SNS Topic with Subscriptions
SNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.
Compare Messaging & Pub/Sub across clouds →
Part of: AWS Production Landing Zone
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-11 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o aws-sns-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/aws-sns/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle aws-sns-1.0.0.sigstore.json \
aws-sns-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "da383ebbe6cc925e8301ad36fdb119845b2fcf075aa2b2d89f0b6b6d092049e3 aws-sns-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "sns" {
source = "www.iac-bazaar.com/iac-bazaar/aws-sns/aws"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Basic, so its contract unlocks when you buy it.
Documentation
aws-sns
SNS standard or FIFO topic, encrypted at rest by default, with a TLS-only
least-privilege topic policy and typed SQS / Lambda / HTTPS / email
subscriptions. Works with Terraform and OpenTofu (>= 1.6), AWS provider
>= 6.0, < 7.0. FIFO naming (.fifo suffix) is automatic, and message signing
defaults to SHA-256 (signature version 2).
Status: static-validated, live-test pending. Ships under live-test quarantine — validated with
tofu fmt,tofu validate, andtflint. Real apply → publish → destroy against an AWS account is pending a cloud sandbox. Live testing will restrict subscriptions to SQS/Lambda endpoints, which auto-confirm; email/SMS/HTTP confirmations cannot be completed in automation.
What you get:
aws_sns_topic— standard or FIFO, always SSE-encrypted.aws_sns_topic_policy— a generated TLS-only, allow-listed policy (override with a fullpolicyJSON string if you need to).aws_sns_topic_subscription— a typed map of subscriptions with filter policies and per-subscription redrive (DLQ) support.
Secure defaults
- Encryption at rest always on: defaults to the AWS-managed
alias/aws/snskey; pass a CMK viakms_master_key_idfor full key control. - TLS-only topic policy: denies any
sns:Publish/sns:Subscribemade over a non-TLS connection (aws:SecureTransport = false). The account owner keeps management rights; IAM publishers and AWS service publishers are allow-listed (services pinned to theiraws:SourceArn), and cross-account subscribe is off unless you name accounts insubscriber_account_ids. - SHA-256 signing (
signature_version = 2) by default. - Subscriptions support redrive to a DLQ so failed deliveries are not lost;
use
raw_message_delivery = truefor SQS/HTTPS when you do not want the SNS envelope.
Provider pin
aws = {
source = "hashicorp/aws"
version = ">= 6.0, < 7.0"
}
License
Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work
(not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
Related modules
EventBridge Bus, Rule & Target
A custom EventBridge event bus, a pattern-filtered rule, and a target wired end-to-end - encryption at rest always on, least-privilege log delivery, and a 24h retry policy with optional DLQ.
Kinesis Data Stream (on-demand)
A Kinesis Data Stream with KMS encryption at rest on by default and ON_DEMAND capacity (no shard math), plus optional enhanced fan-out consumers and IAM-only access.
MSK Serverless (Apache Kafka)
An MSK Serverless Apache Kafka cluster with no brokers to size - SASL/IAM authentication only, encryption in transit and at rest always on, multi-AZ placement, and a locked-down security group.
SES v2 Sending Stack
An SES v2 sending stack - a configuration set with an optional domain/email identity (Easy DKIM) - with TLS required, bounce/complaint suppression, and reputation metrics to CloudWatch.
SQS Queue with DLQ
SQS standard/FIFO queue with dead-letter queue, redrive policy, SSE, and least-privilege queue policy.
Pub/Sub Topics & Subscriptions
Topics with schemas, push/pull/BigQuery subscriptions, dead-letter queues and retry policies preconfigured.