Skip to content

Support S3 as a stream destinations.onFailure type - #461

Open
christiantakle wants to merge 1 commit into
oss-serverless:4.xfrom
christiantakle:fix/stream-onfailure-s3-destination
Open

christiantakle wants to merge 1 commit into
oss-serverless:4.xfrom
christiantakle:fix/stream-onfailure-s3-destination

Conversation

@christiantakle

@christiantakle christiantakle commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Hi, and thanks for osls. We're moving a large set of stacks from 3.x to 4.x and hit this on 13 of them, so here is a small fix. Happy to change it or close it if it doesn't fit how you want the project to go.

AWS supports an S3 bucket as the on-failure destination for Kinesis and DynamoDB event source mappings (docs). 3.x only warned about type: s3 and emitted the destination unchanged; 4.x rejects it with must be equal to one of the allowed values [sns, sqs].

  • adds s3 to the type enum
  • gives S3 its own IAM statement (s3:ListBucket on the bucket, s3:PutObject on <arn>/*, via Fn::Join for intrinsic ARNs). Without it an S3 destination fell into the SQS branch and got sqs:SendMessage
  • tests for a string ARN and Fn::GetAtt plus the expected IAM statement, and a docs example

Package and provider unit tests pass (1449), prettier and eslint are clean.

AWS supports an Amazon S3 bucket as the on-failure destination of Kinesis
and DynamoDB event source mappings, alongside SNS and SQS:
https://docs.aws.amazon.com/lambda/latest/dg/kinesis-on-failure-destination.html

The schema only allowed `type: sns | sqs`, so `type: s3` failed validation
with `must be equal to one of the allowed values [sns, sqs]`. Framework v3
only warned about it and emitted the destination unchanged.

Add `s3` to the enum. Without a branch of its own, an S3 destination fell
into the SQS one and got `sqs:SendMessage` on a bucket ARN. Give it the
permissions the docs list: `s3:ListBucket` on the bucket and `s3:PutObject`
on its objects (`<arn>/*`, or `Fn::Join` when the ARN is an intrinsic).
@christiantakle christiantakle changed the title Support S3 as a stream destinations.onFailure type Support S3 as a stream destinations.onFailure type Sep 29, 2026
@GrahamCampbell
GrahamCampbell self-requested a review October 6, 2026 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant