IaC Bazaar
AWSLive-tested

SNS Topic with Subscriptions

SNS standard/FIFO topic with encryption, delivery policies, and SQS/Lambda/email subscriptions.

terraformAWS#aws

Compare Messaging & Pub/Sub across clouds →

Part of: AWS Production Landing Zone

aws-snsterraform v1.7

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-11 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o aws-sns-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/aws-sns/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle aws-sns-1.0.0.sigstore.json \
  aws-sns-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "da383ebbe6cc925e8301ad36fdb119845b2fcf075aa2b2d89f0b6b6d092049e3  aws-sns-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "sns" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-sns/aws"
  version = "1.0.0"
}

Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every Free module. This one is Basic, so its contract unlocks when you buy it.

Documentation

aws-sns

SNS standard or FIFO topic, encrypted at rest by default, with a TLS-only least-privilege topic policy and typed SQS / Lambda / HTTPS / email subscriptions. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0. FIFO naming (.fifo suffix) is automatic, and message signing defaults to SHA-256 (signature version 2).

Status: static-validated, live-test pending. Ships under live-test quarantine — validated with tofu fmt, tofu validate, and tflint. Real apply → publish → destroy against an AWS account is pending a cloud sandbox. Live testing will restrict subscriptions to SQS/Lambda endpoints, which auto-confirm; email/SMS/HTTP confirmations cannot be completed in automation.

What you get:

  • aws_sns_topic — standard or FIFO, always SSE-encrypted.
  • aws_sns_topic_policy — a generated TLS-only, allow-listed policy (override with a full policy JSON string if you need to).
  • aws_sns_topic_subscription — a typed map of subscriptions with filter policies and per-subscription redrive (DLQ) support.

Secure defaults

  • Encryption at rest always on: defaults to the AWS-managed alias/aws/sns key; pass a CMK via kms_master_key_id for full key control.
  • TLS-only topic policy: denies any sns:Publish/sns:Subscribe made over a non-TLS connection (aws:SecureTransport = false). The account owner keeps management rights; IAM publishers and AWS service publishers are allow-listed (services pinned to their aws:SourceArn), and cross-account subscribe is off unless you name accounts in subscriber_account_ids.
  • SHA-256 signing (signature_version = 2) by default.
  • Subscriptions support redrive to a DLQ so failed deliveries are not lost; use raw_message_delivery = true for SQS/HTTPS when you do not want the SNS envelope.

Provider pin

aws = {
  source  = "hashicorp/aws"
  version = ">= 6.0, < 7.0"
}

License

Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference unlock after purchase

The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.

  • Usage
  • Inputs
  • Outputs

Related modules