Skip to main content

CDK Constructs for AWS S3 to AWS Step Functions integration

Project description

aws-s3-stepfunctions module

---

Stability: Experimental

All classes are under active development and subject to non-backward compatible changes or removal in any future version. These are not subject to the Semantic Versioning model. This means that while you may use them, you may need to update your source code when upgrading to a newer version of this package.


Reference Documentation: https://docs.aws.amazon.com/solutions/latest/constructs/
Language Package
Python Logo Python aws_solutions_constructs.aws_s3_stepfunctions
Typescript Logo Typescript @aws-solutions-constructs/aws-s3-stepfunctions
Java Logo Java software.amazon.awsconstructs.services.s3stepfunctions

Overview

This AWS Solutions Construct implements an Amazon S3 bucket connected to an AWS Step Functions.

Note - This constructs sends S3 Event Notification to EventBridge, then triggers AWS Step Functions State Machine executions from EventBridge.

An alternative architecture can be built that triggers a Lambda function from S3 Event notifications using aws-s3-lambda and aws-lambda-stepfunctions. Channelling the S3 events through Lambda is less flexible than EventBridge, but is more cost effective and has lower latency.

Here is a minimal deployable pattern definition:

Typescript

import { Construct } from 'constructs';
import { Stack, StackProps } from 'aws-cdk-lib';
import { S3ToStepfunctions, S3ToStepfunctionsProps } from '@aws-solutions-constructs/aws-s3-stepfunctions';
import * as stepfunctions from 'aws-cdk-lib/aws-stepfunctions';

const startState = new stepfunctions.Pass(this, 'StartState');

new S3ToStepfunctions(this, 'test-s3-stepfunctions-stack', {
    stateMachineProps: {
      definition: startState
    }
});

Python

from aws_solutions_constructs.aws_s3_stepfunctions import S3ToStepfunctions
from aws_cdk import (
    aws_stepfunctions as stepfunctions,
    Stack
)
from constructs import Construct

start_state = stepfunctions.Pass(self, 'start_state')

S3ToStepfunctions(
    self, 'test_s3_stepfunctions_stack',
    state_machine_props=stepfunctions.StateMachineProps(
        definition=start_state)
)

Java

import software.constructs.Construct;

import software.amazon.awscdk.Stack;
import software.amazon.awscdk.StackProps;
import software.amazon.awscdk.services.stepfunctions.*;
import software.amazon.awsconstructs.services.s3stepfunctions.*;

final Pass startState = new Pass(this, "StartState");

new S3ToStepfunctions(this, "test_s3_stepfunctions_stack",
        new S3ToStepfunctionsProps.Builder()
                .stateMachineProps(new StateMachineProps.Builder()
                        .definition(startState)
                        .build())
                .build());

Pattern Construct Props

Name Type Description
existingBucketObj? s3.IBucket Existing instance of S3 Bucket object. If this is provided, then also providing bucketProps is an error. The existing bucket must have EventBridge enabled for this to work.
bucketProps? s3.BucketProps Optional user provided props to override the default props for the S3 Bucket.
stateMachineProps sfn.StateMachineProps User provided props to override the default props for sfn.StateMachine.
eventRuleProps? events.RuleProps Optional user provided eventRuleProps to override the defaults.
deployCloudTrail? boolean Whether to deploy a Trail in AWS CloudTrail to log API events in Amazon S3. Defaults to true. This is now deprecated and ignored because the construct no longer needs CloudTrail since it uses S3 Event Notifications.
createCloudWatchAlarms boolean Whether to create recommended CloudWatch alarms.
logGroupProps? logs.LogGroupProps Optional user provided props to override the default props for for the CloudWatchLogs LogGroup.
loggingBucketProps? s3.BucketProps Optional user provided props to override the default props for the S3 Logging Bucket.
logS3AccessLogs? boolean Whether to turn on Access Logging for the S3 bucket. Creates an S3 bucket with associated storage costs for the logs. Enabling Access Logging is a best practice. default - true

Pattern Properties

Name Type Description
stateMachine sfn.StateMachine Returns an instance of sfn.StateMachine created by the construct.
stateMachineLogGroup logs.ILogGroup Returns an instance of the ILogGroup created by the construct for StateMachine.
cloudwatchAlarms? cloudwatch.Alarm[] Returns a list of cloudwatch.Alarm created by the construct.
s3Bucket? s3.Bucket Returns an instance of the s3.Bucket created by the construct.
s3LoggingBucket? s3.Bucket Returns an instance of s3.Bucket created by the construct as the logging bucket for the primary bucket.
s3BucketInterface s3.IBucket Returns an instance of s3.IBucket created by the construct.

Note - with the release of Enable EventBridge for Amazon S3, AWS CloudTrail is no longer required to implement this construct. Because of this, the following properties have been removed:

  • cloudtrail
  • cloudtrailBucket
  • cloudtrailLoggingBucket

Default settings

Out of the box implementation of the Construct without any override will set the following defaults:

Amazon S3 Bucket

  • Enable EventBridge to send events from the S3 Bucket
  • Configure Access logging for S3 Bucket
  • Enable server-side encryption for S3 Bucket using AWS managed KMS Key
  • Enforce encryption of data in transit
  • Turn on the versioning for S3 Bucket
  • Don't allow public access for S3 Bucket
  • Retain the S3 Bucket when deleting the CloudFormation stack
  • Applies Lifecycle Rule to move noncurrent object versions to Glacier storage after 90 days

AWS S3 Event Notification

  • Enable S3 to send events to EventBridge when an object is created.

Amazon CloudWatch Events Rule

  • Grant least privilege permissions to CloudWatch Events to trigger the Lambda Function

AWS Step Functions

  • Enable CloudWatch logging for API Gateway
  • Deploy best practices CloudWatch Alarms for the Step Functions

Architecture

Architecture Diagram


© Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

File details

Details for the file aws_solutions_constructs_aws_s3_stepfunctions-2.69.0.tar.gz.

File metadata

File hashes

Hashes for aws_solutions_constructs_aws_s3_stepfunctions-2.69.0.tar.gz
Algorithm Hash digest
SHA256 62d7710c32ee4db1c699dedd2a265bdd947fe939f75be13274eebf05da3441a9
MD5 bb32d1b31fff0ecfa9b082598312a044
BLAKE2b-256 963bde3378ab90b84b6f1549d21da83f5aaea49faee4e544a10d4e164ede59f6

See more details on using hashes here.

File details

Details for the file aws_solutions_constructs.aws_s3_stepfunctions-2.69.0-py3-none-any.whl.

File metadata

File hashes

Hashes for aws_solutions_constructs.aws_s3_stepfunctions-2.69.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8bd38d7988adf0af526c8229ea2e5319346f75a69702f53380bbc279ea2cffe0
MD5 978abd5800f5aab375ded937b5992e5d
BLAKE2b-256 3c6751c404d81a30d6c9a043408d2c68350abcfe5bce57f9a0da1fa90780d293

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page