Repository navigation
Support S3 as a stream destinations.onFailure type - #461
Open
christiantakle wants to merge 1 commit into
Open
christiantakle wants to merge 1 commit into
christiantakle wants to merge 1 commit into
Conversation
AWS supports an Amazon S3 bucket as the on-failure destination of Kinesis and DynamoDB event source mappings, alongside SNS and SQS: https://docs.aws.amazon.com/lambda/latest/dg/kinesis-on-failure-destination.html The schema only allowed `type: sns | sqs`, so `type: s3` failed validation with `must be equal to one of the allowed values [sns, sqs]`. Framework v3 only warned about it and emitted the destination unchanged. Add `s3` to the enum. Without a branch of its own, an S3 destination fell into the SQS one and got `sqs:SendMessage` on a bucket ARN. Give it the permissions the docs list: `s3:ListBucket` on the bucket and `s3:PutObject` on its objects (`<arn>/*`, or `Fn::Join` when the ARN is an intrinsic).
destinations.onFailure type
GrahamCampbell
self-requested a review
October 6, 2026 20:49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi, and thanks for osls. We're moving a large set of stacks from 3.x to 4.x and hit this on 13 of them, so here is a small fix. Happy to change it or close it if it doesn't fit how you want the project to go.
AWS supports an S3 bucket as the on-failure destination for Kinesis and DynamoDB event source mappings (docs). 3.x only warned about
type: s3and emitted the destination unchanged; 4.x rejects it withmust be equal to one of the allowed values [sns, sqs].s3to thetypeenums3:ListBucketon the bucket,s3:PutObjecton<arn>/*, viaFn::Joinfor intrinsic ARNs). Without it an S3 destination fell into the SQS branch and gotsqs:SendMessageFn::GetAttplus the expected IAM statement, and a docs examplePackage and provider unit tests pass (1449), prettier and eslint are clean.