Refer AWS Documentation here
When a rule runs in EventBridge, all of the targets associated with the rule are invoked.
Rules can invoke AWS Lambda functions, publish to Amazon SNS topics or relay the event to Kinesis streams. To make API calls against the resources you own, EventBridge needs appropriate permissions.
EventBridge uses Resource-based policies for:
1. Lambda
2. Amazon SNS
3. Amazon SQS
4. Amazon CloudWatch Logs
EventBridge uses Identity-based policies for:
Kinesis streams
AWS Lambda Permissions will look something like below:
{
"Effect": "Allow",
"Action": "lambda:InvokeFunction",
"Resource": "arn:aws:lambda:region:account-id:function:function-name",
"Principal": {
"Service": "events.amazonaws.com"
},
"Condition": {
"ArnLike": {
"AWS:SourceArn": "arn:aws:events:region:account-id:rule/rule-name"
}
},
"Sid": "InvokeLambdaFunction"
}
Amazon EventBridge is an AWS event-routing service where rules can invoke targets such as Lambda functions, Amazon SNS topics, Kinesis streams, and other AWS resources. The article explains that EventBridge requires appropriate permissions when making API calls against resources owned by the user. Its use of resource-based policies for Lambda, SNS, SQS, and CloudWatch Logs makes permission configuration an important part of an event-driven cloud architecture.
ReplyDeleteThe discussion of EventBridge rules, Lambda invocation, and resource-based permissions is directly relevant to Cloud Computing Projects for Final Year. The article specifically describes how an EventBridge rule can invoke a Lambda function and shows the structure of a Lambda permission policy containing the lambda:InvokeFunction action and the function resource ARN.