Showing posts with label aws cli. Show all posts
Showing posts with label aws cli. Show all posts
AWS SNS with Dynamodb and Lambda
Recently, I tried to create an AWS Lambda trigger to process a stream from a DynamoDB table which triggers SNS notification to subscribers.
Think about a scenario that you have deployed and a website in which a user fille the feedback form and you want to get an email notification for every feedback that has been filled.
So, this is where AWS SNS, Dynamodb, lambda, and API gateway comes in.
Please find my previous tutorial on how to deploy the serverless website here
In this case, I used Terraform and AWS CLI as usual.
Note: Just follow up the tutorial, I'll mention when to use AWS CLI (only for SNS Subscription)
Requirement:
Install all nessacery things to run Terraform and AWS CLI.
Steps
Step 1: Create a DynamoDB Table with a Stream Enabled
Step 2: Create a Lambda Execution Role
Step 3: Create an Amazon SNS Topic
Step 4: Create and Test a Lambda Function
Step 5: Create and Test a Trigger
Step 1: Create a DynamoDB Table with a Stream Enabled
Create a DynamoDB table (mywebsite) to store all of the barks from Woofer users. The primary key as email (partition key) attribute type string.
[fayasak@controller]$ cat iam.tfresource "aws_dynamodb_table" "dynamodb"{ name="mywebsite" hash_key="email" attribute=[ { name="email" type="s" } ] stream_enabled = "true" stream_view_type ="NEW_AND_OLD_IMAGES"}
Step 2: Create a Lambda Execution Role
Create an AWS Identity and Access Management (IAM) role (lamda-dynamodb) and assign permissions to it. This role is used by the Lambda function that you create later.
Also create a policy for the role. The policy contains all of the permissions that the Lambda function needs at runtime.
[fayasak@controller]$ cat dynamo.tfresouce "aws_iam_role" "lamda-iam"{ #role name name="lamda-dynamodb" #assume role to a services assume_role_policy =<<EOF { "Version": "2012-10-17", "Statement": [ { "Action": "sts:AssumeRole", "Principal": { "Service": "lambda.amazonaws.com" }, "Effect": "Allow", "Sid": "" } ] }EOF}
Also Create an inline policy with the following contents. (Replace region and accountID with your AWS Region and account ID where 4444 is placed.)
[fayasak@controller]$ cat iam.tfresource "aws_iam_role_policy" "dynamodb-lambda-policy"{ name = "dynamodb_lambda_policy" role = "${aws_iam_role.lamda-iam.id}"
policy = <<EOF { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "dynamodb:DescribeStream", "dynamodb:GetRecords", "dynamodb:GetShardIterator", "dynamodb:ListStreams" ], "Resource": "${aws_dynamodb_table.dynamodb.arn}" }, { "Effect": "Allow", "Action": "lambda:InvokeFunction", "Resource": "${aws_lamda_function.lambda_test.arn}" }, { "Effect": "Allow", "Action": [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents" ], "Resource": ":aws:logs:eu-west-1:444-444444:*" }, { "Effect": "Allow", "Action": [ "sns:Publish" ], "Resource": [ "*" ] } ] } EOF}
The policy has four statements that allow us to do the following:
1. Execute a Lambda function (lambda_dbstream). You create the function later in this tutorial.
2.Access Amazon CloudWatch Logs. The Lambda function writes diagnostics to CloudWatch Logs at runtime.
3. Read data from the DynamoDB stream for mywebsite .
4. Publish messages to Amazon SNS (since we deploying this via AWS CLI I cannot pass the resource ARN to it. though I required you to manually add the ARN name above ).
Host a Website on AWS S3
Some websites are becoming static websites which means they run without server-side code and consist of only HTML, CSS and JavaScript. Since there's no server-side code, there is no reason to host them on a traditional server.
"If the things are open and you have an intense" you can learn things! with my intense to learn, I tried and deployed my static website on the s3 bucket. Here's the way I did,
Note: when you create an S3 bucket Name is global. So, have to consider creating a unique name.
if your Domain name is www.fayasak.com. you must create the bucket exactly like your domain name
I am going to use AWS CLI for deployment.
if you did not install AWS CLI click the URL
1. Create the bucket
if you did not install AWS CLI click the URL
1. Create the bucket
[fayasak@controller]$ aws s3api create-bucket --bucket fayasak.com --acl public-read
2. Amazon needs to know what is our index document and error document. Though, type AWS S3 API CLI command to enable the "Static website hosting" property of our bucket along with our index and error document
3. Now you can access the website via http://www.f.com.s3-webyasak.com.s3-wasite-us-east-1.amazonaws.com/.
since I did not upload my files and policy my website show error.
let's upload my website and apply a publically accessible bucket policy to my website.
1. create and apply policy the bucket
Note: "Principal": { "AWS": "*" } lines opens up our bucket to the world
2. Uploading Our Static Website
[fayasak@controller]$ aws s3 website s3://www.fayasak.com/ --index-document index.html --error-document 404.html3. Now you can access the website via http://www.f.com.s3-webyasak.com.s3-wasite-us-east-1.amazonaws.com/.
since I did not upload my files and policy my website show error.
let's upload my website and apply a publically accessible bucket policy to my website.
1. create and apply policy the bucket
[fayasak@controller]$ cat policy.jason{
"Version": "2008-10-17",
"Id": "PolicyForPublicWebsiteContent",
"Statement": [
{
"Sid": "PublicReadGetObject",
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::www.fayasak.com/*"
}
]
}# Apply policy to the bucket[fayasak@controller]$ s3api put-bucket-policy --bucket www.fayasak.com --policy file://policy.jsonNote: "Principal": { "AWS": "*" } lines opens up our bucket to the world
2. Uploading Our Static Website
[fayasak@controller]$ aws s3 cp ./website/ s3://www.fayasak.com
3. Test the website
[fayasak@controller]$ curl www.fayasak.com.s3-website-us-east-1.amazonaws.com
[fayasak@controller]$ curl www.fayasak.com.s3-website-us-east-1.amazonaws.com
Subscribe to:
Posts (Atom)
