AWS Notify Slack Terraform module

June 19, 2026 ยท View on GitHub

This module creates an SNS topic (or uses an existing one) and an AWS Lambda function that sends notifications to Slack using the incoming webhooks API.

Start by setting up an incoming webhook integration in your Slack workspace.

Doing serverless with Terraform? Check out serverless.tf framework, which aims to simplify all operations when working with the serverless in Terraform.

Supported Features

  • AWS Lambda runtime Python 3.13
  • Create new SNS topic or use existing one
  • Support plaintext and encrypted version of Slack webhook URL
  • Most of Slack message options are customizable
  • Custom Lambda function
  • Various event types are supported, even generic messages:
    • AWS CloudWatch Alarms
    • AWS CloudWatch LogMetrics Alarms
    • AWS GuardDuty Findings
    • AWS GuardDuty Malware Protection Object Scan Results

Usage

module "notify_slack" {
  source  = "terraform-aws-modules/notify-slack/aws"
  version = "~> 7.0"

  sns_topic_name = "slack-topic"

  slack_webhook_url = "https://hooks.slack.com/services/AAA/BBB/CCC"
  slack_channel     = "aws-notification"
  slack_username    = "reporter"
}

Using with Terraform Cloud Agents

Terraform Cloud Agents are a paid feature, available as part of the Terraform Cloud for Business upgrade package.

This module requires Python 3.11. You can customize tfc-agent to include Python using this sample Dockerfile:

FROM hashicorp/tfc-agent:latest
RUN apt-get -y update && apt-get -y install python3.11 python3-pip
ENTRYPOINT ["/bin/tfc-agent"]

Use existing SNS topic or create new

If you want to subscribe the AWS Lambda Function created by this module to an existing SNS topic you should specify create_sns_topic = false as an argument and specify the name of existing SNS topic name in sns_topic_name.

Examples

  • notify-slack-simple - Creates SNS topic which sends messages to Slack channel.
  • cloudwatch-alerts-to-slack - End to end example which shows how to send AWS Cloudwatch alerts to Slack channel and use KMS to encrypt webhook URL.

Local Development and Testing

See the functions for further details.

Requirements

NameVersion
terraform>= 1.5.7
aws>= 6.28

Providers

NameVersion
aws>= 6.28

Modules

NameSourceVersion
lambdaterraform-aws-modules/lambda/aws8.7.0

Resources

NameType
aws_cloudwatch_log_group.lambdaresource
aws_iam_role.sns_feedback_roleresource
aws_sns_topic.thisresource
aws_sns_topic_subscription.sns_notify_slackresource
aws_caller_identity.currentdata source
aws_iam_policy_document.lambdadata source
aws_iam_policy_document.sns_feedbackdata source
aws_partition.currentdata source
aws_region.currentdata source

Inputs

NameDescriptionTypeDefaultRequired
architecturesInstruction set architecture for your Lambda function. Valid values are ["x86_64"] and ["arm64"].list(string)nullno
cloudwatch_log_group_kms_key_idThe ARN of the KMS Key to use when encrypting log data for Lambdastringnullno
cloudwatch_log_group_retention_in_daysSpecifies the number of days you want to retain log events in log group for Lambda.number0no
cloudwatch_log_group_tagsAdditional tags for the Cloudwatch log groupmap(string){}no
createWhether to create all resourcesbooltrueno
create_sns_topicWhether to create new SNS topicbooltrueno
enable_sns_topic_delivery_status_logsWhether to enable SNS topic delivery status logsboolfalseno
hash_extraThe string to add into hashing function. Useful when building same source path for different functions.string""no
iam_role_boundary_policy_arnThe ARN of the policy that is used to set the permissions boundary for the rolestringnullno
iam_role_name_prefixA unique role name beginning with the specified prefixstring"lambda"no
iam_role_pathPath of IAM role to use for Lambda Functionstringnullno
iam_role_tagsAdditional tags for the IAM rolemap(string){}no
kms_key_arnARN of the KMS key used for decrypting slack webhook urlstring""no
lambda_attach_dead_letter_policyControls whether SNS/SQS dead letter notification policy should be added to IAM role for Lambda Functionboolfalseno
lambda_dead_letter_target_arnThe ARN of an SNS topic or SQS queue to notify when an invocation fails.stringnullno
lambda_descriptionThe description of the Lambda functionstringnullno
lambda_function_ephemeral_storage_sizeAmount of ephemeral storage (/tmp) in MB your Lambda Function can use at runtime. Valid value between 512 MB to 10,240 MB (10 GB).number512no
lambda_function_nameThe name of the Lambda function to createstring"notify_slack"no
lambda_function_s3_bucketS3 bucket to store artifactsstringnullno
lambda_function_store_on_s3Whether to store produced artifacts on S3 or locally.boolfalseno
lambda_function_tagsAdditional tags for the Lambda functionmap(string){}no
lambda_function_vpc_security_group_idsList of security group ids when Lambda Function should run in the VPC.list(string)nullno
lambda_function_vpc_subnet_idsList of subnet ids when Lambda Function should run in the VPC. Usually private or intra subnets.list(string)nullno
lambda_roleIAM role attached to the Lambda Function. If this is set then a role will not be created for you.string""no
lambda_source_pathThe source path of the custom Lambda functionstringnullno
log_eventsBoolean flag to enabled/disable logging of incoming eventsboolfalseno
log_levelLogging level for the Lambda functionstring"INFO"no
putin_khuyloDo you agree that Putin doesn't respect Ukrainian sovereignty and territorial integrity? More info: https://en.wikipedia.org/wiki/Putin_khuylo!booltrueno
recreate_missing_packageWhether to recreate missing Lambda package if it is missing locally or notbooltrueno
reserved_concurrent_executionsThe amount of reserved concurrent executions for this lambda function. A value of 0 disables lambda from being triggered and -1 removes any concurrency limitationsnumber-1no
runtimeLambda Function runtimestring"python3.13"no
slack_channelThe name of the channel in Slack for notificationsstringn/ayes
slack_emojiA custom emoji that will appear on Slack messagesstring":aws:"no
slack_usernameThe username that will appear on Slack messagesstringn/ayes
slack_webhook_urlThe URL of Slack webhookstringn/ayes
sns_topic_feedback_role_descriptionDescription of IAM role to use for SNS topic delivery status loggingstringnullno
sns_topic_feedback_role_force_detach_policiesSpecifies to force detaching any policies the IAM role has before destroying it.booltrueno
sns_topic_feedback_role_nameName of the IAM role to use for SNS topic delivery status loggingstringnullno
sns_topic_feedback_role_pathPath of IAM role to use for SNS topic delivery status loggingstringnullno
sns_topic_feedback_role_permissions_boundaryThe ARN of the policy that is used to set the permissions boundary for the IAM role used by SNS topic delivery status loggingstringnullno
sns_topic_feedback_role_tagsA map of tags to assign to IAM the SNS topic feedback rolemap(string){}no
sns_topic_kms_key_idARN of the KMS key used for enabling SSE on the topicstring""no
sns_topic_lambda_feedback_role_arnIAM role for SNS topic delivery status logs. If this is set then a role will not be created for you.string""no
sns_topic_lambda_feedback_sample_rateThe percentage of successful deliveries to lognumber100no
sns_topic_nameThe name of the SNS topic to createstringn/ayes
sns_topic_policyThe fully-formed AWS policy as JSON.stringnullno
sns_topic_tagsAdditional tags for the SNS topicmap(string){}no
subscription_filter_policy(Optional) A valid filter policy that will be used in the subscription to filter messages seen by the target resource.stringnullno
subscription_filter_policy_scope(Optional) A valid filter policy scope MessageAttributes|MessageBodystringnullno
tagsA map of tags to add to all resourcesmap(string){}no
trigger_on_package_timestamp(Optional) Whether or not to ignore the file timestamp when deciding to create the archiveboolfalseno

Outputs

NameDescription
lambda_cloudwatch_log_group_arnThe Amazon Resource Name (ARN) specifying the log group
lambda_iam_role_arnThe ARN of the IAM role used by Lambda function
lambda_iam_role_nameThe name of the IAM role used by Lambda function
notify_slack_lambda_function_arnThe ARN of the Lambda function
notify_slack_lambda_function_invoke_arnThe ARN to be used for invoking Lambda function from API Gateway
notify_slack_lambda_function_last_modifiedThe date Lambda function was last modified
notify_slack_lambda_function_nameThe name of the Lambda function
notify_slack_lambda_function_versionLatest published version of your Lambda function
slack_topic_arnThe ARN of the SNS topic from which messages will be sent to Slack
sns_topic_feedback_role_arnThe Amazon Resource Name (ARN) of the IAM role used for SNS delivery status logging
this_slack_topic_arnThe ARN of the SNS topic from which messages will be sent to Slack (backward compatibility for version 4.x)

Authors

Module is maintained by Anton Babenko with help from these awesome contributors.

License

Apache 2 Licensed. See LICENSE for full details.