问题描述
在terraform中,尝试将S3存储桶作为我的lambda的触发器并提供权限。对于此用例,创建S3资源并尝试在触发逻辑中引用该lambda函数。但是,当我引用代码失败时,出现以下错误。请帮助我解决此问题。
#########################################
# Creating Lambda resource
###########################################
resource "aws_lambda_function" "test_lambda" {
filename = "output/welcome.zip"
function_name = var.function_name
role = var.role_name
handler = var.handler_name
runtime = var.run_time
}
######################################################
# Creating s3 resource for invoking to lambda function
######################################################
resource "aws_s3_bucket" "bucket" {
bucket = "source-bucktet-testing"
}
#####################################################################
# Adding S3 bucket as trigger to my lambda and giving the permissions
#####################################################################
resource "aws_s3_bucket_notification" "aws-lambda-trigger" {
bucket = aws_s3_bucket.bucket.id
lambda_function {
lambda_function_arn = aws_lambda_function.test_lambda.arn
events = ["s3:ObjectCreated:*"]
filter_prefix = "file-prefix"
filter_suffix = "file-extension"
}
}
resource "aws_lambda_permission" "test" {
statement_id = "AllowS3Invoke"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.test_lambda.function_name
principal = "s3.amazonaws.com"
source_arn = "arn:aws:s3:::aws_s3_bucket.bucket.id"
}
错误消息:
Error: Error putting S3 notification configuration: InvalidArgument: Unable to validate the following destination configurations
status code: 400,request id: 8D16EE1EF8FC0E63,host id: PlzqurwmHo3hDJdr0nUhOGuJKnghOBCtMImZ+8fEFX3JPjKV2M47UZuJ5Z26FalKxmoF1Xl8lag=
解决方法
您在source_arn
中的aws_lambda_permission
不正确。应该是:
source_arn = aws_s3_bucket.bucket.arn
目前,您的source_arn
实际上是字符串“ arn:aws:s3 ::: aws_s3_bucket.bucket.id”,这是不正确的。