import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages a S3 Bucket Notification Configuration. For additional information, see the [Configuring S3 Event Notifications section in the Amazon S3 Developer Guide](https://docs.aws.amazon.com/AmazonS3/latest/dev/NotificationHowTo.html). * * > **NOTE:** The S3 [`PutBucketNotificationConfiguration`](https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketNotificationConfiguration.html) API is atomic — it replaces the bucket's entire notification configuration on every call. Only one `aws.s3.BucketNotification` resource can manage a bucket; declaring more than one causes a perpetual diff, and applying this resource will overwrite any notifications already on the bucket. To configure multiple destinations on the same bucket, declare them all as nested blocks within a single resource (see Trigger multiple Lambda functions below). To let independent teams or Pulumi configurations subscribe to the same bucket without stepping on each other, prefer the Emit events to EventBridge pattern below. To bring existing notifications under management without losing them, see the `aws.s3.BucketNotification` data source. * * > This resource cannot be used with S3 directory buckets. * * ## Example Usage * * ### Add notification configuration to SNS Topic * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const bucket = new aws.s3.Bucket("bucket", {bucket: "your-bucket-name"}); * const topic = aws.iam.getPolicyDocumentOutput({ * statements: [{ * conditions: [{ * test: "ArnLike", * variable: "aws:SourceArn", * values: [bucket.arn], * }], * principals: [{ * type: "Service", * identifiers: ["s3.amazonaws.com"], * }], * effect: "Allow", * actions: ["SNS:Publish"], * resources: ["arn:aws:sns:*:*:s3-event-notification-topic"], * }], * }); * const topicTopic = new aws.sns.Topic("topic", { * name: "s3-event-notification-topic", * policy: topic.json, * }); * const bucketNotification = new aws.s3.BucketNotification("bucket_notification", { * topics: [{ * topicArn: topicTopic.arn, * events: ["s3:ObjectCreated:*"], * filterSuffix: ".log", * }], * bucket: bucket.id, * }); * ``` * * ### Add notification configuration to SQS Queue * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const bucket = new aws.s3.Bucket("bucket", {bucket: "your-bucket-name"}); * const queue = aws.iam.getPolicyDocumentOutput({ * statements: [{ * conditions: [{ * test: "ArnEquals", * variable: "aws:SourceArn", * values: [bucket.arn], * }], * principals: [{ * type: "*", * identifiers: ["*"], * }], * effect: "Allow", * actions: ["sqs:SendMessage"], * resources: ["arn:aws:sqs:*:*:s3-event-notification-queue"], * }], * }); * const queueQueue = new aws.sqs.Queue("queue", { * name: "s3-event-notification-queue", * policy: queue.json, * }); * const bucketNotification = new aws.s3.BucketNotification("bucket_notification", { * queues: [{ * queueArn: queueQueue.arn, * events: ["s3:ObjectCreated:*"], * filterSuffix: ".log", * }], * bucket: bucket.id, * }); * ``` * * ### Add notification configuration to Lambda Function * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const assumeRole = aws.iam.getPolicyDocument({ * statements: [{ * principals: [{ * type: "Service", * identifiers: ["lambda.amazonaws.com"], * }], * effect: "Allow", * actions: ["sts:AssumeRole"], * }], * }); * const iamForLambda = new aws.iam.Role("iam_for_lambda", { * name: "iam_for_lambda", * assumeRolePolicy: assumeRole.then(assumeRole => assumeRole.json), * }); * const func = new aws.lambda.Function("func", { * code: new pulumi.asset.FileArchive("your-function.zip"), * name: "example_lambda_name", * role: iamForLambda.arn, * handler: "exports.example", * runtime: aws.lambda.Runtime.NodeJS24dX, * }); * const bucket = new aws.s3.Bucket("bucket", {bucket: "your-bucket-name"}); * const allowBucket = new aws.lambda.Permission("allow_bucket", { * statementId: "AllowExecutionFromS3Bucket", * action: "lambda:InvokeFunction", * "function": func.arn, * principal: "s3.amazonaws.com", * sourceArn: bucket.arn, * }); * const bucketNotification = new aws.s3.BucketNotification("bucket_notification", { * lambdaFunctions: [{ * lambdaFunctionArn: func.arn, * events: ["s3:ObjectCreated:*"], * filterPrefix: "AWSLogs/", * filterSuffix: ".log", * }], * bucket: bucket.id, * }, { * dependsOn: [allowBucket], * }); * ``` * * ### Trigger multiple Lambda functions * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const assumeRole = aws.iam.getPolicyDocument({ * statements: [{ * principals: [{ * type: "Service", * identifiers: ["lambda.amazonaws.com"], * }], * effect: "Allow", * actions: ["sts:AssumeRole"], * }], * }); * const iamForLambda = new aws.iam.Role("iam_for_lambda", { * name: "iam_for_lambda", * assumeRolePolicy: assumeRole.then(assumeRole => assumeRole.json), * }); * const func1 = new aws.lambda.Function("func1", { * code: new pulumi.asset.FileArchive("your-function1.zip"), * name: "example_lambda_name1", * role: iamForLambda.arn, * handler: "exports.example", * runtime: aws.lambda.Runtime.NodeJS24dX, * }); * const bucket = new aws.s3.Bucket("bucket", {bucket: "your-bucket-name"}); * const allowBucket1 = new aws.lambda.Permission("allow_bucket1", { * statementId: "AllowExecutionFromS3Bucket1", * action: "lambda:InvokeFunction", * "function": func1.arn, * principal: "s3.amazonaws.com", * sourceArn: bucket.arn, * }); * const func2 = new aws.lambda.Function("func2", { * code: new pulumi.asset.FileArchive("your-function2.zip"), * name: "example_lambda_name2", * role: iamForLambda.arn, * handler: "exports.example", * }); * const allowBucket2 = new aws.lambda.Permission("allow_bucket2", { * statementId: "AllowExecutionFromS3Bucket2", * action: "lambda:InvokeFunction", * "function": func2.arn, * principal: "s3.amazonaws.com", * sourceArn: bucket.arn, * }); * const bucketNotification = new aws.s3.BucketNotification("bucket_notification", { * lambdaFunctions: [ * { * lambdaFunctionArn: func1.arn, * events: ["s3:ObjectCreated:*"], * filterPrefix: "AWSLogs/", * filterSuffix: ".log", * }, * { * lambdaFunctionArn: func2.arn, * events: ["s3:ObjectCreated:*"], * filterPrefix: "OtherLogs/", * filterSuffix: ".log", * }, * ], * bucket: bucket.id, * }, { * dependsOn: [ * allowBucket1, * allowBucket2, * ], * }); * ``` * * ### Add multiple notification configurations to SQS Queue * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const bucket = new aws.s3.Bucket("bucket", {bucket: "your-bucket-name"}); * const queue = aws.iam.getPolicyDocumentOutput({ * statements: [{ * conditions: [{ * test: "ArnEquals", * variable: "aws:SourceArn", * values: [bucket.arn], * }], * principals: [{ * type: "*", * identifiers: ["*"], * }], * effect: "Allow", * actions: ["sqs:SendMessage"], * resources: ["arn:aws:sqs:*:*:s3-event-notification-queue"], * }], * }); * const queueQueue = new aws.sqs.Queue("queue", { * name: "s3-event-notification-queue", * policy: queue.json, * }); * const bucketNotification = new aws.s3.BucketNotification("bucket_notification", { * queues: [ * { * id: "image-upload-event", * queueArn: queueQueue.arn, * events: ["s3:ObjectCreated:*"], * filterPrefix: "images/", * }, * { * id: "video-upload-event", * queueArn: queueQueue.arn, * events: ["s3:ObjectCreated:*"], * filterPrefix: "videos/", * }, * ], * bucket: bucket.id, * }); * ``` * * For JSON syntax, use an array instead of defining the `queue` key twice. * * ### Emit events to EventBridge * * For a bucket shared by multiple independent consumers — different teams, different Pulumi configurations, different applications — EventBridge is the recommended pattern. Each consumer subscribes to the bucket through its own `aws.cloudwatch.EventRule`, so they cannot overwrite one another the way notification configurations would. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const shared = new aws.s3.Bucket("shared", {bucket: "shared-bucket"}); * const sharedBucketNotification = new aws.s3.BucketNotification("shared", { * bucket: shared.id, * eventbridge: true, * }); * // Team A: process new uploads under uploads/ * const teamA = new aws.cloudwatch.EventRule("team_a", { * name: "team-a-uploads", * eventPattern: pulumi.jsonStringify({ * source: ["aws.s3"], * "detail-type": ["Object Created"], * detail: { * bucket: { * name: [shared.bucket], * }, * object: { * key: [{ * prefix: "uploads/", * }], * }, * }, * }), * }); * const teamAEventTarget = new aws.cloudwatch.EventTarget("team_a", { * rule: teamA.name, * arn: teamAProcessor.arn, * }); * // Team B: archive deletions under archive/, declared in a separate * // Pulumi configuration that knows nothing about Team A. * const teamB = new aws.cloudwatch.EventRule("team_b", { * name: "team-b-deletions", * eventPattern: pulumi.jsonStringify({ * source: ["aws.s3"], * "detail-type": ["Object Deleted"], * detail: { * bucket: { * name: [shared.bucket], * }, * object: { * key: [{ * prefix: "archive/", * }], * }, * }, * }), * }); * const teamBEventTarget = new aws.cloudwatch.EventTarget("team_b", { * rule: teamB.name, * arn: teamBArchive.arn, * }); * ``` * * For sharing a bucket between Pulumi configurations when EventBridge is not an option, use the `aws.s3.BucketNotification` data source to read existing notifications and re-emit them in your own resource. * * ## Import * * ### Identity Schema * * #### Required * * * `bucket` (String) Name of the bucket. * * #### Optional * * * `accountId` (String) Account ID where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import S3 bucket notification using the `bucket`. For example: * * ```sh * $ pulumi import aws:s3/bucketNotification:BucketNotification bucket_notification bucket-name * ``` */ export declare class BucketNotification extends pulumi.CustomResource { /** * Get an existing BucketNotification resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: BucketNotificationState, opts?: pulumi.CustomResourceOptions): BucketNotification; /** * Returns true if the given object is an instance of BucketNotification. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is BucketNotification; /** * Name of the bucket for notification configuration. * * The following arguments are optional: */ readonly bucket: pulumi.Output; /** * Whether to enable Amazon EventBridge notifications. Defaults to `false`. */ readonly eventbridge: pulumi.Output; /** * Notification configuration to a Lambda Function. See below. */ readonly lambdaFunctions: pulumi.Output; /** * Notification configuration to SQS Queue. See below. */ readonly queues: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Notification configuration to SNS Topic. See below. */ readonly topics: pulumi.Output; /** * Create a BucketNotification resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: BucketNotificationArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering BucketNotification resources. */ export interface BucketNotificationState { /** * Name of the bucket for notification configuration. * * The following arguments are optional: */ bucket?: pulumi.Input; /** * Whether to enable Amazon EventBridge notifications. Defaults to `false`. */ eventbridge?: pulumi.Input; /** * Notification configuration to a Lambda Function. See below. */ lambdaFunctions?: pulumi.Input[] | undefined>; /** * Notification configuration to SQS Queue. See below. */ queues?: pulumi.Input[] | undefined>; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Notification configuration to SNS Topic. See below. */ topics?: pulumi.Input[] | undefined>; } /** * The set of arguments for constructing a BucketNotification resource. */ export interface BucketNotificationArgs { /** * Name of the bucket for notification configuration. * * The following arguments are optional: */ bucket: pulumi.Input; /** * Whether to enable Amazon EventBridge notifications. Defaults to `false`. */ eventbridge?: pulumi.Input; /** * Notification configuration to a Lambda Function. See below. */ lambdaFunctions?: pulumi.Input[] | undefined>; /** * Notification configuration to SQS Queue. See below. */ queues?: pulumi.Input[] | undefined>; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Notification configuration to SNS Topic. See below. */ topics?: pulumi.Input[] | undefined>; } //# sourceMappingURL=bucketNotification.d.ts.map