使用 Cloudformation 到 SQS 的 AWS SNS 发布失败
AWS SNS to SQS publish fails using Cloudformation
我最近开始使用 AWS 服务学习和实施服务。所以,我想我遗漏了一些我无法理解的小步骤。
我正在尝试使用 Cloudformation 模板实现下图。一切正常,除非。 Lambda 和 SQS 队列成功订阅 SNS 主题。每当文件存储在存储桶中时,甚至当我手动向 SNS 主题发布消息时,lambda 函数都会成功触发,但消息不会发布到 SQS 队列。我还添加了 AWS::SQS::QueuePolicy 以允许 SNS 向 SQS 发送消息,但它仍然不起作用。
template.yml:
...
Resources:
S3ObjectPutTopic:
Type: AWS::SNS::Topic
Properties:
TopicName: !Sub ${AppName}-vrp-creation-${Environment}-topic
BucketToSNSPermission:
Type: AWS::SNS::TopicPolicy
...
Bucket:
Type: AWS::S3::Bucket
...
Lambda:
Type: AWS::Serverless::Function
...
Queue:
Type: AWS::SQS::Queue
Properties:
DelaySeconds: 0
MaximumMessageSize: 262144
MessageRetentionPeriod: 864000
QueueName: !Sub ${AppName}-${Environment}-queue
ReceiveMessageWaitTimeSeconds: 0
VisibilityTimeout: 90
TopicToQueuePermission:
Type: AWS::SQS::QueuePolicy
Properties:
Queues:
- !Ref Queue
PolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Principal:
Service: s3.amazonaws.com
Action: sqs:SendMessage
Resource: !GetAtt Queue.Arn
Condition:
ArnEquals:
aws:SourceArn: !Ref S3ObjectPutTopic
TopicToQueueSubscription:
Type: AWS::SNS::Subscription
Properties:
Protocol: sqs
TopicArn: !Ref S3ObjectPutTopic
Endpoint: !GetAtt Queue.Arn
RawMessageDelivery: true
完整的 Cloudformation template.yaml 文件:template.yaml
您在 SQS 政策中提到了 Service: s3.amazonaws.com
而不是 Service: sns.amazonaws.com
。更新模板试试。
TopicToQueuePermission:
Type: AWS::SQS::QueuePolicy
Properties:
Queues:
- !Ref Queue
PolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Principal:
Service: s3.amazonaws.com
Action: sqs:SendMessage
Resource: !GetAtt Queue.Arn
Condition:
ArnEquals:
aws:SourceArn: !Ref S3ObjectPutTopic
我最近开始使用 AWS 服务学习和实施服务。所以,我想我遗漏了一些我无法理解的小步骤。
我正在尝试使用 Cloudformation 模板实现下图。一切正常,除非。 Lambda 和 SQS 队列成功订阅 SNS 主题。每当文件存储在存储桶中时,甚至当我手动向 SNS 主题发布消息时,lambda 函数都会成功触发,但消息不会发布到 SQS 队列。我还添加了 AWS::SQS::QueuePolicy 以允许 SNS 向 SQS 发送消息,但它仍然不起作用。
template.yml:
...
Resources:
S3ObjectPutTopic:
Type: AWS::SNS::Topic
Properties:
TopicName: !Sub ${AppName}-vrp-creation-${Environment}-topic
BucketToSNSPermission:
Type: AWS::SNS::TopicPolicy
...
Bucket:
Type: AWS::S3::Bucket
...
Lambda:
Type: AWS::Serverless::Function
...
Queue:
Type: AWS::SQS::Queue
Properties:
DelaySeconds: 0
MaximumMessageSize: 262144
MessageRetentionPeriod: 864000
QueueName: !Sub ${AppName}-${Environment}-queue
ReceiveMessageWaitTimeSeconds: 0
VisibilityTimeout: 90
TopicToQueuePermission:
Type: AWS::SQS::QueuePolicy
Properties:
Queues:
- !Ref Queue
PolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Principal:
Service: s3.amazonaws.com
Action: sqs:SendMessage
Resource: !GetAtt Queue.Arn
Condition:
ArnEquals:
aws:SourceArn: !Ref S3ObjectPutTopic
TopicToQueueSubscription:
Type: AWS::SNS::Subscription
Properties:
Protocol: sqs
TopicArn: !Ref S3ObjectPutTopic
Endpoint: !GetAtt Queue.Arn
RawMessageDelivery: true
完整的 Cloudformation template.yaml 文件:template.yaml
您在 SQS 政策中提到了 Service: s3.amazonaws.com
而不是 Service: sns.amazonaws.com
。更新模板试试。
TopicToQueuePermission:
Type: AWS::SQS::QueuePolicy
Properties:
Queues:
- !Ref Queue
PolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Principal:
Service: s3.amazonaws.com
Action: sqs:SendMessage
Resource: !GetAtt Queue.Arn
Condition:
ArnEquals:
aws:SourceArn: !Ref S3ObjectPutTopic