Create a Kinesis action

Create an Amazon Kinesis action in the Admin Portal to forward matching events from an Events & Actions listener to an Amazon Kinesis data stream. Before you configure the action, create a data stream and an Identity and Access Management (IAM) role in AWS that lets PubNub write to it.

Use Terraform instead of the AWS console
1resource "aws_kinesis_stream" "pubnub_kinesis" {
2 name = "pubnub-example"
3 shard_count = 1
4
5 stream_mode_details {
6 stream_mode = "PROVISIONED"
7 }
8}
9
10data "aws_iam_policy_document" "pubnub_kinesis_role" {
11 statement {
12 actions = ["sts:AssumeRole"]
13
14 principals {
15 type = "AWS"
show all 58 lines

If you use this Terraform configuration, skip ahead to configure the action in the Admin Portal.

Create a data stream​

  1. Open Amazon Kinesis and go to Data streams.

  2. Click Create data stream and enter a name.

    Events & Actions supports the Data Streams service type. It doesn't support Kinesis Data Firehose.

  3. Click Create data stream to save it.

  4. Copy the stream's ARN. You need it to configure the action.

Create an IAM role​

Create an IAM role that grants PubNub write access to your data stream. An IAM role is an AWS identity with a set of permissions, and it doesn't belong to a single user.

  1. Open AWS Identity and Access Management and go to Roles.

  2. Click Create role and name the role.

  3. Set AWS account as the Trusted entity type.

  4. Under An AWS account, select Another AWS account and enter 535363102202 as the Account ID. This is PubNub's AWS account ID, and this trust relationship is what lets PubNub write to your data stream.

  5. Under Options, select Require external ID.

  6. Paste your app's subscribe key from the keyset's page in the Admin Portal into External ID. AWS recommends this step, though it isn't required. It scopes the trust relationship so only requests carrying your subscribe key as the external ID can assume the role. For example:

    1{
    2 "Version": "2012-10-17",
    3 "Statement": [
    4 {
    5 "Effect": "Allow",
    6 "Principal": {
    7 "AWS": "arn:aws:iam::535363102202:root"
    8 },
    9 "Action": "sts:AssumeRole",
    10 "Condition": {
    11 "StringEquals": {
    12 "sts:ExternalId": "<PubNub subscribe key>"
    13 }
    14 }
    15 }
    show all 17 lines

    Click Next.

  7. Create a policy that grants kinesis:PutRecord. Click Create policy, switch to the JSON editor, and paste this snippet, replacing the resource with your stream's Amazon Resource Name (ARN), the unique identifier AWS assigns to the stream:

    1{
    2 "Statement": [
    3 {
    4 "Action": [
    5 "kinesis:PutRecord"
    6 ],
    7 "Effect": "Allow",
    8 "Resource": "<ARN of your Kinesis data stream>"
    9 }
    10 ],
    11 "Version": "2012-10-17"
    12}

    Complete the policy in the wizard.

  8. Select the new policy and click Next.

  9. Name the role and click Create Role.

  10. Copy the role's ARN. You need it to configure the action.

Configure the action​

  1. In Events & Actions on the Admin Portal, click + Add Action.
  2. Click Amazon Kinesis to select the action type.
  3. Paste the Data Stream ARN and Role ARN you copied earlier.
  4. If you want PubNub to retry failed deliveries automatically, turn on Kinesis retry and set the retry count and interval. When a delivery is retried, PubNub adds retry metadata to the event payload. See Available actions for the full retry mechanics, including the jitter formula.
  5. Pair the action with an event listener without leaving Actions. Click Add event listener and select an existing listener, or create one first.
  6. Click Save changes.

Confirm records arrive in your data stream​

Publish a message, or trigger whichever event you configured, so it matches your listener's filter. For how publishing works, see Publishing messages with PubNub. Then check your data stream in the Amazon Kinesis console for a new record. For the exact JSON structure PubNub sends, see Payloads.

If no record arrives, confirm the action is paired with a listener whose filter matches the event you triggered. Also confirm the IAM role's policy grants kinesis:PutRecord on that exact stream ARN.

Was this page useful?

Last updated on