Description
When notification_arns is not specified for a CloudFormation stack, this setting does not provide SNS notifications. Without another monitoring path, operators can discover deployment failures or unexpected changes late. Stack events remain available in CloudFormation itself.
Ensure the responsible team can see whether infrastructure changes succeeded and investigate failures. Also assess whether an existing alternative path, such as EventBridge, meets notification requirements.
Potential impact
- Stack deployment failures can be discovered late.
- Unexpected infrastructure changes can go unnoticed for longer.
- Incident response and investigation can be delayed.
Remediation
- Set
notification_arnsto an approved operational SNS topic for stacks that need SNS notifications. - Configure publishing permissions and recipient subscriptions, and test whether deployment failure and rollback events reach the responsible team.
- Regularly verify recipients and operational ownership. Notifications do not replace change approval or controls that prevent failures.
Examples
These stack excerpts omit the template_body or template_url required for deployment. Replace the example SNS ARN with the intended topic, and configure permissions and subscriptions separately.
Before
resource "aws_cloudformation_stack" "example" {
name = "networking-stack"
parameters = {
VPCCidr = "10.0.0.0/16"
}
}
After
resource "aws_cloudformation_stack" "example" {
name = "networking-stack"
parameters = {
VPCCidr = "10.0.0.0/16"
}
notification_arns = ["arn:aws:sns:us-east-1:123456789012:stack-events"]
}
Explanation:
- Before: No SNS notification topic is specified for the stack. Check whether other monitoring paths exist.
- After: An SNS topic is specified for stack events. Verify actual delivery and receipt by subscribers.