EventBridge是否支持CloudFormation?求IAM配置变更通知的现成CloudFormation模板
回答
1. EventBridge对CloudFormation的支持
EventBridge 完全支持CloudFormation,你可以通过CloudFormation模板定义所有核心EventBridge资源,包括:
- 事件规则(
AWS::Events::Rule) - 事件总线(
AWS::Events::EventBus) - 目标关联(
AWS::Events::Target) - 权限策略(
AWS::Events::Permission)
所有资源的配置参数都能在CloudFormation官方文档中找到对应定义,可直接嵌入到你的模板中进行基础设施即代码管理。
2. IAM配置变更通知的现成CloudFormation模板
针对IAM配置变更的通知需求,以下是一个可直接使用的简化模板,实现捕获IAM相关API操作并通过SNS发送通知:
AWSTemplateFormatVersion: '2010-09-09' Description: 捕获IAM配置变更并发送SNS通知 Resources: # SNS主题:用于接收并发送通知 IAMChangeNotificationTopic: Type: AWS::SNS::Topic Properties: DisplayName: IAM-Configuration-Change-Alerts Subscription: # 替换为你的接收邮箱/其他端点 - Endpoint: your-email@example.com Protocol: email # EventBridge规则:捕获IAM相关API调用事件 IAMChangeEventRule: Type: AWS::Events::Rule Properties: Description: 触发IAM配置变更的事件规则 EventPattern: source: - aws.iam detail-type: - AWS API Call via CloudTrail detail: eventSource: - iam.amazonaws.com eventName: # 这里列出需要监控的IAM操作,可根据需求扩展 - CreateUser - DeleteUser - UpdateUser - CreateRole - DeleteRole - UpdateRole - CreatePolicy - DeletePolicy - AttachUserPolicy - DetachUserPolicy State: ENABLED Targets: - Arn: !Ref IAMChangeNotificationTopic Id: SNSTarget # 权限:允许EventBridge向SNS主题发送消息 EventBridgeSNSPermission: Type: AWS::SNS::TopicPolicy Properties: PolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: events.amazonaws.com Action: sns:Publish Resource: !Ref IAMChangeNotificationTopic Topics: - !Ref IAMChangeNotificationTopic
使用说明
- 将模板中的
your-email@example.com替换为你实际的通知接收端点(邮箱、Lambda ARN等) - 可根据需求扩展
eventName列表,添加更多需要监控的IAM操作 - 部署模板后,CloudTrail需要处于启用状态(默认大部分区域已启用),因为EventBridge依赖CloudTrail的API调用事件
内容的提问来源于stack exchange,提问作者shantanuo
相关产品推荐
相关产品推荐

