CloudWatch事件模式通配符失效:SSM参数触发Lambda问题求助
I ran into exactly this issue a while back—turns out the problem is how you're using wildcards in your EventBridge pattern. Let me break down what's wrong and how to fix it:
Why Your Current Pattern Isn't Working
Your event pattern has "name": [ "/dev/*" ], but in EventBridge's syntax, putting * directly inside a string treats it as a literal character, not a wildcard. That means your pattern will only trigger if an SSM parameter is created with the exact name /dev/*—not any parameter starting with /dev/.
Solution 1: Use Prefix Matching (Recommended)
The cleanest and most efficient way to match all parameters starting with /dev/ is to use EventBridge's built-in prefix operator. Update your event pattern like this:
{ "source": [ "aws.ssm" ], "detail-type": [ "Parameter Store Change" ], "detail": { "name": [ { "prefix": "/dev/" } ], "operation": [ "Create", "Update", "Delete", "LabelParameterVersion" ] } }
- This will match any SSM parameter whose name starts with
/dev/, regardless of how many sub-paths it has (e.g.,/dev/app/config,/dev/db/url). - I removed
"Parameter Store Policy Action"fromdetail-typesince that's for policy-related events, not parameter creation/updates—you can add it back if you do need those events.
Solution 2: Use Wildcard Operator
If you prefer to use a wildcard pattern, you need to wrap it in the wildcard operator instead of putting it directly in a string:
{ "source": [ "aws.ssm" ], "detail-type": [ "Parameter Store Change" ], "detail": { "name": [ { "wildcard": "/dev/*" } ], "operation": [ "Create", "Update", "Delete", "LabelParameterVersion" ] } }
- The
wildcardoperator treats*as a true wildcard (matches any sequence of characters, including slashes). Note that/dev/*will match/dev/abcand/dev/abc/def—if you only want to match parameters directly under/dev/(not sub-paths), you'd use/dev/?*or adjust the pattern accordingly.
Additional Checks to Ensure Trigger Works
- Verify SSM Event Emission: Make sure the SSM parameter change is actually generating an EventBridge event. You can check this in the EventBridge console under "Event history"—filter by
source:aws.ssmand look for your parameter creation event. - Lambda Permissions: Confirm your Lambda function has a resource-based policy that allows EventBridge to invoke it. The policy should look something like this (replace
YOUR_LAMBDA_ARNandYOUR_EVENT_BUS_ARN):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "events.amazonaws.com" }, "Action": "lambda:InvokeFunction", "Resource": "YOUR_LAMBDA_ARN", "Condition": { "ArnLike": { "AWS:SourceArn": "YOUR_EVENT_BUS_ARN" } } } ] }
- Test with a Simple Parameter: Create a parameter named
/dev/test-paramand check if the Lambda triggers. If it does, the pattern is working correctly.
内容的提问来源于stack exchange,提问作者manu thankachan

