如何使用Ansible删除AWS Lambda时同步删除关联的CloudWatch Event
To tackle your problem of deleting the corresponding CloudWatch Event when removing a Lambda function (especially since your current setup creates Events tied to specific Lambda versions), here are two practical approaches tailored to your scenario:
Approach 1: Use a Fixed Naming Convention (Simplest)
If your CloudWatch Event rule follows a predictable naming pattern (e.g., lambdaNameevent for a Lambda named lambdaName), you can directly delete the Event rule by name before removing the Lambda. This avoids dealing with version-specific ARNs entirely.
First, adjust your creation tasks to use the version-agnostic Lambda ARN (instead of the versioned one returned by the lambda module) to ensure your Event targets the Lambda's latest version:
- name: Deploy Lambda function lambda: name: 'lambdaName' state: present # Add your runtime, handler, code package, etc. here register: lambdaResult - name: Build version-agnostic Lambda ARN set_fact: lambda_base_arn: "arn:aws:lambda:{{ aws_region }}:{{ aws_account_id }}:function:{{ lambdaResult.configuration.function_name }}" - name: Create CloudWatch Event rule targeting Lambda cloudwatchevent_rule: name: 'lambdaNameevent' schedule_expression: 'rate(5 minutes)' # Adjust to your trigger logic targets: - arn: '{{ lambda_base_arn }}' id: "1" state: present
Then, when you need to clean up resources:
- name: Delete associated CloudWatch Event rule cloudwatchevent_rule: name: 'lambdaNameevent' state: absent # Including the target ID ensures we cleanly remove the target before deleting the rule targets: - id: "1" - name: Delete Lambda function lambda: name: 'lambdaName' state: absent
Approach 2: Dynamically Find and Delete Associated Events
If your CloudWatch Event rules don't follow a fixed naming pattern, or multiple Events target the same Lambda, you can query all Event rules, filter those targeting your Lambda, and delete them programmatically.
- name: Get all CloudWatch Event rules in the region cloudwatchevent_rule_info: region: '{{ aws_region }}' register: all_cwe_rules - name: Filter rules targeting our Lambda function set_fact: target_rules: > {{ all_cwe_rules.rules | selectattr('targets', 'defined') | selectattr('targets', '!=', []) | selectattr('targets.0.arn', 'search', lambdaResult.configuration.function_name) | map(attribute='name') | list }} - name: Delete all matching CloudWatch Event rules cloudwatchevent_rule: name: '{{ item }}' state: absent loop: '{{ target_rules }}' - name: Delete the Lambda function lambda: name: 'lambdaName' state: absent
Key Notes:
- Version-Agnostic ARNs: Using the base Lambda ARN (without version suffix) ensures your CloudWatch Event always triggers the latest Lambda version, and simplifies cleanup since you don't have to track versioned ARNs.
- Order Matters: Always delete the CloudWatch Event rule first before removing the Lambda to avoid "target not found" errors in AWS.
- Filter Logic: The
searchfilter in the second approach matches any Event target ARN that includes your Lambda's name, which works for both versioned and base ARNs.
内容的提问来源于stack exchange,提问作者Sumanth Kumar Mora

