Overview
MessagingFactory creates event-driven AWS resources: SQS queues, SNS topics, and EventBridge event buses. These resources decouple application components for asynchronous work.
Basic Usage
Messaging Types
SQS Queue (Standard)
Standard queues for high-throughput messaging:- Nearly unlimited throughput
- At-least-once delivery
- Best-effort ordering
- Suited to background job processing
SQS Queue (FIFO)
FIFO queues for ordered, exactly-once processing:- Exactly-once processing
- First-in-first-out ordering
- Message deduplication (on by default for FIFO queues)
- Suited to ordered workflows
contentBasedDeduplication, fifoThroughputLimit and deduplicationScope apply to FIFO queues only. On a standard queue they are ignored and the synth logs a warning.
Dead Letter Queue
Capture failed messages for analysis:maxReceiveCount defaults to 3.
Supply alertsTopic to arm a CloudWatch alarm that fires when the dead-letter queue holds any visible message. Without it, dead-lettered messages age out silently after 14 days.
SNS Topic
Publish-subscribe messaging for fan-out:- Fan-out to multiple subscribers
- Push-based delivery
- Multiple subscriber types (SQS, Lambda, HTTP, email)
- Message filtering
Fjall attaches a TLS-only resource policy to every topic, and that policy replaces SNS’s implicit default policy. AWS service principals that publish to the topic (CloudWatch, S3, EventBridge) need an explicit allow merged in via
topic.getTopic().addToResourcePolicy(...). Same-account IAM publishers are unaffected.EventBridge Event Bus
Custom event bus for event-driven architectures:- Rule-based routing on event patterns
- Targets across queues, Lambda, ECS, CodeBuild and log groups
- Per-subscription dead-letter queues and retry policies
- Cross-account and cross-region buses via ARN import
app.getEventBus() returns it and names it after the application.
Removal policies
Queues and topics are treated as transient mediums, so they default to
"DESTROY". Opt a durable queue or topic into "RETAIN" explicitly.
The event bus default resolves from the deploy environment. Fjall passes the target account’s stage into synth, and an unrecognised value fails the synth rather than falling back to "DESTROY". Pass an explicit removalPolicy to sidestep the resolution entirely.
Configuration Parameters
Queue Parameters
Queues are created with
enforceSSL, so every request must use TLS.
That TLS deny is a statement in the queue’s resource policy, and from fjall 38 the policy is checked at synthesis: Fjall refuses a queue policy over 20 statements, or one that may reach more than 8,192 bytes, naming the queue. See Queue-policy limits.
Topic Parameters
Topics are unencrypted at rest unless you pass
masterKey. A customer-managed key costs roughly 3 per month per account and region, so Fjall leaves the choice to you. Every AWS service principal that publishes to an encrypted topic needs kms:Decrypt and kms:GenerateDataKey* on that key’s resource policy.
Event Bus Parameters
Subscriptions
Callsubscribe(id, props) on an event bus to route matching events to a target. Each subscription synthesises an EventBridge rule scoped to that bus.
Subscription Options
EventPattern and the EventField / RuleTargetInput helpers are re-exported from @fjall/components-infrastructure.
An ECS target takes the shape { ecs: ecsCompute, serviceName: "worker", taskCount?: 1 } rather than the compute wrapper on its own.
Subscribing to AWS Service Events
AWS service events (aws.ecr, aws.ec2, aws.ecs) fire only on the account and region default bus. Subscribing an aws.* source on a custom application bus deploys cleanly and never invokes the target, so subscribe() rejects it with an error.
Import the default bus instead:
Importing an Existing Bus
Wrap a bus owned by another account or region by ARN. The importing stack owns the rules, and no newAWS::Events::EventBus is synthesised:
Common Patterns
Background Job Processing
connections grants IAM permissions. It does not create the Lambda trigger, so add the SQS event source explicitly:
A Lambda with
connections needs a VPC. ComputeFactory injects app.getVpc() automatically when the props carry connections, so no extra wiring is required.Event Fan-Out
Route matching events to multiple targets with an EventBridge event bus:MessagingFactory topics expose no wrapper subscription method. Use an EventBridge event bus for declarative fan-out, or attach SNS subscriptions to the underlying CDK construct via topic.getTopic().
ISR Revalidation Queue (OpenNext)
Connecting to Compute
Access Levels
connections accepts a queue directly, or a { resource, access } pair:
A bare queue in
connections defaults to "full".
ECS with Queue Access
connections lives on each service entry, not on the compute root:
connections to the service keeps the grant least-privilege. Other services in the same cluster get no queue access.
Access Grants
Queue Permissions
Topic Permissions
Event Bus Permissions
Best Practices
- Set
removalPolicy: "RETAIN"on any queue or topic whose contents cannot be regenerated - Configure a DLQ on every production queue and point
alertsTopicat your alarm topic - Use FIFO queues when order matters, and pass
messageGroupIdon FIFO subscriptions - Set
visibilityTimeoutto at least the consumer’s processing time - Use EventBridge for pattern-based routing and SNS for simple broadcast
- Import the default bus with
fromAwsServiceBusfor anyaws.*event source - Make consumers idempotent. EventBridge and standard SQS both deliver at least once
Next Steps
Compute Factory
Process messages with Lambda or ECS.
SQS Queue Resource
Configure queues at the resource level.
EventBridge Resource
Build rules, schedules, and subscriptions.
Payload Pattern
See messaging in a full OpenNext application.