even if I create the log group by myself later on in pulumi I then get
Your function doesn't have permission to write to Amazon CloudWatch Logs. To view logs, add the
AWSLambdaBasicExecutionRole managed policy to its execution role.
Open the IAM console