2.8 KiB
Assignment
The Nautilus DevOps team needs to set up an SNS topic for sending notifications. They need to create an SNS topic with the following specifications:
- The topic name should be nautilus-notifications.
Use Terraform to create this SNS topic. The Terraform working directory is /home/bob/terraform. Create the main.tf file (do not create a different .tf file) to accomplish this task.
Note: Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.
Solution
SNS Topic — nautilus-notifications
Terraform solution to create a standard SNS topic.
main.tf
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 6.0"
}
}
}
provider "aws" {
region = "us-east-1"
}
resource "aws_sns_topic" "nautilus_notifications" {
name = "nautilus-notifications"
}
How to run
cd /home/bob/terraform
terraform init
terraform apply -auto-approve
How it works
aws_sns_topic
One resource is all this task needs. The name argument sets the topic name to
nautilus-notifications exactly as required.
A few points on what's happening:
-
Standard topic by default. SNS has two topic classes: Standard (high throughput, best-effort ordering, at-least-once delivery) and FIFO (strict ordering, exactly-once, name must end in
.fifo). Since the name has no.fifosuffix andfifo_topicisn't set, this creates a Standard topic — the right choice for general notifications. -
A topic is just the pub/sub channel. Creating the topic gives you an endpoint that publishers send messages to. Nothing receives those messages until you add subscriptions (email, SMS, SQS, Lambda, HTTP, etc.). The task only asks for the topic itself, so no
aws_sns_topic_subscriptionresources are included — those would be added later as delivery targets are decided. -
No access policy specified. By default SNS attaches a policy allowing the topic owner (this account) to publish and manage it. That default is sufficient for the task; a custom
policywould only be needed to grant cross-account or service-specific publish rights.
Sandbox note
Constrained lab environments permit basic SNS operations — standard topics like this one. Nothing advanced (FIFO, complex delivery policies) is in play, so the create proceeds without restriction.
Verify
TOPIC_ARN=$(aws sns list-topics \
--query "Topics[?ends_with(TopicArn, ':nautilus-notifications')].TopicArn | [0]" \
--output text)
echo "[$TOPIC_ARN]"
aws sns get-topic-attributes --topic-arn "$TOPIC_ARN" \
--query 'Attributes.{Name:DisplayName,Arn:TopicArn,Owner:Owner}'
Expected — a topic ARN of the form
arn:aws:sns:us-east-1:<account-id>:nautilus-notifications.