Skip to main content

CDK Constructs for AWS S3 to AWS Step Functions integration

Project description

aws-s3-stepfunctions module

---

Stability: Experimental

All classes are under active development and subject to non-backward compatible changes or removal in any future version. These are not subject to the Semantic Versioning model. This means that while you may use them, you may need to update your source code when upgrading to a newer version of this package.


Reference Documentation: https://docs.aws.amazon.com/solutions/latest/constructs/
Language Package
Python Logo Python aws_solutions_constructs.aws_s3_stepfunctions
Typescript Logo Typescript @aws-solutions-constructs/aws-s3-stepfunctions
Java Logo Java software.amazon.awsconstructs.services.s3stepfunctions

This AWS Solutions Construct implements an Amazon S3 bucket connected to an AWS Step Functions.

Note - This construct uses Amazon EventBridge (Amazon CloudWatch Events) to trigger AWS Step Functions State Machine executions. EventBridge is more flexible, but triggering executions with S3 Event Notifications has less latency and is more cost effective. If cost and/or latency is an issue, you should consider deploying aws-s3-lambda and aws-lambda-stepfunctions in place of this construct.

Here is a minimal deployable pattern definition in Typescript:

# Example automatically generated from non-compiling source. May contain errors.
import { S3ToStepfunctions, S3ToStepfunctionsProps } from '@aws-solutions-constructs/aws-s3-stepfunctions';
import * as stepfunctions from '@aws-cdk/aws-stepfunctions';

const startState = new stepfunctions.Pass(stack, 'StartState');

new S3ToStepfunctions(this, 'test-s3-stepfunctions-stack', {
    stateMachineProps: {
      definition: startState
    }
});

Initializer

new S3ToStepfunctions(scope: Construct, id: string, props: S3ToStepfunctionsProps);

Parameters

Pattern Construct Props

Name Type Description
existingBucketObj? s3.IBucket Existing instance of S3 Bucket object. If this is provided, then also providing bucketProps is an error.
bucketProps? s3.BucketProps Optional user provided props to override the default props for the S3 Bucket.
stateMachineProps sfn.StateMachineProps User provided props to override the default props for sfn.StateMachine.
eventRuleProps? events.RuleProps Optional user provided eventRuleProps to override the defaults.
deployCloudTrail? boolean Whether to deploy a Trail in AWS CloudTrail to log API events in Amazon S3. Defaults to true.
createCloudWatchAlarms boolean Whether to create recommended CloudWatch alarms.
logGroupProps? logs.LogGroupProps Optional user provided props to override the default props for for the CloudWatchLogs LogGroup.
loggingBucketProps? s3.BucketProps Optional user provided props to override the default props for the S3 Logging Bucket.
logS3AccessLogs? boolean Whether to turn on Access Logging for the S3 bucket. Creates an S3 bucket with associated storage costs for the logs. Enabling Access Logging is a best practice. default - true

Pattern Properties

Name Type Description
stateMachine sfn.StateMachine Returns an instance of sfn.StateMachine created by the construct.
stateMachineLogGroup logs.ILogGroup Returns an instance of the ILogGroup created by the construct for StateMachine.
cloudwatchAlarms? cloudwatch.Alarm[] Returns a list of cloudwatch.Alarm created by the construct.
s3Bucket? s3.Bucket Returns an instance of the s3.Bucket created by the construct.
s3LoggingBucket? s3.Bucket Returns an instance of s3.Bucket created by the construct as the logging bucket for the primary bucket.
cloudtrail cloudtrail.Trail Returns an instance of the cloudtrail.Trail created by the construct.
cloudtrailBucket s3.Bucket Returns an instance of the s3.Bucket created by the construct for CloudTrail.
cloudtrailLoggingBucket s3.Bucket Returns an instance of s3.Bucket created by the construct as the logging bucket for the primary CloudTrail bucket.
s3BucketInterface s3.IBucket Returns an instance of s3.IBucket created by the construct.

Default settings

Out of the box implementation of the Construct without any override will set the following defaults:

Amazon S3 Bucket

  • Configure Access logging for S3 Bucket
  • Enable server-side encryption for S3 Bucket using AWS managed KMS Key
  • Enforce encryption of data in transit
  • Turn on the versioning for S3 Bucket
  • Don't allow public access for S3 Bucket
  • Retain the S3 Bucket when deleting the CloudFormation stack
  • Applies Lifecycle rule to move noncurrent object versions to Glacier storage after 90 days

AWS CloudTrail

  • Configure a Trail in AWS CloudTrail to log API events in Amazon S3 related to the Bucket created by the Construct

Amazon CloudWatch Events Rule

  • Grant least privilege permissions to CloudWatch Events to trigger the Lambda Function

AWS Step Functions

  • Enable CloudWatch logging for API Gateway
  • Deploy best practices CloudWatch Alarms for the Step Functions

Architecture

Architecture Diagram


© Copyright 2021 Amazon.com, Inc. or its affiliates. All Rights Reserved.

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file aws-solutions-constructs.aws-s3-stepfunctions-1.133.0.tar.gz.

File metadata

File hashes

Hashes for aws-solutions-constructs.aws-s3-stepfunctions-1.133.0.tar.gz
Algorithm Hash digest
SHA256 a496fdd582eb06d5be025b1a7608277a0589b360fb94017590902921c5d7acda
MD5 8c053fc106bbfde69dc22621a979da36
BLAKE2b-256 0baf3d8e47312b44d24559ca6c2a0b5fdb87b893982d7d1acf468fa34d7aa37e

See more details on using hashes here.

File details

Details for the file aws_solutions_constructs.aws_s3_stepfunctions-1.133.0-py3-none-any.whl.

File metadata

File hashes

Hashes for aws_solutions_constructs.aws_s3_stepfunctions-1.133.0-py3-none-any.whl
Algorithm Hash digest
SHA256 4980108a058c7d654dcf93758455695946c5c0dcb035eba1d1c7820decd59767
MD5 4abf08b6a7e87b127f29991bbd4e56f6
BLAKE2b-256 4d5165ca8d4e50f6c095a60b5dd4e03b2f2dd2ecc3dee73f84b57a05ddf14f4a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page