Skip to content
🎉 Bem-vindo! Sinfonia by 27Devs é uma plataforma completa de orquestração de robôs, solicite já seu acesso.
AWS (SQS and S3)

AWS (SQS and S3)

Use AWS triggers when a bot must react to events in your AWS account: a new message in an SQS queue or a file uploaded to an S3 bucket. Sinfonia watches the configured resource and fires the bot on every event.

AWS Triggers

There are 2 types of AWS triggers:

  • SQS: Monitors a specific SQS queue and triggers the bot when a new message is received.
  • S3: Monitors an S3 bucket for events like file uploads and triggers the bot in response to these events.

Note

To use these triggers, you need an AWS account with appropriate permissions to access SQS and S3 services. Additionally, AWS credentials (Access Key and Secret Key) must be configured as environment variables to make selection during the trigger configuration process.

SQS

Below is the description of the fields needed to configure an SQS type trigger.

AWS Triggers

Configuration Fields

Queue URL

  • Expected format: https://sqs.<queue_region>.amazonaws.com/account_id/queue_name
  • Description: Complete address of the SQS queue that will be monitored to trigger the event.

AWS Access Key

  • Description: AWS access key with permissions to access the SQS queue.
  • Example: AWS_ACCESS_KEY
  • Important: This key must be previously configured as an environment variable in the system variables section.

AWS Secret Key

  • Description: AWS secret key corresponding to the access key.
  • Example: AWS_SECRET_KEY
  • Important: This key must be previously configured as an environment variable in the system variables section.
FieldDescriptionNotes
BotBot that will be executed when the trigger is fired.Must be previously created and available on the platform for selection.
VersionSpecific version of the bot to be used.Accepts X.Y.Z (example: 1.0.0) or release, which always uses the latest available version.
LabelOptional identifier for the trigger.Can be used for organization or filtering.
AgentDefines the agent responsible for bot execution.The agent must be active and connected. Multiple agents can be selected, avoiding execution bottlenecks.
Parameters (JSON)Additional parameters sent to the bot, in JSON format.Reach the code as environment variables. Example: {"arg1": "1366", "arg2": "768"}
DescriptionFree text describing the trigger’s purpose.Makes it easier to identify on listing screens.

Permissions

For the trigger to work correctly, the SQS queue must have a permissions policy that allows the platform service to access and read messages. The policy must include the following statement:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "SQSSpecificQueue",
            "Effect": "Allow",
            "Action": [
                "sqs:CreateQueue",
                "sqs:DeleteQueue",
                "sqs:TagQueue",
                "sqs:ListQueues",
                "sqs:SetQueueAttributes",
                "sqs:ReceiveMessage",
                "sqs:DeleteMessage"
            ],
            "Resource": [
                "arn:aws:sqs:${Region}:${Account}:${QueueName}"
            ]
        }
    ]
}

Note

Replace ${Region}, ${Account} and ${QueueName} with the actual values of the queue you want to monitor. If you want to monitor multiple queues, use "Resource": ["*"], but be aware of associated security risks.

S3

Below is the description of the fields needed to configure an S3 type trigger.

AWS Triggers

Configuration Fields

Bucket Name

  • Description: Exact name of the S3 bucket that will be monitored for events.

AWS Region

  • Description: AWS region where the bucket is located (e.g., us-east-1, sa-east-1).

Filter objects by prefix

  • Description: Allows triggering only for objects whose name starts with the specified prefix.

Filter objects by suffix

  • Description: Allows triggering only for objects whose name ends with the specified suffix (e.g., .csv, .jpg).

AWS Access Key

  • Description: AWS access key with permissions to access the SQS queue.
  • Example: AWS_ACCESS_KEY
  • Important: This key must be previously configured as an environment variable in the system variables section.

AWS Secret Key

  • Description: AWS secret key corresponding to the access key.
  • Example: AWS_SECRET_KEY
  • Important: This key must be previously configured as an environment variable in the system variables section.
FieldDescriptionNotes
BotBot that will be executed when the trigger is fired.Must be previously created and available on the platform for selection.
VersionSpecific version of the bot to be used.Accepts X.Y.Z (example: 1.0.0) or release, which always uses the latest available version.
LabelOptional identifier for the trigger.Can be used for organization or filtering.
AgentDefines the agent responsible for bot execution.The agent must be active and connected. Multiple agents can be selected, avoiding execution bottlenecks.
Parameters (JSON)Additional parameters sent to the bot, in JSON format.Reach the code as environment variables. Example: {"arg1": "1366", "arg2": "768"}
DescriptionFree text describing the trigger’s purpose.Makes it easier to identify on listing screens.

Permissions

For the trigger to work correctly, the S3 bucket must have a permissions policy that allows the platform service to access bucket events. The policy must include the following statement:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "S3BucketLevel",
            "Effect": "Allow",
            "Action": [
                "s3:ListBucket",
                "s3:GetBucketPolicy",
                "s3:GetBucketNotification",
                "s3:PutBucketNotification"
            ],
            "Resource": [
                "arn:aws:s3:::${BucketName}/${KeyName}"
            ]
        },
        {
            "Sid": "S3ObjectLevel",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:PutObject",
                "s3:GetObjectVersion",
                "s3:PutObjectAcl",
                "s3:PutObjectTagging"
            ],
            "Resource": [
                "arn:aws:s3:::${BucketName}/${KeyName}"
            ]
        }
    ]
}

Note

Replace ${BucketName} and ${KeyName} with the actual values of the bucket and prefix/suffix you want to monitor.

Complete IAM Policy

Create an IAM user with the policy below to allow the trigger to work correctly with both S3 and SQS services.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "S3BucketLevel",
            "Effect": "Allow",
            "Action": [
                "s3:ListBucket",
                "s3:GetBucketPolicy",
                "s3:GetBucketNotification",
                "s3:PutBucketNotification"
            ],
            "Resource": [
                "arn:aws:s3:::${BucketName}/${KeyName}"
            ]
        },
        {
            "Sid": "S3ObjectLevel",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:PutObject",
                "s3:GetObjectVersion",
                "s3:PutObjectAcl",
                "s3:PutObjectTagging"
            ],
            "Resource": [
                "arn:aws:s3:::${BucketName}/${KeyName}"
            ]
        },
        {
            "Sid": "SQSSpecificQueue",
            "Effect": "Allow",
            "Action": [
                "sqs:CreateQueue",
                "sqs:DeleteQueue",
                "sqs:TagQueue",
                "sqs:ListQueues",
                "sqs:SetQueueAttributes",
                "sqs:ReceiveMessage",
                "sqs:DeleteMessage"
            ],
            "Resource": [
                "*"
            ]
        }
    ]
}

Note

Replace ${BucketName} and ${KeyName} with the actual values of the bucket and prefix/suffix you want to monitor.

Last updated on