Files
kodekloud-engineer/terraform/task-19.md

2.8 KiB

Assignment

The Nautilus DevOps team needs to set up an SNS topic for sending notifications. They need to create an SNS topic with the following specifications:

  1. The topic name should be nautilus-notifications.

Use Terraform to create this SNS topic. The Terraform working directory is /home/bob/terraform. Create the main.tf file (do not create a different .tf file) to accomplish this task.

Note: Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.

Solution

SNS Topic — nautilus-notifications

Terraform solution to create a standard SNS topic.

main.tf

terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 6.0"
    }
  }
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_sns_topic" "nautilus_notifications" {
  name = "nautilus-notifications"
}

How to run

cd /home/bob/terraform
terraform init
terraform apply -auto-approve

How it works

aws_sns_topic

One resource is all this task needs. The name argument sets the topic name to nautilus-notifications exactly as required.

A few points on what's happening:

  • Standard topic by default. SNS has two topic classes: Standard (high throughput, best-effort ordering, at-least-once delivery) and FIFO (strict ordering, exactly-once, name must end in .fifo). Since the name has no .fifo suffix and fifo_topic isn't set, this creates a Standard topic — the right choice for general notifications.

  • A topic is just the pub/sub channel. Creating the topic gives you an endpoint that publishers send messages to. Nothing receives those messages until you add subscriptions (email, SMS, SQS, Lambda, HTTP, etc.). The task only asks for the topic itself, so no aws_sns_topic_subscription resources are included — those would be added later as delivery targets are decided.

  • No access policy specified. By default SNS attaches a policy allowing the topic owner (this account) to publish and manage it. That default is sufficient for the task; a custom policy would only be needed to grant cross-account or service-specific publish rights.

Sandbox note

Constrained lab environments permit basic SNS operations — standard topics like this one. Nothing advanced (FIFO, complex delivery policies) is in play, so the create proceeds without restriction.

Verify

TOPIC_ARN=$(aws sns list-topics \
  --query "Topics[?ends_with(TopicArn, ':nautilus-notifications')].TopicArn | [0]" \
  --output text)

echo "[$TOPIC_ARN]"

aws sns get-topic-attributes --topic-arn "$TOPIC_ARN" \
  --query 'Attributes.{Name:DisplayName,Arn:TopicArn,Owner:Owner}'

Expected — a topic ARN of the form arn:aws:sns:us-east-1:<account-id>:nautilus-notifications.