Only Lambda has a declared "SNS Publish" connection on the canvas today (EC2 and ECS do not — for either of those, the manual policy below is the only path). Lambda↔SNS can mean two different things — the topic invoking the function (a subscription) or the function publishing to the topic via the SDK — so CloudStack Canvas only generates the sns:Publish policy once you tell it which one you mean: click the edge label and choose "Publish Access" (every direction defaults to the topic-invokes-the-function meaning until you explicitly pick access).
Paste into this field
IAM Role → permissions policy (or draw the edge on the canvas)Output looks like
Canvas edge: Lambda → SNS (auto-generates an sns:Publish policy)Click the edge label between the Lambda and the topic and choose "Publish Access" in the chooser. Re-open Export and the warning is gone.
Replace REGION, ACCOUNT, and my-topic with your topic ARN values.
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": "sns:Publish",
"Resource": "arn:aws:sns:REGION:ACCOUNT:my-topic"
}]
}Name it AllowSNSPublish and click "Create policy". If the topic is encrypted with a customer-managed KMS key, also grant kms:GenerateDataKey and kms:Decrypt on that key.
Once you have the value, go back to CloudStack Canvas and paste it into the highlighted field.
CloudStack Canvas · Validation Guide