Description
If a bucket needs downstream processing when objects are created or deleted, missing event notifications can interrupt operational automation or security response. Not every bucket needs the same notifications; also check any existing alternative event-processing paths.
S3 event notifications do not replace a complete audit log. Delivery is designed to be at least once, so consumers must account for duplicate events.
Potential impact
- Important file uploads or deletions can be discovered late.
- Event-dependent security monitoring or downstream automation can fail to run.
- Missing required events or processing duplicates can disrupt operational workflows.
Remediation
- Choose the required event types and object filters, and configure an appropriate delivery path such as SNS, SQS, Lambda or EventBridge.
- Verify the destination resource, permissions, applicable Region requirements and the actual recipient path, including SNS subscriptions. Test using the relevant events.
- Manage each bucket's Terraform notification configuration in one place and retain other required destinations. Design consumers to handle duplicates safely.
Examples
Replace the bucket name with the intended value. The after example omits the policy data source, which must allow S3 to publish to the SNS topic in the bucket's Region. SNS recipient subscriptions are also required. Applying an empty notification configuration can clear existing notifications, so review the complete configuration.
Before
resource "aws_s3_bucket" "bucket" {
bucket = "your-bucket-name"
}
resource "aws_s3_bucket_notification" "bucket_notification" {
bucket = aws_s3_bucket.bucket.id
}
After
resource "aws_sns_topic" "topic" {
name = "s3-event-notification-topic"
policy = data.aws_iam_policy_document.topic.json
}
resource "aws_s3_bucket" "bucket" {
bucket = "your-bucket-name"
}
resource "aws_s3_bucket_notification" "bucket_notification" {
bucket = aws_s3_bucket.bucket.id
topic {
topic_arn = aws_sns_topic.topic.arn
events = ["s3:ObjectCreated:*"]
filter_suffix = ".log"
}
}
Explanation:
- Before: The notification resource does not specify a destination.
- After: Creation events for objects whose names end in
.logare delivered to the SNS topic. This does not cover every object or deletion events.