Close|CloudStack Canvas · How-To Guide
How-To Fix

Grant a Compute Service Permission to Publish to an SNS Topic

Only Lambda has a declared "SNS Publish" connection on the canvas today (EC2 and ECS do not — for either of those, the manual policy below is the only path). Lambda↔SNS can mean two different things — the topic invoking the function (a subscription) or the function publishing to the topic via the SDK — so CloudStack Canvas only generates the sns:Publish policy once you tell it which one you mean: click the edge label and choose "Publish Access" (every direction defaults to the topic-invokes-the-function meaning until you explicitly pick access).

Paste into this field

IAM Role → permissions policy (or draw the edge on the canvas)

Output looks like

Canvas edge: Lambda → SNS (auto-generates an sns:Publish policy)

1Make the choice on the canvas (Lambda only)

Click the edge label between the Lambda and the topic and choose "Publish Access" in the chooser. Re-open Export and the warning is gone.

3Manual policy (EC2/ECS, or if the above does not apply to your case)

Replace REGION, ACCOUNT, and my-topic with your topic ARN values.

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": "sns:Publish",
    "Resource": "arn:aws:sns:REGION:ACCOUNT:my-topic"
  }]
}

6Save the policy

Name it AllowSNSPublish and click "Create policy". If the topic is encrypted with a customer-managed KMS key, also grant kms:GenerateDataKey and kms:Decrypt on that key.

Once you have the value, go back to CloudStack Canvas and paste it into the highlighted field.

CloudStack Canvas · Validation Guide

Grant a Compute Service Permission to Publish to an SNS Topic — CloudStack Canvas