Skip to content
Back to skills

Aws Sqs Sns

ASecurity

Expert coverage of AWS SQS and SNS managed messaging services: standard and FIFO queues, visibility timeout, dead-letter queues, SNS fan-out, message filtering, Lambda integration, and operational management. Use for \"SQS\", \"SNS\", \"Amazon SQS\", \"Amazon SNS\", \"FIFO queue\", \"standard queue\", \"message group\", \"MessageGroupId\", \"MessageDeduplicationId\", \"visibility timeout\", \"dead letter queue SQS\", \"DLQ SQS\", \"redrive policy\", \"SNS topic\", \"SNS subscription\", \"SNS ...

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopsawsterraform

Works with

  • cli

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill aws-sqs-sns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Aws Sqs Sns?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Aws Sqs Sns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-aws-sqs-sns/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-aws-sqs-sns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: aws-sqs-sns
description: "Expert coverage of AWS SQS and SNS managed messaging services: standard and FIFO queues, visibility timeout, dead-letter queues, SNS fan-out, message filtering, Lambda integration, and operational management. Use for \"SQS\", \"SNS\", \"Amazon SQS\", \"Amazon SNS\", \"FIFO queue\", \"standard queue\", \"message group\", \"MessageGroupId\", \"MessageDeduplicationId\", \"visibility timeout\", \"dead letter queue SQS\", \"DLQ SQS\", \"redrive policy\", \"SNS topic\", \"SNS subscription\", \"SNS filter\", \"filter policy\", \"fan-out SQS\", \"Lambda SQS\", \"Event Source Mapping\", \"SQS long polling\", \"batch item failures\", \"SQS Extended Client\", \"aws sqs\", \"aws sns\". Do NOT use for general AWS architecture, IAM, or non-messaging service provisioning -- that's the `cloud-platforms` plugin."
license: MIT
---

# AWS SQS/SNS

This skill covers Amazon SQS (Simple Queue Service) and Amazon SNS (Simple Notification Service), including:

- SQS Standard queues (at-least-once, best-effort ordering, unlimited throughput)
- SQS FIFO queues (exactly-once, strict ordering per message group, high-throughput mode)
- Visibility timeout, long polling, message retention, delay queues
- Dead-letter queues (redrive policy, message move tasks, DLQ redrive)
- SNS Standard and FIFO topics (fan-out to SQS, Lambda, HTTP, email, SMS)
- SNS message filtering (subscription filter policies on attributes and body)
- Lambda Event Source Mapping (batch processing, partial batch responses)
- Server-side encryption (SSE-SQS, SSE-KMS)
- Resource policies, cross-account access, VPC endpoints
- CloudFormation/Terraform IaC patterns
- CloudWatch monitoring and alerting

## How to Approach Tasks

1. **Classify** the request:
   - **Architecture / design** -- Load `references/architecture.md` for queue types, SNS topics, fan-out, FIFO semantics, DLQ
   - **Best practices** -- Load `references/best-practices.md` for Lambda integration, FIFO throughput, filtering, IaC patterns
   - **Troubleshooting** -- Load `references/diagnostics.md` for visibility timeout issues, DLQ analysis, FIFO throughput, Lambda failures

2. **Gather context** -- Standard vs FIFO, Lambda vs EC2 consumers, encryption requirements, cross-account needs

3. **Recommend** -- Provide actionable guidance with AWS CLI commands, CloudFormation snippets, and SDK code.

## Core Architecture

### SQS Standard
At-least-once delivery. Best-effort ordering. Unlimited throughput. 120,000 in-flight message limit. Use when order and exactly-once are not required.

### SQS FIFO
Exactly-once processing via MessageDeduplicationId (5-minute window). Strict FIFO within MessageGroupId. Name must end with `.fifo`. Default: 300 msg/s without batching, 3,000 with batching. High-throughput mode: up to 70,000 transactions/s.

### SNS Standard Topics
Push-based pub/sub. Fan-out to SQS, Lambda, HTTP, email, SMS, Firehose. At-least-once delivery.

### SNS FIFO Topics
Strict ordering and exactly-once to SQS FIFO subscriptions only. MessageGroupId propagated.

### Fan-Out Pattern
```
Producer --> SNS Topic --> SQS Queue A --> Consumer A
                       --> SQS Queue B --> Consumer B
                       --> SQS Queue C --> Consumer C
```

## Anti-Patterns

| Anti-Pattern | Why It Fails | Instead |
|---|---|---|
| Short polling (`WaitTimeSeconds=0`) | Empty responses, higher cost, higher latency | Always use long polling (20 seconds) |
| Not deleting messages after processing | Messages reappear after visibility timeout | Delete immediately after successful processing |
| Single MessageGroupId for all FIFO messages | All messages serialized; no parallelism | Use many distinct group IDs (e.g., per entity) |
| DLQ retention shorter than source | Messages expire before investigation | DLQ retention >= source retention |
| Ignoring partial batch failures (Lambda) | Entire batch retried including successes | Enable `ReportBatchItemFailures` |
| Visibility timeout < 6x Lambda timeout | Message reappears before Lambda finishes | Set visibility timeout >= 6x Lambda timeout |

## Reference Files

- `references/architecture.md` -- Standard/FIFO queues, visibility timeout, DLQ/redrive, SNS topics, subscriptions, filtering, FIFO topics, encryption, resource policies
- `references/best-practices.md` -- Long polling, FIFO throughput, Lambda integration, CloudFormation/Terraform patterns, SNS filtering, cost optimization
- `references/diagnostics.md` -- Visibility timeout issues, DLQ analysis, FIFO deduplication, Lambda ESM failures, CloudWatch metrics, throughput troubleshooting

## Cross-References

- The `overview` skill -- cross-broker comparisons and event-driven architecture design

## Diagnostic Scripts

Ready-made AWS CLI v2 audits (read-only IAM) in `scripts/`, numbered by investigation order.

- `scripts/01-queue-depth-audit.sh` -- Depth/in-flight across all queues with DLQ-buildup flags
- `scripts/02-redrive-config-audit.sh` -- Queues without DLQs and maxReceiveCount sanity

Files in this skill

  • SKILL.md4.9 KB
  • references/architecture.md4.5 KB
  • references/best-practices.md5 KB
  • references/diagnostics.md6.2 KB
  • scripts/01-queue-depth-audit.sh1.9 KB
  • scripts/02-redrive-config-audit.sh1.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…