NNp80S8i/mPUjH7rVFKyrE9m6b\nBnaLbff2EdDxlfOttmLXkwiBVuKzP4Q1s3LEN/wDzzR3nWtqjQBgpNesvDLP\nKTUv3UK1akT6+yVgvv23s/NK4mVDu44vMLE4FkOXVV/VvbAHOnV+6yoGl9cs\nw02TxNihjhYUOQeNDzqe71EnXasu64ekcpvQEV3EqiLjmCnr3udth5SDCvbO\nfONLiZGI1yRUv8dRyeQ0oWqBpXmLGxw4OdJtcsyZq27Zk/O+Cjfe3gKh9mA8\nY3zvtnoDMFojWRVVS3hvGEJkMlyds8Wd2K4q58RgwAKXNUnl1NRVi+uNp9py\nuOV1\r\n=2JMx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC/0cwtiVvzP2HowWq9wJgC/DXgbvhDrKPtf5k/gacTBgIhANcZoWr8igyb2sYG+h5O4eCKiP44BuKxNhdwUGIuhve9"}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.0-354af97_1604338027978_0.725935197619932"},"_hasShrinkwrap":false},"3.0.0-d84bffd":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.0-d84bffd","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version"},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.15"},"devDependencies":{"@serverless/enterprise-plugin":"^1.3.10","@types/chai":"^4.2.0","@types/lodash":"^4.14.138","@types/mocha":"^5.2.7","@types/node":"^6.14.7","chai":"^4.2.0","coveralls":"^3.0.6","mocha":"^6.2.0","npm-get-version":"^1.0.2","nyc":"^14.1.1","rimraf":"^3.0.0","serverless":"^1.51.0","source-map-support":"^0.5.13","standard-version":"^8.0.1","ts-node":"^8.3.0","tslint":"^5.19.0","typescript":"^3.6.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true}},"readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","gitHead":"d84bffd625c57e9615f8a1299e7c228770b36f25","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.0-d84bffd","_nodeVersion":"12.18.3","_npmVersion":"6.14.6","dist":{"integrity":"sha512-AkGjb1ycFKJnBU/WvExCHCYhqVerFH9yuONvKhnEkW54ca13qX3QLB3Y074faKSihzz9iQL4NFlnwHYatrtV9A==","shasum":"1c2b6bb7f031953c113f089cce18980359471f1d","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.0-d84bffd.tgz","fileCount":11,"unpackedSize":75806,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfoEPCCRA9TVsSAnZWagAAhFYP/RrBYTnCiwPL3CbAjSZ7\nb8ctoF3fiuaNPLF+ndg9pMT0GTFOzsuD75invNQgMScAEMU9fGw4ElR/vIck\nsFswDpadpMye0yy93LejSjIgiqYxn5IXGUkbvlMhT/0CG+jAvVmReptsj7FN\n9cr/wG1HynWOgHEiVJvxGMH67jojN4COZEpZVUXtaBkeCgmF8dx1NsyoSI+9\nUitsY1uQFkYxdhpumTy3BM2VzCqD0l1K+qJOEhT+l3Rhpm11Ydpwe4m8QMvu\nSpHcg4truRGoIvvOUYHH6aVF9Ic2LgUKpUC5J8aa79b6GdPDet5PoXmvve7V\nsPdcX1ne3515W5r6pT75vqHlw3agApXJhop4gVNe/9ROkM1NxKNohnNexr5q\nQQzfNPT0hr9z/IGR2PB2xqREtCkRdcto0MgO7jLuh/FuoYnDfseXOs5tHf2X\nRVyajkhwvvNuHdNn/yeu2gamvUTcLYfv3bECzK6AIlPl5iSTHJ6gb/C8O7AO\nSdWiUQMmDggixOmyKqYUa+ngx8Aid0S2u0EmPV9ZXYD/U3HzdJl14P4IDuYL\nWfOtbcfGp/uGV/sA1iaK7v+C4vTKGWDwQRbMRlUtTeayOU7+ewUF4F1bnnDc\nn8m882r0lgsRCnrcZCU71bcBcWqdHi512rkxLpkWQtNxiIU2/c6bWT34l552\nWsrF\r\n=5bl+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCrpiOkKnSMkUpH4o3He57FYzYVxZaMN4fa4FmhD7GVZwIgZml+ePJDW6AUUA8tGPc6v3j6A1q2jj5t2qxl1MwbhUg="}]},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.0-d84bffd_1604338625942_0.902494264528076"},"_hasShrinkwrap":false},"3.0.0-a5cedab":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.0-a5cedab","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true}},"gitHead":"a5cedabf359ee9c1965fc093682d691fbd49673a","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.0-a5cedab","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-ZeeKQ5LniplsOOQ1FFXYW5raSvYofSaotduIoN25nUyuJb9Qed9Qv5bDhZHVY3VGrNd3EFr6/eYgI8dpUP2x6Q==","shasum":"85547a819fab19d017961c834abf1089a901a88b","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.0-a5cedab.tgz","fileCount":11,"unpackedSize":82121,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfwg/hCRA9TVsSAnZWagAA134P+wdseQjXYgSyNEtCWG8l\nG7Wck7Yom35BWoKan4rSQKf0fJ70IPxtRvoTTWgC7XLUfXbBpBA6fCwpCH8A\nKegDUyWp1BC0cb+kXrPDEQ5tr4Li0eSIo4wZ9dSsuI+nGx/GlVyYbGHVLCBG\n2QMtcfSL69WvU7DzYZXqltcLfO9VyXAApmQCL15FMb9pYyfQerBOhFRVlIK7\n3Ky/6UKwNVyfBcEEsCqJ+yuliZSWdYTf9DLrnub4iOJkeDls6bl0+Gk2hhGj\nJNeTjvZeiFpe0HpED2+plzza7sgefGGB/ZDPtiRMcUWn+I+fwXpJiF6KREgd\n8Lar0Yuw5CAs3kNGLVe9YTxuCktBLKEhIksfTYo4Qumi3Wcvfhlw4Wx5UPrv\niJCg+feJo/uicz724lSuwcEaR3n4ggrgdF4Q7wiP2D0HOUIgaX7mplvXG2WB\nRagQ9hC6s9i1ULCsDujTkD78S7BKgTCjJ8oHvfLOBmVauC5atAr5OxXkqyxF\nKpdCoD9fPnpgR5Nxt8sF1OySzDRwM/rlpSk7S1iV+GyTribrGFwxUMm3Wdcg\ndeMu46gagGnwR6luXwKKdpLCoYzjTWN17VCISeeeDqy2PMEWEEdj/ByYxaTY\nB0k0jVOg1Uuvoa2hMT79jBQMVxd09hUslpdxpQNI2HlC3qgrMFa/oAjiSMhs\ntWUy\r\n=sNvS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAEAlO9Fl5Aa0N2ZYA3DC8EEzdPdszFJB2XW9FytGGYzAiBQHoxsgEwts0wOIZqfj6jIx//6dZGORHAPilpaVZgl1A=="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.0-a5cedab_1606553569021_0.476146254792601"},"_hasShrinkwrap":false},"3.0.0-5593c96":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.0-5593c96","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true}},"gitHead":"5593c9618952945514426a8b8902cd8c2d177c5f","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.0-5593c96","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-R9n4urBB7djc4lBmhaBEpIhfN+jThLeX2+q3Fun8Mx/aG+lExyao3BTJL3c7rik8nWWkhDLw4LCcStUuedU9oA==","shasum":"5dc6333934fbf75ade3182663e6906325fedb920","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.0-5593c96.tgz","fileCount":11,"unpackedSize":82345,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfwmcvCRA9TVsSAnZWagAAc3UP/0h6P41o8303NdARgLh2\nXQUWr3fwcJ2sgK+4WYDBGlfeANTUjjNWY0cgVpbJARKR3o+F322uw9E264X8\nXyOC8F5zGRhLExOfQ6qs8bXQrMPz9gg61QYZTSeTAVbZByK/l5Oq2h8VrP5w\nMqqvS+Odu5kvbx9Q+xTUJ79jqVCTM/ATCHerDgWqBOJ4mNmeydaiYIhlp/0T\n7T7VVSCJQa2ZDYCl1+Cft3TAE93TA6TeyBmeUAruCItRMJ12a5JpE9cOCw4y\nWZLRGV7EvlFaXOatj5Z/zgvdspBklp+duIUu/LJq2RRSV9Ynim9iMgrElnC9\nV/sNCegBh70jbDL2cpZS1zFhwQPTZV2Nx1XZyiFjHkYPRo9Y9P7pfRI1nPzk\no16w0yd1LgIuQTt6bcHL1FxkuxqxYW6Uh/RbukumLwLG0vcbYWFOHtNfoLpf\n9x1tERcqtOb0Dvxc2Q2FB0jnoQkjHMvteq25TgzSqzhqYBCmaIDi/AtN5L5Q\n44JkiAC4OH7jDMU5wqwE1tPEOuT8G09U6DIdEdyqHgg19zK8/UZAgte0zM7j\nDaj9NmzrWpkzdRb+yx7gP4UigGL2yjVQpmdnuUU6owE5hVgn9HAF643ZrcFX\nfDEwrDq8u0+TalIcurnCkWZPOUKeldZabUakwYenc8nFDi7ewvoenp+6Xy2S\nFTn0\r\n=S25G\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICSYtneHzDPA6Sq7oL8Z22sHvjpaT6uQVUorzMwyZqmKAiEA4fTvMTqS8dNgEtKc+XIvwgScbgbpb+rljdd4/HxM8WU="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.0-5593c96_1606575918661_0.537508308155028"},"_hasShrinkwrap":false},"3.0.0-9c593c8":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.0-9c593c8","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true}},"gitHead":"9c593c8007f1db6408875aa1d37a4b7fc69621f5","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.0-9c593c8","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-wBkKCd9bBHqFp28zk8kCSeQTzo7aGElok1oMkYqi8ZwXxVwc6PGTdyiLwudCmN/DCh/kEbnERv7Pmq9H1Y9Lbw==","shasum":"2587fca9426f42bcb1bda415f267c3d1fc8ca260","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.0-9c593c8.tgz","fileCount":11,"unpackedSize":82345,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfwn42CRA9TVsSAnZWagAAXEwQAKJOjVYF6vhaxDG+GkHs\n/rlhvUqNulf8PVSviTtNeNcPLt4pAv661gNPROfF5QHdN4wwZGHQOoK+Z/KU\na1T9s5pvK+u4XZnMlWulGdZNZkdojQK3H29IZOJiIYoodfu6CmZMSHUWtlXa\nZRfI7IoduSB/LO8WSIAcKIBvqyXhDpbgBLU4s51ohFvtkbwjggSuCg4sc0CS\ngiZ8bDn7sjnq6s3D2ZBQN4MLQO+CtwgRIou9r5nkZGluRVmi5VR6hALwUkrH\nwit0vBhPyccYbT8Ph5XSLAU/3CpxEJtFTWA4fKf2ur/GZEq/0mUmurX5sFZj\n2pjOQ/Mkdhc7MmB6ToK4JPNxjDW6WfAMEnz+Jmq0dZZYmp/dJ0mnBd41tjB+\nSbVNPhHGBI1WbWSl7RS2Ys+Gi11C+uqudZSAwOF9XgL7wAU946Uv/P67K5Rq\nGyeDbNUT6C9E3SmwA//HvH+Td8k5L7JKgK72cIp190ayZOGk1Seb0iZaSr0g\nwgHNN4Iq+FRw8WFQNX6JEOc4VZIWY72NQ4PAWA/MZjruvw1i7UU8SzAImhha\nTniu0F6CJ9PDycGjkFsrpKBebqoBPJ0nbO9ZCI91P3SGoER287DQP4JlxiDa\nFUTJ634pdpLJoH4i9GL5/hrAX8gxAN3t+sFr0cgp7+ds+sLMNuWTtVJC2/df\nVTjH\r\n=nz2O\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEvor8rSfK7cXFmTKfrHxPzc/hSKoPjIMVd6Jls99HCbAiEA4Gwr6fLhZjrtJ+WUYuH0SyXZ4I/VpD3klzjR+Vf2uww="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.0-9c593c8_1606581814044_0.20328319449478993"},"_hasShrinkwrap":false},"3.0.1-21342a9":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.1-21342a9","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"21342a93a2dcf432a8806e46822050f5f3d72ebf","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.1-21342a9","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-MxgOsVVuMc/l9kFPi7zBS2LNR0yEkT3f+r2McjZbZafWL/SPAEObKTuswEIFGJ/2LR6vPPgXuvPIiiVNggOmdA==","shasum":"86f104d917a1fadf54c62e926d90a1da57b784fb","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.1-21342a9.tgz","fileCount":11,"unpackedSize":84108,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfwozlCRA9TVsSAnZWagAAZs8P/3HORvyKjsr4CFO//Mvb\nq7YntjFtqASku8rpSB22SQMpS3K7nyUMSEIYC1oHukvL66aMMrcQU+o4RM6o\nb0vTSezjZEYnLrYql0cuN4g2Pf1Rop3ySbB7CFExqJKMGsXXfQSVK7wjBMzd\n/aTMdlzKJKD1Z5kHI4FDKEqTin38cWseznyPx+JylDvuYwTWzTyGi/F4HhDw\nHeApb7zG2jlMUc70bryOXqbS2u90Mmk+UoLGkKx/locLhgX10RSioFSMYiqo\n+wmugKUSyYLMc4mijAJZ3usX+VUxoT6zTrG0CX/rZWmz4Kjm2w0IvFdiw4g8\nmrD15Pzp0E4A1G6srHlDeQx8d5PrScOGC10AsVee2I9QW3jjEh4Sx1Wzvizp\nk9yzfy6NX1ZdViOo0EDMLz0ho3dclgzA57c4hM70niQwK97OeBdUlYfxxPyX\nYso2SXZ+fdTZ3qRHqLQFrqQpAnfyuWAHWLrdUn2Kobfco/ZDnHMNnVST1m/M\nc30V1kkltiA3lvqnqyEjNxstUYpqqrcoPJ5CepTo8ybOQAyEDVCxB3MYPY4Q\nuOc4FaDLlP+7eCC1iv84vzg7GvaTC8okrWwbG9X2bfQDDzdIPNB4Mf83mzgE\nVs1Bc+OOLYD+MrztakD1GtRRx1MUCD5LdkoYAWUpRVQw3f23DvFwG7Lsa9E2\n7kLr\r\n=+kIo\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCmelwhW3FQN2+6EMAEq7daN/rockaexU37lN/TKKMONAIgO1L1brdabqSzBT/CwXEiGwbQMP8YpGYIGFreyDepYJo="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.1-21342a9_1606585572857_0.6979629220103805"},"_hasShrinkwrap":false},"3.0.1-1321494":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.1-1321494","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"13214946dae3214a54aab64ab20079ade559f395","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.1-1321494","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-QVnIwz4DUqkCcy5MukdkKyDHNvOlDBeanxGREPFYpNjViYPXl4GRzp1O+WPvN8hpY+tefEgyFfWk+OaZEVAkMA==","shasum":"b24501d7f04d1c7a7d262cd727225499e0abc52e","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.1-1321494.tgz","fileCount":11,"unpackedSize":84108,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfwqTBCRA9TVsSAnZWagAAGZQP/2rUPY8TY9iZ14K0jiDN\nqyYgBily/vhOVv418Q2RLdrfCYDl6vBkB/kFR/NwgkR+eo8kmvpnV1/xlx5c\n2lh38GGqXoqPhgHD22PffLKBxPY5UFSx+1LYTE7yJDOLdQj3XZqWhlq5dkXV\nL6O7PP7MQY75nA5l1DjtHeRwaf65/gfsgcgVDc7gPe3ehx+zqib0Ew+rg/WY\nAoHiPvEFSgaRW2NLV1E/+KjsroSdS5xYnMmiT5j+lEpGbonA9QXCdTaCj0of\nkgxMHyS8o/PZHKaNSy2pwfrrvihEeFtBemCU4EsFQYN19e8YEmlquJwwDlC8\nfdhy/V2V2ovaDY5GydHp9h8b7WQJ4hNv4b9zLAa/JUJxT9KAhynG1LsHpuSI\n39GbHlupobHsrN+upnSm9N3VU/aT6Lpw8w91unEA0nwHliNhNMKCWUneeQa5\nrGKB5ewWg+eWPlXk0aoAi34CGf1xcWsOUOeLyAX9W9VcVG1rjvqiM+TyFZX6\n+j1n47usOzFNoL0yMvdJd9c+YOEehdyqOG7f1tric+XhSXiQDRNUMLNR6aPh\nlGCFi8pXbUqoLewjgsEeV9QUajiPGvufwR8WDT/lVJAh34sf12v5R8VOyvUE\n/NABv9x7qi9xkGsicPnkMRMtzuw0hoRk1ArPSwSTPaCPCKnbyDkwG49zKHA0\nfHbJ\r\n=3OLF\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFBvGs9Q1Tw462ll4ETbkoKBe4VFY9/XY7wnTE0UWz4ZAiEA+QSk3s4QOR5qtOUjL04mcMhHj/8F+QW7VZ+O4b5p6rE="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.1-1321494_1606591680622_0.9052602833863863"},"_hasShrinkwrap":false},"3.0.1-6e7bcb2":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.1-6e7bcb2","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"6e7bcb214f6368a92e4e66091926e9e662feaa9f","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.1-6e7bcb2","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-C5WB6J7VBSDRTSrDiuYhaVRXBZX9DQXhowENZ8yP7d2qD6S1qjS70zv/mO/3Rcx1aPBZVcySWr4+7qjezoV7Qw==","shasum":"0069ac96f3720650bb2e00eab1f926bf2bcefa26","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.1-6e7bcb2.tgz","fileCount":11,"unpackedSize":84108,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfwsJ9CRA9TVsSAnZWagAAb5cP/2yNm6axcsxR+TmSDB3n\nDVfz2Dc3G+siBQr+3UIYZ/8gpt6C/AF6dqzMxKFIRpRrdQ40SUKeiFPqKqmA\nbWKvWTfh6rvwyhTFh/yAAJXDR7kBidzZBaf+ehLOA4wIsNU/IYkcuLcHjyXt\nzEIewn6dn8afPjyoFVDZRnpwAZ3sdRrBcy73hjB4iFW6if0kkuzfuhh1/LxC\nqYTE73ObBBiGacuyw0t+DZGIAxRU69lIL4/J4V0eYvgD5UOO7HkuyvtrvVXV\nMp2jdb2qX0R7ImhCVGabEP/hgqfkvPSlx0/WeMoOrKLB9z6bXYNd8wKP9Zpm\nAU/BKtYq2x0KpAPXS3HuZBHL2kcHEAeUYEz8jZzR6CxLQIwdsnIEzmsZ/DO+\neebwnFW3l06H1GZmMe5LRZDyEqj+2SefnAkIV2jYfrp4LTCFYg3vIu3VVCGA\njQDSg6J9yJJs56qoP674v3x8zoz+hPz/V22T6AfG1Kn01bu3vkujdfo9F9nR\nkxzz959x1VSi2PWx1YFarWHzsl0YuKqzt02p4DtyewVqgXjQuY8/37zJRtKr\nm2GCKtl4T3WlitTHwMqwI2gjqwigeyTS/afstKPL8iQMD/eeJL4beLx1lBx5\nk3J8r4RJOo8jElFfMCqvmylR7rs7bZ8e4UIiUDpcNJTZV5xVTMiYudix+/0T\nsPfc\r\n=P0AI\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICwDF2Z0XQLHPJSUVbYQuyHyzci1hLaHyXlDGNi8KP6NAiArwjyCj7tjakVl/y/MCtpz5ZesajcOusalAvDDdYeVxQ=="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.1-6e7bcb2_1606599293440_0.06496279008671513"},"_hasShrinkwrap":false},"3.0.1-b5e1837":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.1-b5e1837","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"b5e1837e2655ea1dc69b3c088e8d6ec8e5c5e74b","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.1-b5e1837","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-DU77x22NXlnHcH3zKBWni3xjzNqQ/9V7pTU3KnDGdLHEU2XuaOpTrugprd3hgEmAMnVvsFF55GTv4BPMSGKIHw==","shasum":"efe7769f4161a1a2a8bb84791da59d569e9e22a1","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.1-b5e1837.tgz","fileCount":11,"unpackedSize":84166,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfyNPbCRA9TVsSAnZWagAAtl8QAJpDR5UGQe9ZTgic9mXZ\nvKOpcyqfHQ6sQf+qSsV4v9IIyFUpcgcblAyb2rIanqfYHYDVrmxNMscrxAoi\nTTDGzJHh4QYh7BUaMdqvCwjWKBG0sm9oy89Lqupiv7wlF6jfrqx83zdmcnyT\nERGZ1J9IlxnrhVQ80bkWlhXFpr9RJ+221EcFsZaIXnmHz15JWgEGcctobICz\njsMQ8viZQB/yy2dZCgE+tDXmHk6EEYgz3g5WKlmXFS6aIMbBjjSk7v9FGfla\nQOIU/PGJ8wuzsX4NWMmr8dOkd/3sZs+YL1+buZ/7CrfRybeFb7GmS4cR5vD/\nuShMyVpXU3FlvJNY0t7yt3cI8TgeRF+2caST552BtBT/Yrpy1AmS+20kESv4\nDPajaFVv0Po9VQDvrzzCDFLpu0Dto54XcEcp2Dk27afuO3DHTN+jsK/vP1rj\n5EXup1EVMoba92KwpbGLg+2WvO9u3du/ceRwX1PDcMNkrm9Ygzi1500zqJ1P\nAwGNZvS8jRovlhSEN5QuxfYd13esBDy1GEopIrzF9bNoONFZ0g2Hv7s7gIPf\nd3nYfVPd1qr/48qW43j9B9vlfXIPHkof68RsycQdZmYterBjqfQ5vGHJz0Kq\nRl81pR2sSH8jvWsT43PM7tS2gKCeAUnNat2K2QohrcmBU2V5UeX+NA7mMNA2\nobsg\r\n=D4Tg\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHH40irhOkAnVR15VeA0mDX6wPStz52j28dIyMsaQ7uIAiEAmMn45mUA5dLbblyzH2cmhv6coCUIOLl6mzj6sMVGjmo="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.1-b5e1837_1606996954949_0.30538061343369804"},"_hasShrinkwrap":false},"3.0.1":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.1","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"6e7bcb214f6368a92e4e66091926e9e662feaa9f","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.1","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-XHsmzjYdflL6Pv1HY0Olpn00LpFqCaEGeNSv+wBx/2+p/yEDzSCuFAqmPY43OyyXZlqeyQfFNZJc/2OAfTwvYA==","shasum":"6876864e713ea5d28ef734d767ec3fa5b10c98c3","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.1.tgz","fileCount":11,"unpackedSize":84101,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfynnfCRA9TVsSAnZWagAAtFMP/3y7KRhruam1LflFLde0\neqnQlhDkJvB2LAP6Squ+xPj2BfJW7lOnXopKp7qfhrG/mcYRnyAIWtzUGvLk\nO1EcfsARhyYXWTE6uwKcvFJanv/wjIfz6+yUeK2S6ywn+CZao/mtzwSr6Hiu\nzADwknVSfVzl5ujQwcTsNN18ckojEbzkKlCqFrASyIr5h/L6ys+EacCZdGIF\nTzItlMm2b20aeZYvXqt+qoD1wuiov8n/XPriueC1Cr/TKUKCf1HoTW2Jom+O\nEns64OAVOGENvnQ3JdinApxioFEO1CjkDzRUCoBZ3HrvJBRVrBClnKSAOyVI\n3ScO2GFcuGZ+BYTiT8/UwFnHOORYmzyh9WTRzMm8diZodzrv+YlD0vD/iel0\nCRv4UOlniBMIbhnoaJL/oEIROaexfMaoiLuvluZr7v4Hgc2iV/TqYQtjz002\nfmFamybNkaQHnef/0LEao7CDM8K8ay5pmlYkQIu67uXxcOLIIZ555HEck0cn\n7L+PIHXq3MRJcI8siMMY649ybLVectCzmhecek3/o1zOPHi4EaxfDJrOXzX0\nnKchh/3rOOQ8Bv92BwETxgh26CJJA/SqeMgvbNKiXf1BDGbYIC5+r5L+qJOg\nkSR22lZHU9X+BLrMkFj3mZ3ldBnReylcVRgNWQUy6pv7Hu4cAfUA8PhtbOiE\n2xkl\r\n=xNFd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC0+4mbnSCdaWHI3j44hgxHKWlyCg6XATvccTBxjh0uTQIgcHmLNLju3q7fLpD7PuLSIXcK1D85X4sGcwG9S60wSJ0="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.1_1607104990748_0.3986925041714151"},"_hasShrinkwrap":false},"3.0.2-fb28ee6":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.2-fb28ee6","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"fb28ee6b4dc25f2a160b148b7f23bf5358e73aa4","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.org/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.2-fb28ee6","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-Mg/F5wUPcpTDuYmRfyN3ohs9pBreLYO3djUS0svbXHZhlaQ7f4NFpKqn21tZv7wIYxoSa2UvXmWo/8DUo+kyIA==","shasum":"1f4a18fef5d9efe1670a406c352eeee033ea9868","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.2-fb28ee6.tgz","fileCount":11,"unpackedSize":84528,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfyoyPCRA9TVsSAnZWagAA47cQAILCYT6ZYtEf7vUWoyKz\nPGm6x+WlFyJWzHdb6BqMrgtgW5p7dBIkkGiUTEPpyfC05LiqcNa7EoNsekwu\nm7h+0pCvkBjCoz1sv/anNNJIXFleHBPcGFWkyDAMPK7YHcFOPHpvJQs207xS\nsJ1Fe5ZmlHiPE83GZygq+9k04Q+8zRMPSvIoy8II59/OhQ1fvZgReE2MUvh7\nlBySNfSg1EvfojHVEqZi/IEKnZwKB5WDqliYb8D31XkgSv+MIH5ng1N8vH3l\nmelAR/NthrkRIS4u3apxkeA+qtvMVe4xhRF6z1goY+n61cGfm1+BtyW+2GQy\n1Kl/4/lYF2asdb6sAcl9vFEApEtKHIvfV+RV2v53w1D4hj6cJtaJ23XKWFdk\nreR3yJPWpci+XIuEAenrVDsO3sjGaID5o4rOy8wI88jZfakIoW0qMZ84qo3j\ntn3++iythxY+8FmC4YkkkXC5ELcPfFVgEv/Tv97DKhFr7aR04l0JTD1M+/OU\nAX6svzLN9WqHXKHWDZSNFxjykW+bn831Eu1z5+lmRG64T30ELECW3Stv41LQ\nWmoY1HI2PVrsE8xDZ9h8SxfCA2LFeC2s9+vJ9+L0/JP8+m8rngoxOSlzV8RW\nxF2GywgfehflgZasJqFkEOerQS4FOaUArzlmDAleTlwRfjobfZxn2oKq2I5r\n6zmi\r\n=FxzU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAvXcsyS3FuLRf7ottdXzpfYwcVo2VUtetrno3sr7psmAiEAz/s1p8fOHbmHAGwJHmfwu/zEC7ZGPJhiCn8aFr729q8="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.2-fb28ee6_1607109774928_0.982998437531833"},"_hasShrinkwrap":false},"3.0.2-223021":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.0.2-223021","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"0223021db107733d04a542ce4a5d5af4664101c9","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## Publishing a Production Release (Maintainers)\nOnce a contributed PR (or multiple PRs) have been merged into `master`, there is need to publish a production release, after we are sure that the release is stable. Maintainers with commit access to the repository can publish a release by merging into the `release` branch. Steps to follow:\n* Verify that the current deployed pre-release version under the `next` tag in npmjs is working properly. Usually, it is best to allow the `next` version to gain traction a week or two before releasing. Also, if the version solves a specific reported issue, ask the community on the issue to test out the `next` version.\n* Make sure the version being used in master hasn't been released. This can happen if a PR was merged without bumping the version by running `npm run release`. If the version needs to be advanced, open a PR to advance the version as specified [here](#contributing).\n* Open a PR to merge into the `release` branch. Use as a base the `release` branch and compare the `tag` version to `release`. For example:\n![Example PR](https://user-images.githubusercontent.com/1395797/101236848-1866e180-36dd-11eb-9281-6c726d15e4f1.png)\n\n* Once approved by another maintainer, merge the PR.\n* Make sure to check after the Travis CI build completes that the release has been published to the `latest` tag on [nmpjs](https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions). \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.0.2-223021","_nodeVersion":"14.15.1","_npmVersion":"6.14.9","dist":{"integrity":"sha512-DMSYvrP636leiJUZr+Hsv6z4xkof5+0aL/ljTSFgZvtY0Nxfyq8UzKRTZBR4IL8hYy6UHDY0wnjvOUWwLLw0aw==","shasum":"0c2c29abc4fa6fa2d19212b881b106451ad26438","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.0.2-223021.tgz","fileCount":11,"unpackedSize":85976,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfy+EACRA9TVsSAnZWagAA88kP/RpnDbCM9lWgqb8G5ORE\n28gtjdsBZ6WZ3XT/0UZKKb0tZXvbYQ110ScZpAWgXx6MelEoVe9HS9H/n/ti\n3hZbPIR8C7KUWd1t7LwN36GGzKCz67N5lH17BhS9+JD83yjo1gtWtKnwmt2c\nO1n4WZoPv3oCdFXT+ZmF1f9pVL9W18yS4VSGdM4zPUgOZzWq7Qy4G6XBCYAz\nOF19b5r9ANcUzULGBR+yaPMSOSVu/xyHum6JaU8C24os7g3gboX2d2j05JsJ\nqeo0VtzWiCacKsHig+MeRT2JSzhhmQOiwu/gHkfYlpCNRWeP/kcTcxjkN4va\nK6g7UjYJQgw7fl0hAQqIsV4X+tKMfqIllYzTzly1fjXSSjOw9lv8NXkExnSw\nSBM0GhYp9uqF2GD6mYbRDGygAjC3lLikGoCshPwopPLTIjsb9fPuz4/SOUVz\nDn0L0B52toGSKGsLiNU/mjLGxQO5w00kbNbrSPgvD0JLWOt26t1a7DTVE0Zc\n2nPLoHmn+3Qi6etM2O1up0P4SskXC6uGhwW88jPJVGFczICpWlGzV/dK0Nxi\n6OT58dsmqc0iYJdffLY1fCD2UtaIUCHU8SOHgqageRoIzVC3VjAVLhALmdyH\nPPaNmjS3Bn2A8Ws0Yt5HDH129LmoldrIEjJbJgUtItIqmKLLxYF07JP14AQM\nF8Ax\r\n=VJnW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDNOy1gW7eO/3ClpyfR8PGStD4PsvA/WjBFTG2UEWFfmAiEAsss6VFGBy9eUXV8R4kqjjO3FdTTg+Ko1bYj4ZIVDJEs="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.0.2-223021_1607196927638_0.4207685499081495"},"_hasShrinkwrap":false},"3.1.0-d68046e":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.1.0-d68046e","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"d68046ee4bf773bbbbe852d9ae3053cf96818640","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## Permissions boundaries\n\nDefine iamPermissionsBoundary definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamPermissionsBoundary: arn:aws:iam::xxxxx:policy/your_permissions_boundary_policy\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - sqs:*        \n        Resource: \"*\"\n    ...\n```\n\nYou can set permissionsBoundary for all roles with iamGlobalPermissionsBoundary in custom:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    iamGlobalPermissionsBoundary: arn:aws:iam::xxxx:policy/permissions-boundary-policy\n```\n\nFor more information, see [Permissions Boundaries](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html).\n\n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## Publishing a Production Release (Maintainers)\nOnce a contributed PR (or multiple PRs) have been merged into `master`, there is need to publish a production release, after we are sure that the release is stable. Maintainers with commit access to the repository can publish a release by merging into the `release` branch. Steps to follow:\n* Verify that the current deployed pre-release version under the `next` tag in npmjs is working properly. Usually, it is best to allow the `next` version to gain traction a week or two before releasing. Also, if the version solves a specific reported issue, ask the community on the issue to test out the `next` version.\n* Make sure the version being used in master hasn't been released. This can happen if a PR was merged without bumping the version by running `npm run release`. If the version needs to be advanced, open a PR to advance the version as specified [here](#contributing).\n* Open a PR to merge into the `release` branch. Use as a base the `release` branch and compare the `tag` version to `release`. For example:\n![Example PR](https://user-images.githubusercontent.com/1395797/101236848-1866e180-36dd-11eb-9281-6c726d15e4f1.png)\n\n* Once approved by another maintainer, merge the PR.\n* Make sure to check after the Travis CI build completes that the release has been published to the `latest` tag on [nmpjs](https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions). \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.1.0-d68046e","_nodeVersion":"14.15.3","_npmVersion":"6.14.10","dist":{"integrity":"sha512-xsrDZF1zhsKbMWhswbi3ltIxCvMbvnuQxfxDzbRpoetM9yoxFPPyVm18wrRkhcLmqwK/7MN9VuJd8gJaaMfR7Q==","shasum":"17edef87773c2dc2be347ed25b2873451a2408db","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.1.0-d68046e.tgz","fileCount":11,"unpackedSize":90609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf57baCRA9TVsSAnZWagAAPjAP/0EmPqtrXi/DtHv8S+qB\nqmC04RaiZhTWqOqP9NNBiNmH7y5nAuiZX9OCDcJk7GU0W/ip1nArfqQ5/FAo\nTPLFhQjpuzd9LK1S0/fDvuPv0Veg/+Xzi9flaJ0kqt7gHSaZDeBED58zXyEf\ngJyvUCX03PWI6acLPh5iXcF3Vjnj1I7Wv4Llm8nE97gBpWW1yE47tnVd8EpG\nRmGcSH/bi4CcJbRr856GGZtAFyh/BUFyq8OU7/jl1sxwEsIyS17tG2BChK3G\n8FGhgJdGGngFbrGHvaXOoZXp5wWD0uvJi9PIGY27RnIqsfCJUpADVkgN2xkl\nyg1rgYkLp5DzZ0hiHRxbm7HoUGXWNjisnu4cOzZAENB1muNj44AyEytwQM1+\nww5nbJJFoTUB6hqilsquhZlYbl5MXFkWjEn4uI1dMKNzkF5NJhqck65PLxAA\nUscrKkFymyh1RfjM9oMU7+CHxyg/sGDaAm9jWSoiNvkfWkK5oAw9qwNZ/tMK\nATOYaYLFuDa1fJ1ok9unDO2mXtmbVeB0BEsoH1DtgoHBb6I/R5JYVwUVa0Fq\nHWmID0j4TAKWqYfDDu3kvvOkeWzfdwAbrcN/+ZQ2KI8kzqW4+GnzSdydVLh9\nP3nd1IDV4R5+e3P9GddJE9mTrHSjNcqArE9/rZ5G989u7KoobEAkbfOCE1Sf\ngP57\r\n=yGnS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDf3B0VnO2Vzkjb2XSgtQwtOnP9Ywe7BRyrp75iXe4OOAiEA2bjrdvVA5R/eEWLdrY5TaQMBaDi2gQ0pSP4SV66I0R8="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.1.0-d68046e_1609021146164_0.2892318868353616"},"_hasShrinkwrap":false},"3.1.0":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.1.0","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"d54cee99b7260aad463670162e4eecb03ebf59d8","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.1.0","_nodeVersion":"14.15.4","_npmVersion":"6.14.11","dist":{"integrity":"sha512-/kNfT169FOOrYtkN6WV3fU9Nt0E2pku/1Vio1My82iKnbUQ9Bx35PSOvdRS32e7mLVwbdwZ5ecMKG1lpsuQLoA==","shasum":"3bd87011234641f4e4883b1a8aeecb8610ac71c5","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.1.0.tgz","fileCount":11,"unpackedSize":90602,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgAzDICRA9TVsSAnZWagAATWMP/18R/fmE9NJO5FuLUv6N\nHcs2bCokTvd76KxDiLcgLmDmdyP82IlbeHEPiAQJJJ1WefARz/vGUTMzV41u\nQUB3olQhyNJV+6nbhSL76hU6oP/y0AgQOHQrybjgWTsI5vaT5MEs3r4VH1tA\nK1iByZjlzez+YdIo19x7nA6seWHgW6zudtXtZf8FzHjOjnYdrDaxjAnFw6q2\nejTFanicKy2jF5k/AdiLbrVa2Pv54U9iBWQ0Rc1ECHon1Rqy1EOJGBCjMQyP\nESgOMr5vqxZ2wMp78/ZWdyL2xre2b0tOyrn/DdMvx7gOzyDWj50uq36r010h\n+t2iqjAKFgkuPO1mNq4H95u3p8sakeWoAbBTqnSfkK5I9IpjxOZy3oMNoWlT\nhQ54m5zvrcHIJ4A4hte2xDLfG7exzSZOSE1paql7j+oLglP3GrQSuJiqByLS\nTC+Ecm/s2UwikGWK5eJd8xbVio0UzNBM7dLSnPXtsJCO1hwgE+szpbnyQ7rx\nK8xgUxfIsub66IWfiBx2epVExtYIr7SC2q2UYawv7ojUQvwfg128yMFm7YBH\nhOmVDSAwhq9hmYe7KbiiebCIcZcvHuqvyfolvSVhdpwX6RibrFtQ95dlhCCH\n0PqkDoDAZjdpMUuSm0xKnRH+Gb0exxkX/KK/16MkvftaCHn4Fgn/A1M7mvhF\nvRfN\r\n=98CE\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDh2SrBe2qiJZ56RdJnuWrqjdiWKrLGBxu/pjPQMK3jLAiEA/6KFp/YYt5P70bKTl1mgMiVjX+Figo/lMVll4T5XGag="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.1.0_1610821832258_0.1569030421892026"},"_hasShrinkwrap":false},"3.1.1-720dc0f":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.1.1-720dc0f","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"720dc0fa9f06eb7dd2feb7da968226ab503aa446","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## PermissionsBoundary\n\nDefine iamPermissionsBoundary definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamPermissionsBoundary: !Sub arn:aws:iam::xxxxx:policy/your_permissions_boundary_policy\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - sqs:*        \n        Resource: \"*\"\n    ...\n```\n\nYou can set permissionsBoundary for all roles with iamGlobalPermissionsBoundary in custom:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    iamGlobalPermissionsBoundary: !Sub arn:aws:iam::xxxx:policy/permissions-boundary-policy\n```\n\nFor more information, see [Permissions Boundaries](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html).\n\n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## Publishing a Production Release (Maintainers)\nOnce a contributed PR (or multiple PRs) have been merged into `master`, there is need to publish a production release, after we are sure that the release is stable. Maintainers with commit access to the repository can publish a release by merging into the `release` branch. Steps to follow:\n* Verify that the current deployed pre-release version under the `next` tag in npmjs is working properly. Usually, it is best to allow the `next` version to gain traction a week or two before releasing. Also, if the version solves a specific reported issue, ask the community on the issue to test out the `next` version.\n* Make sure the version being used in master hasn't been released. This can happen if a PR was merged without bumping the version by running `npm run release`. If the version needs to be advanced, open a PR to advance the version as specified [here](#contributing).\n* Open a PR to merge into the `release` branch. Use as a base the `release` branch and compare the `tag` version to `release`. For example:\n![Example PR](https://user-images.githubusercontent.com/1395797/101236848-1866e180-36dd-11eb-9281-6c726d15e4f1.png)\n\n* Once approved by another maintainer, merge the PR.\n* Make sure to check after the Travis CI build completes that the release has been published to the `latest` tag on [nmpjs](https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions). \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.1.1-720dc0f","_nodeVersion":"14.15.4","_npmVersion":"6.14.11","dist":{"integrity":"sha512-k4zjyGhTTTMeiXpQq2ZKxlCMlIhP48xRR8zkcGnDX89Z8yj2Gq1myXCUc8PzZ+Lk2nvaC95n03Nxeqmtq73u3g==","shasum":"ffbe8857d2dcff5d1e4e31d017b5b5a0a84962ae","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.1.1-720dc0f.tgz","fileCount":11,"unpackedSize":90772,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgA0bHCRA9TVsSAnZWagAAiPgP/21TEjSy2UI7ShgIFICO\nrdU4PPhDmFU4JfHhnHH5+5+uXyJDWiOj4iDNSEg5BV1OwjVgYeiTyWkqsQva\n3mZ+EdMtN8/0z/pc2GabVlT3QnAi8qMcJv59Yi07hVYJNT4yBnI6G4g05M/J\njvEjmeanYObxzQVkde6Od+7auEEhs0zr9E69ocuv1PewN2uCtl0NsjE9o4Be\nuDHoBjfbVbmB4C50Ao7M6u9VOPgpHxBnBhjABQ8LZ9OOH978fbHNMry8zQt8\ny268AQJJc1pTCwr32IzOkzLBujooaGi1KthxSUksnXj990RfPVtIn+KcKf14\nLLd4XRj0g+o+d3QtEQu3lVKmMwOX7ms4mbFdpNnwtWOlSEKaXUnUN+vSZXCC\nTJogaEKk0MsxH3kDfh+CYRlI0fn9vyLN9iaHwvSIor4sXM68MmO7xQCnupL6\nrYoCNKR54YqC9Ee0vjOvsAXy9pWgHmgkT13S59ghS17A4IqvvLVGGzWhsYjg\nil+FXmCGBOoWcx5OqPYlWn7SeO57TeP4RQySwONKFIcL+5kbY36SHPO87JV7\nr3UrYY6eAr0euodi/xjWnQgWR5Jd8Je1PO6mIjW1OyJSm2Rv67Vce4qNTi3B\nwa34lpQu9bEP6wvLkC1grMo66Bf6gwt3/HvUi5AzkDtCXTzazAJocCg8kgh7\nqNZA\r\n=OWTq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD7hBRMxGI4GRothl+SL5qvMZ4KP7qbOXJNUnp27HfQjAIgCPCLMqG0gV/hSuqAXJb4/ixAZMvFo6HYjjTdAceNszE="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.1.1-720dc0f_1610827462621_0.1706110781562038"},"_hasShrinkwrap":false},"3.2.0-e97ab49":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.2.0-e97ab49","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"e97ab499d2278cb9876ddee7810002356b1ba6f9","readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n**serverless >= v2.24.0**\n```yaml\nprovider:\n  name: aws\n  iam:\n    role:\n      statements:\n        - Effect: \"Allow\"\n          Action:\n            - xray:PutTelemetryRecords\n            - xray:PutTraceSegments\n          Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\n\n**serverless < v2.24.0**\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\n\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## PermissionsBoundary\n\nDefine iamPermissionsBoundary definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamPermissionsBoundary: !Sub arn:aws:iam::xxxxx:policy/your_permissions_boundary_policy\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - sqs:*        \n        Resource: \"*\"\n    ...\n```\n\nYou can set permissionsBoundary for all roles with iamGlobalPermissionsBoundary in custom:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    iamGlobalPermissionsBoundary: !Sub arn:aws:iam::xxxx:policy/permissions-boundary-policy\n```\n\nFor more information, see [Permissions Boundaries](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html).\n\n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## Publishing a Production Release (Maintainers)\nOnce a contributed PR (or multiple PRs) have been merged into `master`, there is need to publish a production release, after we are sure that the release is stable. Maintainers with commit access to the repository can publish a release by merging into the `release` branch. Steps to follow:\n* Verify that the current deployed pre-release version under the `next` tag in npmjs is working properly. Usually, it is best to allow the `next` version to gain traction a week or two before releasing. Also, if the version solves a specific reported issue, ask the community on the issue to test out the `next` version.\n* Make sure the version being used in master hasn't been released. This can happen if a PR was merged without bumping the version by running `npm run release`. If the version needs to be advanced, open a PR to advance the version as specified [here](#contributing).\n* Open a PR to merge into the `release` branch. Use as a base the `release` branch and compare the `tag` version to `release`. For example:\n![Example PR](https://user-images.githubusercontent.com/1395797/101236848-1866e180-36dd-11eb-9281-6c726d15e4f1.png)\n\n* Once approved by another maintainer, merge the PR.\n* Make sure to check after the Travis CI build completes that the release has been published to the `latest` tag on [nmpjs](https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions). \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.2.0-e97ab49","_nodeVersion":"14.16.0","_npmVersion":"6.14.11","dist":{"integrity":"sha512-D4mFiqJxNb+IRep2wMm2uz8sSjdC61/t5VNqjOAVe1WYos2PnBS3+ttAQwUqAeQ7GGPNLajDMmaOPR18J8yCMg==","shasum":"4174acd48785e7ce91cad128d8433e995ebefa56","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.2.0-e97ab49.tgz","fileCount":11,"unpackedSize":97751,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgWKtRCRA9TVsSAnZWagAA2/gQAKMlCjzJbduDLx9zYaTO\nFnoILwxUUBe76OpUkqZozsurcyyfjG39fYawxRw4JZuevWERceC30BagIwkE\nymKoqau87Fato5gldhHA28TvQwW55/MLDULQXdh10LHbnh4RjZ3YZpzkKaiz\ny4qdQekOV9gLdFx+jB+thIm0lrYWVcXnWslFNXmft8oTXOky8Ym45B4/1uaF\n/EREszml9Gg8MSDYpcGjVOjtm34DncvbTfe+S89OVKZdldPFPTczFBWSZo/N\n5brD+470ruUU8Ewcb2Sw500I2SZ9nqTP4hXMdG9kUWEpr46SYRZeCI6uVrYp\n1IJUFplAmVJoTWTdUVcll1fzJeCEtjeol6XsYCM+UPJ5l94mVm1HzfSKv8cF\nHnc2z/T7HXyNkQnbPtoH+xx2/F8cOGM+ManAM9QoUlY3rkMARNoOLaNeqglM\nGPhdX9OuLLPmJruQ6wz2eVNojnH3yFz4tSoiyLQUbgdXDmhYmpqZo5LRo/EW\nL/C6+tcsAt7fBp56bYd9j6NJTQJmpg12pVUVXJxZ0UoUm7tHBGE8/qNALS7v\nIVxpoGet0wsV0eS3AeC1zDKsFBSpX33+HoKds5cyP+wI+mrAz6pbWLii9dtG\n9Y+WafdoEM6C+SpO8z10OLFZBXW2kfo6oxmeIan6eF626qjn8pDqGLzVnVOf\nVPDc\r\n=wwMw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBw6gEhj67oXFCgyvzE3ra5hGmJDeE6y/QjaaFAc5ssIAiB+UslHP928o7uYZgox6vgGxHoqc9acgCc86Ir8d73gMg=="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.2.0-e97ab49_1616423760522_0.8705529388753543"},"_hasShrinkwrap":false},"3.2.0":{"name":"serverless-iam-roles-per-function","private":false,"version":"3.2.0","engines":{"node":">=10"},"description":"A Serverless plugin to define IAM Role statements as part of the function definition block","main":"dist/lib/index.js","scripts":{"clean":"rimraf dist","test-bare":"npm run compile && mocha ./dist/test/**/*.test.js","test":"nyc mocha --require ts-node/register --require source-map-support/register  ./src/test/**/*.test.ts","coverage":"nyc report --reporter=text-lcov | coveralls","compile":"tsc","watch":"tsc -w","prepublishOnly":"npm run clean && npm run compile","release":"standard-version","lint":"eslint ."},"author":{"name":"Functional One, Ltd."},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"dependencies":{"lodash":"^4.17.20"},"devDependencies":{"@serverless/enterprise-plugin":"^4.1.2","@types/chai":"^4.2.14","@types/lodash":"^4.14.165","@types/mocha":"^8.0.4","@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.2","@typescript-eslint/parser":"^4.8.2","chai":"^4.2.0","coveralls":"^3.1.0","eslint":"^7.14.0","eslint-plugin-import":"^2.22.1","mocha":"^8.2.1","npm-get-version":"^1.0.2","nyc":"^15.1.0","rimraf":"^3.0.2","serverless":"^2.12.0","source-map-support":"^0.5.19","standard-version":"^9.0.0","ts-node":"^9.0.0","typescript":"^4.1.2"},"nyc":{"extension":[".ts",".tsx"],"include":["src/lib/**"],"exclude":["**/*.d.ts"],"reporter":["html","text"],"all":true},"standard-version":{"skip":{"tag":true,"commit":true}},"gitHead":"d848cdc6eedb0de1a900e27c53af4b15c210ade9","bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","_id":"serverless-iam-roles-per-function@3.2.0","_nodeVersion":"14.17.0","_npmVersion":"6.14.13","dist":{"integrity":"sha512-AXmxACHEUsDcFDcv8QNwDgn2L0brRJ7pz/phD3lFB/wQ3TtPJkorC+J7PxgFQbaWIQk15EIlU83BtKXeQoPTAg==","shasum":"8bb5f68e73f391ac8ff9809b8e7726e5bafba4c4","tarball":"https://registry.npmjs.org/serverless-iam-roles-per-function/-/serverless-iam-roles-per-function-3.2.0.tgz","fileCount":11,"unpackedSize":97744,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgp04zCRA9TVsSAnZWagAAV4cP/RDjJr0YH2BS1T/aEXnZ\nUMBd0FhJgZ8c5QdWMyDzkIRq9DZLR5y8WLqcrW/j2SyA2HEnbA4ICfHEq7aP\nKSAuJ3vAvCbtVHqA3OrZkyp383oG4CmjxN84MTMhWkydXTAAdWlcwCykmKqf\n9v/zMAOID39XH4Q34Y5QEo2sGYRyomQfdCmZm6qU5vdGP1aibh5LCUZZXc6w\nYLn3WUDJHPd4tG9blQjubSmO4gZ6FWp8r2prUFCktekggCXkY0pMd8jRCQad\nK2oVLEbcZ0p94Lu9GljDS5BTxDdqI5GavCwl9wTpU+vMaGyYzto/aUIDNAIr\nubcpJe4xKH6nm5uHqIDDPoYpPD43+bfe+5AyTadhiFK5VvaxE3xFi5EBLIw+\nM6OkTjUBNhU2/cdaxpi5aJpkGZAMJaoJo/E8D1XnzLbhEtyf9pPltFECjwdB\n4LRuZ6HXeCYR8g5OkbyUz1jVehelyaZneFYfBz3XXHzha12K8OM8yJzrxLLU\nWkEe/mzhA+r0AynkA+bog/vPf7HkZKy5+S0Mkn8Hxs0aQYed6wfnuMD7usXu\nsY0Koehurptdq7mhBtryBS64HguddShrh4SUMtQFFvKFi75DFhhs/mHeJFAG\nIeI34EZ6lmigD80Q31uq/ViovuA1WPZDNsgeCUp2mSvtf3B42M/CNooOLfyg\n87dq\r\n=uh4c\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDVVitInBFHwZKpZGVkFDmVZ2T7qkvVRlnKd7zPLgDrkgIgNtg0v+ikfNTB1x3C7TBCT5nNu9wU54NLQlMoGUy1muc="}]},"_npmUser":{"name":"glicht","email":"guy@guylichtman.com"},"directories":{},"maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-iam-roles-per-function_3.2.0_1621577267425_0.444791900962755"},"_hasShrinkwrap":false}},"readme":"# Serverless IAM Roles Per Function Plugin\n\n[![serverless][sls-image]][sls-url] \n[![npm package][npm-image]][npm-url] \n[![Build Status][travis-image]][travis-url] \n[![Coverage Status][coveralls-image]][coveralls-url] \n[![Dependencies Status][david-image]][david-url]\n[![Downloads][downloads-image]][npm-url] \n\nA Serverless plugin to easily define IAM roles per function via the use of `iamRoleStatements` at the function definition block. \n\n## Installation\n```\nnpm install --save-dev serverless-iam-roles-per-function\n```\n\nOr if you want to try out the `next` upcoming version:\n```\nnpm install --save-dev serverless-iam-roles-per-function@next\n```\n\nAdd the plugin to serverless.yml:\n\n```yaml\nplugins:\n  - serverless-iam-roles-per-function\n```\n\n**Note**: Node 6.10 or higher runtime required.\n\n## Usage\n\nDefine `iamRoleStatements` definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name #optional custom role name setting instead of the default generated one\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n  func2:\n    handler: handler.put    \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:PutItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```\n\nThe plugin will create a dedicated role for each function that has an `iamRoleStatements` definition. It will include the permissions for create and write to CloudWatch logs, stream events and if VPC is defined: `AWSLambdaVPCAccessExecutionRole` will be included (as is done when using `iamRoleStatements` at the provider level).\n\nif `iamRoleStatements` are not defined at the function level default behavior is maintained and the function will receive the global iam role. It is possible to define an empty `iamRoleStatements` for a function and then the function will receive a dedicated role with only the permissions needed for CloudWatch and (if needed) stream events and VPC. Example of defining a function with empty `iamRoleStatements` and configured VPC. The function will receive a custom role with CloudWatch logs permissions and the policy `AWSLambdaVPCAccessExecutionRole`:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get    \n    iamRoleStatements: []\n    vpc:\n      securityGroupIds:\n        - sg-xxxxxx\n      subnetIds:\n        - subnet-xxxx\n        - subnet-xxxxx\n```\n\nBy default, function level `iamRoleStatements` override the provider level definition. It is also possible to inherit the provider level definition by specifying the option `iamRoleStatementsInherit: true`:\n\n**serverless >= v2.24.0**\n```yaml\nprovider:\n  name: aws\n  iam:\n    role:\n      statements:\n        - Effect: \"Allow\"\n          Action:\n            - xray:PutTelemetryRecords\n            - xray:PutTraceSegments\n          Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\n\n**serverless < v2.24.0**\n```yaml\nprovider:\n  name: aws\n  iamRoleStatements:\n    - Effect: \"Allow\"\n      Action:\n        - xray:PutTelemetryRecords\n        - xray:PutTraceSegments\n      Resource: \"*\"\n  ...\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsInherit: true\n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n```\n\nThe generated role for `func1` will contain both the statements defined at the provider level and the ones defined at the function level.\n\nIf you wish to change the default behavior to `inherit` instead of `override` it is possible to specify the following custom configuration:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    defaultInherit: true\n```\n## Role Names\nThe plugin uses a naming convention for function roles which is similar to the naming convention used by the Serverless Framework. Function roles are named with the following convention:\n```\n<service-name>-<stage>-<function-name>-<region>-lambdaRole\n```\nAWS has a 64 character limit on role names. If the default naming exceeds 64 chars the plugin will remove the suffix: `-lambdaRole` to shorten the name. If it still exceeds 64 chars an error will be thrown containing a message of the form:\n```\nauto generated role name for function: ${functionName} is too long (over 64 chars).\nTry setting a custom role name using the property: iamRoleStatementsName.\n``` \nIn this case you should set the role name using the property `iamRoleStatementsName`. For example:\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - dynamodb:GetItem        \n        Resource: \"arn:aws:dynamodb:${self:provider.region}:*:table/mytable\"\n    ...\n```  \n\n## PermissionsBoundary\n\nDefine iamPermissionsBoundary definitions at the function level:\n\n```yaml\nfunctions:\n  func1:\n    handler: handler.get\n    iamPermissionsBoundary: !Sub arn:aws:iam::xxxxx:policy/your_permissions_boundary_policy\n    iamRoleStatementsName: my-custom-role-name \n    iamRoleStatements:\n      - Effect: \"Allow\"        \n        Action:\n          - sqs:*        \n        Resource: \"*\"\n    ...\n```\n\nYou can set permissionsBoundary for all roles with iamGlobalPermissionsBoundary in custom:\n\n```yaml\ncustom:\n  serverless-iam-roles-per-function:\n    iamGlobalPermissionsBoundary: !Sub arn:aws:iam::xxxx:policy/permissions-boundary-policy\n```\n\nFor more information, see [Permissions Boundaries](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html).\n\n\n## Contributing\nContributions are welcome and appreciated. \n\n* Before opening a PR it is best to first open an [issue](https://github.com/functionalone/serverless-iam-roles-per-function/issues/new). Describe in the issue what you want you plan to implement/fix. Based on the feedback in the issue, you should be able to plan how to implement your PR. \n* Once ready, open a [PR](https://github.com/functionalone/serverless-iam-roles-per-function/compare) to contribute your code.\n* To help updating the [CHANGELOG.md](CHANGELOG.md) file, we use [standard-version](https://github.com/conventional-changelog/standard-version). Make sure to use conventional commit messages as specified at: https://www.conventionalcommits.org/en/v1.0.0/.\n* Update the release notes at [CHANGELOG.md](CHANGELOG.md) and bump the version by running:\n  ```\n  npm run release \n  ```\n* Examine the [CHANGELOG.md](CHANGELOG.md) and update if still required.\n* Don't forget to commit the files modified by `npm run release` (we have the auto-commit option disabled by default).\n* Once the PR is approved and merged into master, travis-ci will automatically tag the version you created and deploy to npmjs under the `next` tag. You will see your version deployed at: https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions.\n* Test your deployed version by installing with the `next` tag. For example:\n  ```\n  npm install --save-dev serverless-iam-roles-per-function@next\n  ``` \n\n## Publishing a Production Release (Maintainers)\nOnce a contributed PR (or multiple PRs) have been merged into `master`, there is need to publish a production release, after we are sure that the release is stable. Maintainers with commit access to the repository can publish a release by merging into the `release` branch. Steps to follow:\n* Verify that the current deployed pre-release version under the `next` tag in npmjs is working properly. Usually, it is best to allow the `next` version to gain traction a week or two before releasing. Also, if the version solves a specific reported issue, ask the community on the issue to test out the `next` version.\n* Make sure the version being used in master hasn't been released. This can happen if a PR was merged without bumping the version by running `npm run release`. If the version needs to be advanced, open a PR to advance the version as specified [here](#contributing).\n* Open a PR to merge into the `release` branch. Use as a base the `release` branch and compare the `tag` version to `release`. For example:\n![Example PR](https://user-images.githubusercontent.com/1395797/101236848-1866e180-36dd-11eb-9281-6c726d15e4f1.png)\n\n* Once approved by another maintainer, merge the PR.\n* Make sure to check after the Travis CI build completes that the release has been published to the `latest` tag on [nmpjs](https://www.npmjs.com/package/serverless-iam-roles-per-function?activeTab=versions). \n\n## More Info\n\n**Introduction post**:\n[Serverless Framework: Defining Per-Function IAM Roles](https://medium.com/@glicht/serverless-framework-defining-per-function-iam-roles-c678fa09f46d)\n\n\n**Note**: Serverless Framework provides support for defining custom IAM roles on a per function level through the use of the `role` property and creating CloudFormation resources, as documented [here](https://serverless.com/framework/docs/providers/aws/guide/iam#custom-iam-roles). This plugin doesn't support defining both the `role` property and `iamRoleStatements` at the function level.\n\n[npm-image]:https://img.shields.io/npm/v/serverless-iam-roles-per-function.svg\n[npm-url]:http://npmjs.org/package/serverless-iam-roles-per-function\n[sls-image]:http://public.serverless.com/badges/v3.svg\n[sls-url]:http://www.serverless.com\n[travis-image]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function.svg?branch=master\n[travis-url]:https://travis-ci.com/functionalone/serverless-iam-roles-per-function\n[david-image]:https://david-dm.org/functionalone/serverless-iam-roles-per-function/status.svg\n[david-url]:https://david-dm.org/functionalone/serverless-iam-roles-per-function\n[coveralls-image]:https://coveralls.io/repos/github/functionalone/serverless-iam-roles-per-function/badge.svg?branch=master\n[coveralls-url]:https://coveralls.io/github/functionalone/serverless-iam-roles-per-function?branch=master\n[downloads-image]:https://img.shields.io/npm/dm/serverless-iam-roles-per-function.svg\n\n","maintainers":[{"name":"glicht","email":"guy@guylichtman.com"}],"time":{"modified":"2022-05-17T12:59:09.021Z","created":"2018-01-31T23:22:24.394Z","0.1.0":"2018-01-31T23:22:24.394Z","0.1.1":"2018-02-01T17:05:10.228Z","0.1.2":"2018-02-07T19:01:27.215Z","0.1.3":"2018-02-20T09:47:28.705Z","0.1.4":"2018-02-23T17:30:22.508Z","0.1.5":"2018-02-25T11:27:35.927Z","0.1.6":"2018-05-15T20:39:03.615Z","0.1.7":"2018-05-16T21:15:30.381Z","0.1.8":"2018-05-17T14:38:18.942Z","0.1.9":"2018-05-26T10:24:13.442Z","1.0.0":"2018-05-29T17:30:08.161Z","1.0.1":"2018-05-31T10:01:58.965Z","1.0.2":"2018-07-28T19:04:25.118Z","1.0.3":"2018-08-26T15:07:34.746Z","1.0.4":"2018-09-02T12:58:56.100Z","2.0.0":"2019-04-30T22:34:46.258Z","2.0.1":"2019-05-10T15:51:46.105Z","2.0.2":"2019-08-30T20:07:12.894Z","3.0.0-354af97":"2020-11-02T17:27:08.091Z","3.0.0-d84bffd":"2020-11-02T17:37:06.098Z","3.0.0-a5cedab":"2020-11-28T08:52:49.157Z","3.0.0-5593c96":"2020-11-28T15:05:18.844Z","3.0.0-9c593c8":"2020-11-28T16:43:34.209Z","3.0.1-21342a9":"2020-11-28T17:46:13.021Z","3.0.1-1321494":"2020-11-28T19:28:00.763Z","3.0.1-6e7bcb2":"2020-11-28T21:34:53.599Z","3.0.1-b5e1837":"2020-12-03T12:02:35.128Z","3.0.1":"2020-12-04T18:03:10.940Z","3.0.2-fb28ee6":"2020-12-04T19:22:55.105Z","3.0.2-223021":"2020-12-05T19:35:27.759Z","3.1.0-d68046e":"2020-12-26T22:19:06.368Z","3.1.0":"2021-01-16T18:30:32.394Z","3.1.1-720dc0f":"2021-01-16T20:04:22.736Z","3.2.0-e97ab49":"2021-03-22T14:36:00.694Z","3.2.0":"2021-05-21T06:07:47.612Z"},"homepage":"https://github.com/functionalone/serverless-iam-roles-per-function#readme","keywords":["aws","lambda","aws lambda","serverless","policy","role","iam","custom","permissions","security"],"repository":{"type":"git","url":"git+https://github.com/functionalone/serverless-iam-roles-per-function.git"},"author":{"name":"Functional One, Ltd."},"bugs":{"url":"https://github.com/functionalone/serverless-iam-roles-per-function/issues"},"license":"MIT","readmeFilename":"README.md"}