Description: Grants read-only access to AWS Lambda service, AWS Lambda console features, and other related AWS services.
AWSLambda_ReadOnlyAccess
is an AWS managed policy.
Using this policy
You can attach AWSLambda_ReadOnlyAccess
to your users, groups, and roles.
Policy
details
-
Type: AWS managed policy
-
Creation time: November 17, 2020, 21:10 UTC
-
Edited time: March 17, 2025, 21:07 UTC
-
ARN:
arn:aws:iam::aws:policy/AWSLambda_ReadOnlyAccess
Policy version
Policy version: v3 (default)
The policy's default version is the version that defines the permissions for the policy. When a user or role with the policy makes a request to access an AWS resource, AWS checks the default version of the policy to determine whether to allow the request.
JSON policy document
{
"Version" : "2012-10-17",
"Statement" : [
{
"Effect" : "Allow",
"Action" : [
"cloudformation:DescribeStacks",
"cloudformation:ListStacks",
"cloudformation:ListStackResources",
"cloudwatch:GetMetricData",
"cloudwatch:ListMetrics",
"ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets",
"ec2:DescribeVpcs",
"kms:ListAliases",
"iam:GetPolicy",
"iam:GetPolicyVersion",
"iam:GetRole",
"iam:GetRolePolicy",
"iam:ListAttachedRolePolicies",
"iam:ListRolePolicies",
"iam:ListRoles",
"logs:DescribeLogGroups",
"lambda:Get*",
"lambda:List*",
"states:DescribeStateMachine",
"states:ListStateMachines",
"tag:GetResources",
"xray:GetTraceSummaries",
"xray:BatchGetTraces"
],
"Resource" : "*"
},
{
"Effect" : "Allow",
"Action" : [
"logs:DescribeLogStreams",
"logs:GetLogEvents",
"logs:FilterLogEvents",
"logs:StartQuery",
"logs:StopQuery",
"logs:DescribeQueries",
"logs:GetLogGroupFields",
"logs:GetLogRecord",
"logs:GetQueryResults",
"logs:StartLiveTail",
"logs:StopLiveTail"
],
"Resource" : "arn:aws:logs:*:*:log-group:/aws/lambda/*"
}
]
}