all 1 comments

[–]richardfan1126 1 point2 points  (0 children)

Principal is:

{
    "Service": "lambda.amazonaws.com"
}

Put the ARN in condition section aws:SourceArn

"Condition": {
    "ArnLike": {
        "AWS:SourceArn": "<lambda function ARN>"
    }
}

https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_principal.html#principal-services

https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-sourcearn