Claude Skill

sns

AWS SNS notification service for pub/sub messaging. Use when creating topics, managing subscriptions, configuring message filtering, sending notifications, or setting up mobile push.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download itsmostafa-aws-agent-skills-skills_sns-e786d25.zip · 5 KB
Part of itsmostafa/aws-agent-skills — 17 skills

Install

skills CLI npx skills add https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/sns
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install itsmostafa-aws-agent-skills@llmmart
Git git clone https://github.com/itsmostafa/aws-agent-skills.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole itsmostafa/aws-agent-skills collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

AWS SNS

Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service for application-to-application (A2A) and application-to-person (A2P) communication.

Table of Contents

Core Concepts

Topics

Named channels for publishing messages. Publishers send to topics, subscribers receive from topics.

Topic Types

Type Description Use Case
Standard Best-effort ordering, at-least-once Most use cases
FIFO Strict ordering, exactly-once Order-sensitive

Subscription Protocols

Protocol Description
Lambda Invoke Lambda function
SQS Send to SQS queue
HTTP/HTTPS POST to endpoint
Email Send email
SMS Send text message
Application Mobile push notification

Message Filtering

Route messages to specific subscribers based on message attributes.

Common Patterns

Create Topic and Subscribe

AWS CLI:

# Create standard topic
aws sns create-topic --name my-topic

# Create FIFO topic
aws sns create-topic \
  --name my-topic.fifo \
  --attributes FifoTopic=true

# Subscribe Lambda
aws sns subscribe \
  --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
  --protocol lambda \
  --notification-endpoint arn:aws:lambda:us-east-1:123456789012:function:my-function

# Subscribe SQS
aws sns subscribe \
  --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
  --protocol sqs \
  --notification-endpoint arn:aws:sqs:us-east-1:123456789012:my-queue

# Subscribe email
aws sns subscribe \
  --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
  --protocol email \
  --notification-endpoint user@example.com

boto3:

import boto3

sns = boto3.client('sns')

# Create topic
response = sns.create_topic(Name='my-topic')
topic_arn = response['TopicArn']

# Subscribe Lambda
sns.subscribe(
    TopicArn=topic_arn,
    Protocol='lambda',
    Endpoint='arn:aws:lambda:us-east-1:123456789012:function:my-function'
)

# Subscribe SQS with filter
sns.subscribe(
    TopicArn=topic_arn,
    Protocol='sqs',
    Endpoint='arn:aws:sqs:us-east-1:123456789012:order-queue',
    Attributes={
        'FilterPolicy': '{"event_type": ["order_created", "order_updated"]}'
    }
)

Publish Messages

import boto3
import json

sns = boto3.client('sns')
topic_arn = 'arn:aws:sns:us-east-1:123456789012:my-topic'

# Simple publish
sns.publish(
    TopicArn=topic_arn,
    Message='Hello, World!',
    Subject='Notification'
)

# Publish with attributes (for filtering)
sns.publish(
    TopicArn=topic_arn,
    Message=json.dumps({'order_id': '12345', 'status': 'created'}),
    MessageAttributes={
        'event_type': {
            'DataType': 'String',
            'StringValue': 'order_created'
        },
        'priority': {
            'DataType': 'Number',
            'StringValue': '1'
        }
    }
)

# Publish to FIFO topic
sns.publish(
    TopicArn='arn:aws:sns:us-east-1:123456789012:my-topic.fifo',
    Message=json.dumps({'order_id': '12345'}),
    MessageGroupId='order-12345',
    MessageDeduplicationId='unique-id'
)

Message Filtering

# Add filter policy to subscription
aws sns set-subscription-attributes \
  --subscription-arn arn:aws:sns:us-east-1:123456789012:my-topic:abc123 \
  --attribute-name FilterPolicy \
  --attribute-value '{
    "event_type": ["order_created"],
    "priority": [{"numeric": [">=", 1]}]
  }'

Filter policy examples:

// Exact match
{"event_type": ["order_created", "order_updated"]}

// Prefix match
{"customer_id": [{"prefix": "PREMIUM-"}]}

// Numeric comparison
{"price": [{"numeric": [">=", 100, "<=", 500]}]}

// Exists check
{"customer_id": [{"exists": true}]}

// Anything but
{"event_type": [{"anything-but": ["deleted"]}]}

// Combined
{
  "event_type": ["order_created"],
  "region": ["us-east", "us-west"],
  "priority": [{"numeric": [">=", 1]}]
}

Fan-Out Pattern (SNS to Multiple SQS)

import boto3
import json

sns = boto3.client('sns')
sqs = boto3.client('sqs')

# Create topic
topic = sns.create_topic(Name='orders-topic')
topic_arn = topic['TopicArn']

# Create queues for different processors
queues = {
    'analytics': sqs.create_queue(QueueName='order-analytics')['QueueUrl'],
    'fulfillment': sqs.create_queue(QueueName='order-fulfillment')['QueueUrl'],
    'notification': sqs.create_queue(QueueName='order-notification')['QueueUrl']
}

# Subscribe each queue
for name, queue_url in queues.items():
    queue_arn = sqs.get_queue_attributes(
        QueueUrl=queue_url,
        AttributeNames=['QueueArn']
    )['Attributes']['QueueArn']

    sns.subscribe(
        TopicArn=topic_arn,
        Protocol='sqs',
        Endpoint=queue_arn
    )

# One publish reaches all queues
sns.publish(
    TopicArn=topic_arn,
    Message=json.dumps({'order_id': '12345', 'total': 99.99})
)

Lambda Permission for SNS

aws lambda add-permission \
  --function-name my-function \
  --statement-id sns-trigger \
  --action lambda:InvokeFunction \
  --principal sns.amazonaws.com \
  --source-arn arn:aws:sns:us-east-1:123456789012:my-topic

CLI Reference

Topic Management

Command Description
aws sns create-topic Create topic
aws sns delete-topic Delete topic
aws sns list-topics List topics
aws sns get-topic-attributes Get topic settings
aws sns set-topic-attributes Update topic settings

Subscriptions

Command Description
aws sns subscribe Create subscription
aws sns unsubscribe Remove subscription
aws sns list-subscriptions List all subscriptions
aws sns list-subscriptions-by-topic List topic subscriptions
aws sns confirm-subscription Confirm pending subscription

Publishing

Command Description
aws sns publish Publish message

Best Practices

Reliability

  • Use SQS for durability — SNS is push-based, SQS queues messages
  • Implement retries for HTTP/HTTPS endpoints
  • Configure DLQ for failed deliveries
  • Use FIFO topics for ordering requirements

Security

  • Use topic policies to control access
  • Enable encryption with SSE
  • Use VPC endpoints for private access
# Enable SSE
aws sns set-topic-attributes \
  --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
  --attribute-name KmsMasterKeyId \
  --attribute-value alias/my-key

Cost Optimization

  • Use message filtering to reduce unnecessary deliveries
  • Batch operations where possible
  • Monitor and clean up unused topics/subscriptions

Message Design

  • Keep messages small (256 KB limit)
  • Use message attributes for routing
  • Include correlation IDs for tracing

Troubleshooting

Subscription Not Receiving Messages

Check:

  1. Subscription is confirmed (not pending)
  2. Filter policy matches message attributes
  3. Target permissions (Lambda, SQS)
# Check subscription status
aws sns list-subscriptions-by-topic \
  --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic

# Check subscription attributes
aws sns get-subscription-attributes \
  --subscription-arn arn:aws:sns:us-east-1:123456789012:my-topic:abc123

HTTP Endpoint Not Working

Debug:

# Check delivery status logging
aws sns set-topic-attributes \
  --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
  --attribute-name DeliveryPolicy \
  --attribute-value '{
    "http": {
      "defaultHealthyRetryPolicy": {
        "minDelayTarget": 20,
        "maxDelayTarget": 20,
        "numRetries": 3,
        "numMaxDelayRetries": 0,
        "numNoDelayRetries": 0,
        "numMinDelayRetries": 0,
        "backoffFunction": "linear"
      }
    }
  }'

Messages Not Matching Filter

Verify:

  • Message attributes are set (not in body)
  • Attribute types match (String vs Number)
  • Filter policy syntax is correct
# Correct: attributes must be message attributes
sns.publish(
    TopicArn=topic_arn,
    Message='body content',
    MessageAttributes={
        'event_type': {
            'DataType': 'String',
            'StringValue': 'order_created'  # This is filtered
        }
    }
)

# Wrong: this won't be filtered
sns.publish(
    TopicArn=topic_arn,
    Message=json.dumps({'event_type': 'order_created'})  # Not filtered
)

SQS Not Receiving from SNS

Check SQS queue policy:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {"Service": "sns.amazonaws.com"},
      "Action": "sqs:SendMessage",
      "Resource": "arn:aws:sqs:us-east-1:123456789012:my-queue",
      "Condition": {
        "ArnEquals": {
          "aws:SourceArn": "arn:aws:sns:us-east-1:123456789012:my-topic"
        }
      }
    }
  ]
}

References

Files (aws-agent-skills)
  • notification-patterns.md 7.7 KB
    # SNS Notification Patterns
    
    Advanced notification patterns and configurations.
    
    ## Topic Policies
    
    ### Allow Cross-Account Publishing
    
    ```json
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "AWS": "arn:aws:iam::111111111111:root"
          },
          "Action": "sns:Publish",
          "Resource": "arn:aws:sns:us-east-1:123456789012:my-topic"
        }
      ]
    }
    ```
    
    ### Allow S3 Events
    
    ```json
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Service": "s3.amazonaws.com"
          },
          "Action": "sns:Publish",
          "Resource": "arn:aws:sns:us-east-1:123456789012:my-topic",
          "Condition": {
            "ArnLike": {
              "aws:SourceArn": "arn:aws:s3:::my-bucket"
            }
          }
        }
      ]
    }
    ```
    
    ### Allow CloudWatch Alarms
    
    ```json
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Service": "cloudwatch.amazonaws.com"
          },
          "Action": "sns:Publish",
          "Resource": "arn:aws:sns:us-east-1:123456789012:alerts-topic"
        }
      ]
    }
    ```
    
    ## Delivery Policies
    
    ### HTTP/HTTPS Retry Policy
    
    ```json
    {
      "http": {
        "defaultHealthyRetryPolicy": {
          "minDelayTarget": 1,
          "maxDelayTarget": 60,
          "numRetries": 50,
          "numMaxDelayRetries": 0,
          "numNoDelayRetries": 3,
          "numMinDelayRetries": 2,
          "backoffFunction": "exponential"
        },
        "disableSubscriptionOverrides": false,
        "defaultThrottlePolicy": {
          "maxReceivesPerSecond": 10
        }
      }
    }
    ```
    
    ### Configure Delivery Policy
    
    ```bash
    aws sns set-topic-attributes \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --attribute-name DeliveryPolicy \
      --attribute-value file://delivery-policy.json
    ```
    
    ## Dead-Letter Queues
    
    ### Configure DLQ for Subscription
    
    ```bash
    # Create DLQ
    aws sqs create-queue --queue-name sns-dlq
    
    # Get DLQ ARN
    DLQ_ARN=$(aws sqs get-queue-attributes \
      --queue-url https://sqs.us-east-1.amazonaws.com/123456789012/sns-dlq \
      --attribute-names QueueArn --query 'Attributes.QueueArn' --output text)
    
    # Set DLQ on subscription
    aws sns set-subscription-attributes \
      --subscription-arn arn:aws:sns:us-east-1:123456789012:my-topic:abc123 \
      --attribute-name RedrivePolicy \
      --attribute-value "{\"deadLetterTargetArn\":\"${DLQ_ARN}\"}"
    ```
    
    ## SMS Notifications
    
    ### Send SMS
    
    ```python
    import boto3
    
    sns = boto3.client('sns')
    
    # Direct publish to phone number
    sns.publish(
        PhoneNumber='+12025551234',
        Message='Your verification code is 123456',
        MessageAttributes={
            'AWS.SNS.SMS.SMSType': {
                'DataType': 'String',
                'StringValue': 'Transactional'  # or 'Promotional'
            },
            'AWS.SNS.SMS.SenderID': {
                'DataType': 'String',
                'StringValue': 'MyApp'
            }
        }
    )
    ```
    
    ### SMS Preferences
    
    ```bash
    aws sns set-sms-attributes \
      --attributes '{
        "DefaultSMSType": "Transactional",
        "DefaultSenderID": "MyApp",
        "MonthlySpendLimit": "100"
      }'
    ```
    
    ### Check SMS Status
    
    ```bash
    # Check spending
    aws sns get-sms-attributes \
      --attributes MonthlySpendLimit
    ```
    
    ## Mobile Push Notifications
    
    ### Create Platform Application
    
    ```bash
    # For iOS (APNS)
    aws sns create-platform-application \
      --name MyApp-iOS \
      --platform APNS \
      --attributes '{
        "PlatformCredential": "<private-key>",
        "PlatformPrincipal": "<certificate>"
      }'
    
    # For Android (FCM)
    aws sns create-platform-application \
      --name MyApp-Android \
      --platform GCM \
      --attributes '{
        "PlatformCredential": "<server-key>"
      }'
    ```
    
    ### Register Device Endpoint
    
    ```python
    import boto3
    
    sns = boto3.client('sns')
    
    # Register device
    response = sns.create_platform_endpoint(
        PlatformApplicationArn='arn:aws:sns:us-east-1:123456789012:app/GCM/MyApp-Android',
        Token='device-token-from-fcm'
    )
    endpoint_arn = response['EndpointArn']
    ```
    
    ### Send Push Notification
    
    ```python
    import boto3
    import json
    
    sns = boto3.client('sns')
    
    # Direct to device
    sns.publish(
        TargetArn=endpoint_arn,
        Message=json.dumps({
            'default': 'Default message',
            'GCM': json.dumps({
                'notification': {
                    'title': 'New Message',
                    'body': 'You have a new message'
                },
                'data': {
                    'message_id': '12345'
                }
            })
        }),
        MessageStructure='json'
    )
    ```
    
    ## Multi-Protocol Messages
    
    ### Protocol-Specific Messages
    
    ```python
    import boto3
    import json
    
    sns = boto3.client('sns')
    
    sns.publish(
        TopicArn='arn:aws:sns:us-east-1:123456789012:my-topic',
        Message=json.dumps({
            'default': 'Default message for all protocols',
            'email': 'Detailed email message with formatting',
            'sms': 'Short SMS msg',
            'lambda': json.dumps({'action': 'process', 'data': {...}}),
            'sqs': json.dumps({'queue_message': {...}}),
            'http': json.dumps({'webhook_payload': {...}})
        }),
        MessageStructure='json',
        Subject='Email Subject Line'
    )
    ```
    
    ## Raw Message Delivery
    
    ### Enable Raw Delivery for SQS
    
    By default, SNS wraps messages. Raw delivery sends just the message body.
    
    ```bash
    aws sns set-subscription-attributes \
      --subscription-arn arn:aws:sns:us-east-1:123456789012:my-topic:abc123 \
      --attribute-name RawMessageDelivery \
      --attribute-value true
    ```
    
    ### Message Format Comparison
    
    **Without raw delivery (wrapped):**
    ```json
    {
      "Type": "Notification",
      "MessageId": "...",
      "TopicArn": "arn:aws:sns:...",
      "Subject": "...",
      "Message": "{\"actual\":\"content\"}",
      "Timestamp": "...",
      "SignatureVersion": "1",
      "Signature": "...",
      "SigningCertURL": "...",
      "UnsubscribeURL": "..."
    }
    ```
    
    **With raw delivery:**
    ```json
    {"actual": "content"}
    ```
    
    ## FIFO Topics
    
    ### Create FIFO Topic
    
    ```bash
    aws sns create-topic \
      --name orders.fifo \
      --attributes FifoTopic=true,ContentBasedDeduplication=true
    ```
    
    ### Subscribe FIFO Queue to FIFO Topic
    
    ```bash
    # Create FIFO queue
    aws sqs create-queue \
      --queue-name order-processing.fifo \
      --attributes FifoQueue=true
    
    # Subscribe
    aws sns subscribe \
      --topic-arn arn:aws:sns:us-east-1:123456789012:orders.fifo \
      --protocol sqs \
      --notification-endpoint arn:aws:sqs:us-east-1:123456789012:order-processing.fifo
    ```
    
    ### Publish to FIFO Topic
    
    ```python
    sns.publish(
        TopicArn='arn:aws:sns:us-east-1:123456789012:orders.fifo',
        Message=json.dumps({'order_id': '12345'}),
        MessageGroupId='customer-abc',
        MessageDeduplicationId='order-12345-v1'
    )
    ```
    
    ## Monitoring
    
    ### CloudWatch Metrics
    
    Key metrics:
    - `NumberOfMessagesPublished`
    - `NumberOfNotificationsDelivered`
    - `NumberOfNotificationsFailed`
    - `PublishSize`
    
    ### Enable Delivery Status Logging
    
    ```bash
    # Create IAM role for logging
    aws sns set-topic-attributes \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --attribute-name LambdaSuccessFeedbackRoleArn \
      --attribute-value arn:aws:iam::123456789012:role/sns-delivery-status-role
    
    aws sns set-topic-attributes \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --attribute-name LambdaFailureFeedbackRoleArn \
      --attribute-value arn:aws:iam::123456789012:role/sns-delivery-status-role
    
    # Sample percentage (0-100)
    aws sns set-topic-attributes \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --attribute-name LambdaSuccessFeedbackSampleRate \
      --attribute-value 100
    ```
    
    ### Alarm for Failed Deliveries
    
    ```bash
    aws cloudwatch put-metric-alarm \
      --alarm-name "SNS-DeliveryFailures" \
      --metric-name NumberOfNotificationsFailed \
      --namespace AWS/SNS \
      --dimensions Name=TopicName,Value=my-topic \
      --statistic Sum \
      --period 60 \
      --threshold 1 \
      --comparison-operator GreaterThanOrEqualToThreshold \
      --evaluation-periods 1 \
      --alarm-actions arn:aws:sns:us-east-1:123456789012:alerts-topic
    ```
    
  • SKILL.md 9.6 KB
    ---
    name: sns
    description: AWS SNS notification service for pub/sub messaging. Use when creating topics, managing subscriptions, configuring message filtering, sending notifications, or setting up mobile push.
    last_updated: "2026-01-07"
    doc_source: https://docs.aws.amazon.com/sns/latest/dg/
    ---
    
    # AWS SNS
    
    Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service for application-to-application (A2A) and application-to-person (A2P) communication.
    
    ## Table of Contents
    
    - [Core Concepts](#core-concepts)
    - [Common Patterns](#common-patterns)
    - [CLI Reference](#cli-reference)
    - [Best Practices](#best-practices)
    - [Troubleshooting](#troubleshooting)
    - [References](#references)
    
    ## Core Concepts
    
    ### Topics
    
    Named channels for publishing messages. Publishers send to topics, subscribers receive from topics.
    
    ### Topic Types
    
    | Type | Description | Use Case |
    |------|-------------|----------|
    | **Standard** | Best-effort ordering, at-least-once | Most use cases |
    | **FIFO** | Strict ordering, exactly-once | Order-sensitive |
    
    ### Subscription Protocols
    
    | Protocol | Description |
    |----------|-------------|
    | **Lambda** | Invoke Lambda function |
    | **SQS** | Send to SQS queue |
    | **HTTP/HTTPS** | POST to endpoint |
    | **Email** | Send email |
    | **SMS** | Send text message |
    | **Application** | Mobile push notification |
    
    ### Message Filtering
    
    Route messages to specific subscribers based on message attributes.
    
    ## Common Patterns
    
    ### Create Topic and Subscribe
    
    **AWS CLI:**
    
    ```bash
    # Create standard topic
    aws sns create-topic --name my-topic
    
    # Create FIFO topic
    aws sns create-topic \
      --name my-topic.fifo \
      --attributes FifoTopic=true
    
    # Subscribe Lambda
    aws sns subscribe \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --protocol lambda \
      --notification-endpoint arn:aws:lambda:us-east-1:123456789012:function:my-function
    
    # Subscribe SQS
    aws sns subscribe \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --protocol sqs \
      --notification-endpoint arn:aws:sqs:us-east-1:123456789012:my-queue
    
    # Subscribe email
    aws sns subscribe \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --protocol email \
      --notification-endpoint user@example.com
    ```
    
    **boto3:**
    
    ```python
    import boto3
    
    sns = boto3.client('sns')
    
    # Create topic
    response = sns.create_topic(Name='my-topic')
    topic_arn = response['TopicArn']
    
    # Subscribe Lambda
    sns.subscribe(
        TopicArn=topic_arn,
        Protocol='lambda',
        Endpoint='arn:aws:lambda:us-east-1:123456789012:function:my-function'
    )
    
    # Subscribe SQS with filter
    sns.subscribe(
        TopicArn=topic_arn,
        Protocol='sqs',
        Endpoint='arn:aws:sqs:us-east-1:123456789012:order-queue',
        Attributes={
            'FilterPolicy': '{"event_type": ["order_created", "order_updated"]}'
        }
    )
    ```
    
    ### Publish Messages
    
    ```python
    import boto3
    import json
    
    sns = boto3.client('sns')
    topic_arn = 'arn:aws:sns:us-east-1:123456789012:my-topic'
    
    # Simple publish
    sns.publish(
        TopicArn=topic_arn,
        Message='Hello, World!',
        Subject='Notification'
    )
    
    # Publish with attributes (for filtering)
    sns.publish(
        TopicArn=topic_arn,
        Message=json.dumps({'order_id': '12345', 'status': 'created'}),
        MessageAttributes={
            'event_type': {
                'DataType': 'String',
                'StringValue': 'order_created'
            },
            'priority': {
                'DataType': 'Number',
                'StringValue': '1'
            }
        }
    )
    
    # Publish to FIFO topic
    sns.publish(
        TopicArn='arn:aws:sns:us-east-1:123456789012:my-topic.fifo',
        Message=json.dumps({'order_id': '12345'}),
        MessageGroupId='order-12345',
        MessageDeduplicationId='unique-id'
    )
    ```
    
    ### Message Filtering
    
    ```bash
    # Add filter policy to subscription
    aws sns set-subscription-attributes \
      --subscription-arn arn:aws:sns:us-east-1:123456789012:my-topic:abc123 \
      --attribute-name FilterPolicy \
      --attribute-value '{
        "event_type": ["order_created"],
        "priority": [{"numeric": [">=", 1]}]
      }'
    ```
    
    Filter policy examples:
    
    ```json
    // Exact match
    {"event_type": ["order_created", "order_updated"]}
    
    // Prefix match
    {"customer_id": [{"prefix": "PREMIUM-"}]}
    
    // Numeric comparison
    {"price": [{"numeric": [">=", 100, "<=", 500]}]}
    
    // Exists check
    {"customer_id": [{"exists": true}]}
    
    // Anything but
    {"event_type": [{"anything-but": ["deleted"]}]}
    
    // Combined
    {
      "event_type": ["order_created"],
      "region": ["us-east", "us-west"],
      "priority": [{"numeric": [">=", 1]}]
    }
    ```
    
    ### Fan-Out Pattern (SNS to Multiple SQS)
    
    ```python
    import boto3
    import json
    
    sns = boto3.client('sns')
    sqs = boto3.client('sqs')
    
    # Create topic
    topic = sns.create_topic(Name='orders-topic')
    topic_arn = topic['TopicArn']
    
    # Create queues for different processors
    queues = {
        'analytics': sqs.create_queue(QueueName='order-analytics')['QueueUrl'],
        'fulfillment': sqs.create_queue(QueueName='order-fulfillment')['QueueUrl'],
        'notification': sqs.create_queue(QueueName='order-notification')['QueueUrl']
    }
    
    # Subscribe each queue
    for name, queue_url in queues.items():
        queue_arn = sqs.get_queue_attributes(
            QueueUrl=queue_url,
            AttributeNames=['QueueArn']
        )['Attributes']['QueueArn']
    
        sns.subscribe(
            TopicArn=topic_arn,
            Protocol='sqs',
            Endpoint=queue_arn
        )
    
    # One publish reaches all queues
    sns.publish(
        TopicArn=topic_arn,
        Message=json.dumps({'order_id': '12345', 'total': 99.99})
    )
    ```
    
    ### Lambda Permission for SNS
    
    ```bash
    aws lambda add-permission \
      --function-name my-function \
      --statement-id sns-trigger \
      --action lambda:InvokeFunction \
      --principal sns.amazonaws.com \
      --source-arn arn:aws:sns:us-east-1:123456789012:my-topic
    ```
    
    ## CLI Reference
    
    ### Topic Management
    
    | Command | Description |
    |---------|-------------|
    | `aws sns create-topic` | Create topic |
    | `aws sns delete-topic` | Delete topic |
    | `aws sns list-topics` | List topics |
    | `aws sns get-topic-attributes` | Get topic settings |
    | `aws sns set-topic-attributes` | Update topic settings |
    
    ### Subscriptions
    
    | Command | Description |
    |---------|-------------|
    | `aws sns subscribe` | Create subscription |
    | `aws sns unsubscribe` | Remove subscription |
    | `aws sns list-subscriptions` | List all subscriptions |
    | `aws sns list-subscriptions-by-topic` | List topic subscriptions |
    | `aws sns confirm-subscription` | Confirm pending subscription |
    
    ### Publishing
    
    | Command | Description |
    |---------|-------------|
    | `aws sns publish` | Publish message |
    
    ## Best Practices
    
    ### Reliability
    
    - **Use SQS for durability** — SNS is push-based, SQS queues messages
    - **Implement retries** for HTTP/HTTPS endpoints
    - **Configure DLQ** for failed deliveries
    - **Use FIFO topics** for ordering requirements
    
    ### Security
    
    - **Use topic policies** to control access
    - **Enable encryption** with SSE
    - **Use VPC endpoints** for private access
    
    ```bash
    # Enable SSE
    aws sns set-topic-attributes \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --attribute-name KmsMasterKeyId \
      --attribute-value alias/my-key
    ```
    
    ### Cost Optimization
    
    - **Use message filtering** to reduce unnecessary deliveries
    - **Batch operations** where possible
    - **Monitor and clean up** unused topics/subscriptions
    
    ### Message Design
    
    - **Keep messages small** (256 KB limit)
    - **Use message attributes** for routing
    - **Include correlation IDs** for tracing
    
    ## Troubleshooting
    
    ### Subscription Not Receiving Messages
    
    **Check:**
    1. Subscription is confirmed (not pending)
    2. Filter policy matches message attributes
    3. Target permissions (Lambda, SQS)
    
    ```bash
    # Check subscription status
    aws sns list-subscriptions-by-topic \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic
    
    # Check subscription attributes
    aws sns get-subscription-attributes \
      --subscription-arn arn:aws:sns:us-east-1:123456789012:my-topic:abc123
    ```
    
    ### HTTP Endpoint Not Working
    
    **Debug:**
    
    ```bash
    # Check delivery status logging
    aws sns set-topic-attributes \
      --topic-arn arn:aws:sns:us-east-1:123456789012:my-topic \
      --attribute-name DeliveryPolicy \
      --attribute-value '{
        "http": {
          "defaultHealthyRetryPolicy": {
            "minDelayTarget": 20,
            "maxDelayTarget": 20,
            "numRetries": 3,
            "numMaxDelayRetries": 0,
            "numNoDelayRetries": 0,
            "numMinDelayRetries": 0,
            "backoffFunction": "linear"
          }
        }
      }'
    ```
    
    ### Messages Not Matching Filter
    
    **Verify:**
    - Message attributes are set (not in body)
    - Attribute types match (String vs Number)
    - Filter policy syntax is correct
    
    ```python
    # Correct: attributes must be message attributes
    sns.publish(
        TopicArn=topic_arn,
        Message='body content',
        MessageAttributes={
            'event_type': {
                'DataType': 'String',
                'StringValue': 'order_created'  # This is filtered
            }
        }
    )
    
    # Wrong: this won't be filtered
    sns.publish(
        TopicArn=topic_arn,
        Message=json.dumps({'event_type': 'order_created'})  # Not filtered
    )
    ```
    
    ### SQS Not Receiving from SNS
    
    **Check SQS queue policy:**
    
    ```json
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {"Service": "sns.amazonaws.com"},
          "Action": "sqs:SendMessage",
          "Resource": "arn:aws:sqs:us-east-1:123456789012:my-queue",
          "Condition": {
            "ArnEquals": {
              "aws:SourceArn": "arn:aws:sns:us-east-1:123456789012:my-topic"
            }
          }
        }
      ]
    }
    ```
    
    ## References
    
    - [SNS Developer Guide](https://docs.aws.amazon.com/sns/latest/dg/)
    - [SNS API Reference](https://docs.aws.amazon.com/sns/latest/api/)
    - [SNS CLI Reference](https://docs.aws.amazon.com/cli/latest/reference/sns/)
    - [boto3 SNS](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/sns.html)
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related