You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EventBridge是否支持CloudFormation?求IAM配置变更通知的现成CloudFormation模板

回答

1. EventBridge对CloudFormation的支持

EventBridge 完全支持CloudFormation,你可以通过CloudFormation模板定义所有核心EventBridge资源,包括:

  • 事件规则(AWS::Events::Rule)
  • 事件总线(AWS::Events::EventBus)
  • 目标关联(AWS::Events::Target)
  • 权限策略(AWS::Events::Permission)

所有资源的配置参数都能在CloudFormation官方文档中找到对应定义,可直接嵌入到你的模板中进行基础设施即代码管理。

2. IAM配置变更通知的现成CloudFormation模板

针对IAM配置变更的通知需求,以下是一个可直接使用的简化模板,实现捕获IAM相关API操作并通过SNS发送通知:

AWSTemplateFormatVersion: '2010-09-09'
Description: 捕获IAM配置变更并发送SNS通知
Resources:
  # SNS主题:用于接收并发送通知
  IAMChangeNotificationTopic:
    Type: AWS::SNS::Topic
    Properties:
      DisplayName: IAM-Configuration-Change-Alerts
      Subscription:
        # 替换为你的接收邮箱/其他端点
        - Endpoint: your-email@example.com
          Protocol: email

  # EventBridge规则:捕获IAM相关API调用事件
  IAMChangeEventRule:
    Type: AWS::Events::Rule
    Properties:
      Description: 触发IAM配置变更的事件规则
      EventPattern:
        source:
          - aws.iam
        detail-type:
          - AWS API Call via CloudTrail
        detail:
          eventSource:
            - iam.amazonaws.com
          eventName:
            # 这里列出需要监控的IAM操作,可根据需求扩展
            - CreateUser
            - DeleteUser
            - UpdateUser
            - CreateRole
            - DeleteRole
            - UpdateRole
            - CreatePolicy
            - DeletePolicy
            - AttachUserPolicy
            - DetachUserPolicy
      State: ENABLED
      Targets:
        - Arn: !Ref IAMChangeNotificationTopic
          Id: SNSTarget

  # 权限:允许EventBridge向SNS主题发送消息
  EventBridgeSNSPermission:
    Type: AWS::SNS::TopicPolicy
    Properties:
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: events.amazonaws.com
            Action: sns:Publish
            Resource: !Ref IAMChangeNotificationTopic
      Topics:
        - !Ref IAMChangeNotificationTopic

使用说明

  1. 将模板中的your-email@example.com替换为你实际的通知接收端点(邮箱、Lambda ARN等)
  2. 可根据需求扩展eventName列表,添加更多需要监控的IAM操作
  3. 部署模板后,CloudTrail需要处于启用状态(默认大部分区域已启用),因为EventBridge依赖CloudTrail的API调用事件

内容的提问来源于stack exchange,提问作者shantanuo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 11:23:36