Description
CloudFormation’s NotificationARNs specifies SNS topics that receive stack events. Without these notifications or another monitoring path, deployment failures and rollbacks may be noticed late.
Potential impact
Missed stack-state changes can delay responses to deployment problems.
Remediation
Add SNS topic ARNs to NotificationARNs, and configure publishing permissions and subscriptions. Verify that operators actually receive the events.
Examples
These excerpts add an SNS topic to a nested stack. Set the template URL and parameters to match the actual nested template.
Before
yaml
Resources:
myStackWithParams:
Type: AWS::CloudFormation::Stack
Properties:
TemplateURL: https://s3.amazonaws.com/cloudformation-templates-us-east-2/EC2ChooseAMI.template
Parameters:
InstanceType: t1.micro
KeyName: mykey
After
yaml
Resources:
myStackWithParams:
Type: AWS::CloudFormation::Stack
Properties:
NotificationARNs:
- "arn:aws:sns:ap-northeast-2:123456789012:stack-alerts"
TemplateURL: https://s3.amazonaws.com/cloudformation-templates-us-east-2/EC2ChooseAMI.template
Parameters:
InstanceType: t1.micro
KeyName: mykey