Description
CloudFormation can publish stack creation, update, and rollback status changes to SNS topics. Without notifications or alternative monitoring, deployment problems may be noticed late.
Potential impact
Failed deployments may take longer to identify or reach the responsible operators.
Remediation
Set SNS topic ARNs in notification_arns when notifications are needed, then verify publishing permissions, subscriptions, and receipt.
Examples
The examples add an SNS notification destination. Prepare the topic, template URL, and parameters for the actual environment.
Before
yaml
- name: Create CloudFormation stack
amazon.aws.cloudformation:
stack_name: ansible-cloudformation
state: present
region: us-east-1
disable_rollback: true
template_url: https://s3.amazonaws.com/my-bucket/cloudformation.template
template_parameters:
KeyName: jmartin
DiskType: ephemeral
InstanceType: m1.small
ClusterSize: 3
tags:
Stack: ansible-cloudformation
After
yaml
- name: Create CloudFormation stack
amazon.aws.cloudformation:
stack_name: ansible-cloudformation
notification_arns: arn:aws:sns:us-east-1:123456789012:stack-events
state: present
region: us-east-1
disable_rollback: true
template_url: https://s3.amazonaws.com/my-bucket/cloudformation.template
template_parameters:
KeyName: jmartin
DiskType: ephemeral
InstanceType: m1.small
ClusterSize: 3
tags:
Stack: ansible-cloudformation