Amazon web services s3错误:无法验证以下目标配置。未授权调用函数

Amazon web services s3错误:无法验证以下目标配置。未授权调用函数,amazon-web-services,amazon-s3,Amazon Web Services,Amazon S3,我正在努力实现以下目标。我有一个s3 bucket,它有一个云前端策略和get only策略 { "Version": "2008-10-17", "Id": "PolicyForCloudFrontPrivateContent", "Statement": [ { "Sid": "1", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::clou

我正在努力实现以下目标。我有一个s3 bucket,它有一个云前端策略和get only策略

     {
"Version": "2008-10-17",
"Id": "PolicyForCloudFrontPrivateContent",
"Statement": [
    {
        "Sid": "1",
        "Effect": "Allow",
        "Principal": {
            "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E*********R"
        },
        "Action": "s3:GetObject",
        "Resource": "arn:aws:s3:::s3-bucket-dev/*"
    }
]
 }
我试图从Lambda函数向s3添加一个触发器。但是,当我添加事件通知时,我得到了以下错误

Error: Unable to validate the following destination configurations. Not 
authorized to invoke the function.
Lambda角色具有管理员访问策略