AWS eventbridge: Restructure EventBridge quotas: Custom Event Bus, Classic, API destinations
Summary
Reorganizes the EventBridge quotas page: renames 'EventBridge event bus quotas' to 'Custom Event Bus quotas', adds new Service Quotas and fixed-limits tables for the Custom Event Bus (including a resource policy size quota and the PolicyLengthExceededException behavior), adds a 'Custom Event Bus - Classic quotas' section, and a new 'API destinations and connections' section covering account-wide quotas for both bus types. Also updates nav labels and the page footer link from 'Troubleshooting' to 'Tags'.
Security assessment
The change is primarily a quotas-documentation restructure (new Service Quotas and fixed-limit tables, renamed sections, nav/footer label updates). The only security-adjacent content is the resource-policy size quota (20,480 bytes) and the note that oversized policies fail with PolicyLengthExceededException, plus mention of AWS RAM-written policies not counting toward the quota; this touches access-control policy management but documents nothing new about a vulnerability, mitigation, or security best practice, and no CVE/advisory is referenced.
Evidence
+If the `default` policy in a `PutResourcePolicy` call exceeds the resource policy size quota, the call fails with `PolicyLengthExceededException`. See [Write a custom resource policy](./eb-custom-bus-sharing.html#eb-custom-bus-access-policy).
Diff
diff --git a/eventbridge/latest/userguide/eb-quota.md b/eventbridge/latest/userguide/eb-quota.md index 8c9d4c3ee..c943e8e47 100644 --- a//eventbridge/latest/userguide/eb-quota.md +++ b//eventbridge/latest/userguide/eb-quota.md @@ -7 +7 @@ -EventBridge event bus quotasSchema Registry quotasPipes quotas +Custom Event Bus quotasCustom Event Bus - Classic quotasAPI destinations and connectionsSchema Registry quotasPipes quotas @@ -11 +11,5 @@ EventBridge event bus quotasSchema Registry quotasPipes quotas -The following quotas apply to the various feature areas of Amazon EventBridge. +The following quotas apply to the Custom Event Bus, to Custom Event Bus - Classic, to the API destinations and connections that both buses deliver to, to the schema registry, and to EventBridge Pipes. + +###### Note + +If you use Custom Event Bus - Classic, the event bus that routes with rules and targets, see Custom Event Bus - Classic quotas. @@ -15 +19,5 @@ The following quotas apply to the various feature areas of Amazon EventBridge. - * EventBridge event bus quotas + * Custom Event Bus quotas + + * Custom Event Bus - Classic quotas + + * API destinations and connections @@ -28 +36 @@ For a list of the quotas for EventBridge Scheduler, see [Quotas for EventBridge -## EventBridge event bus quotas +## Custom Event Bus quotas @@ -30 +38,44 @@ For a list of the quotas for EventBridge Scheduler, see [Quotas for EventBridge -EventBridge event buses have the following quotas. +The Service Quotas console lists 6 quotas for the Custom Event Bus under Amazon EventBridge, each with an `[EventsV2]` prefix; 4 of them are adjustable. To raise the bus limit, for example, request an increase to `[EventsV2] Event Buses`. The other limits in this section are fixed values that the API enforces and are not adjustable. These quotas are separate from the Custom Event Bus - Classic quotas in Custom Event Bus - Classic quotas. + +### Service Quotas + +The following table lists the quotas in the Service Quotas console, per account per Region. + +Quota| Default| Adjustable +---|---|--- +Event buses owned by the account. Buses shared with the account do not count| 5| Yes +Event sources owned by the account| 200| Yes +Subscribers per bus the account owns, counting every account the bus is shared with| 10,000| Yes +Size, in bytes, of the `default` resource policy of a bus the account owns. The `AWS_RAM` policy that AWS RAM writes for a shared bus does not count| 20,480| Yes +Events per second per bus, counting every event source and every account the bus is shared with| 500,000| No +Ingestion per event group per second, counted as the number of events plus their total size in KB in any one-second window| 1,500| No + +Your account's bus count is also published as the `ResourceCount` metric in the `AWS/Usage` namespace, so you can alarm before you reach the limit; see [Observability for the Custom Event Bus: metrics, logs, and CloudTrail](./eb-custom-bus-observability.html). Publishing and subscriber management are throttled separately for each account: `PutEvents` and `PutRawEvents` draw from one budget, and `CreateSubscriber` and `DeleteSubscriber` from another. Handle `ThrottlingException` with backoff and retry. + +If the `default` policy in a `PutResourcePolicy` call exceeds the resource policy size quota, the call fails with `PolicyLengthExceededException`. See [Write a custom resource policy](./eb-custom-bus-sharing.html#eb-custom-bus-access-policy). + +### Fixed limits + +The following values are set by the API and cannot be raised. Where a setting takes a range, you choose any value in the range; the maximum is the fixed part. + +Setting| You choose| Fixed maximum or value +---|---|--- +`StorageConfiguration.RetentionPeriodInDays`| 1 to 365 days| 365 days +`RetryPolicy.MaxRetryAttempts`| 0 to 185, default 5| 185 +`RetryPolicy.MaxEventAgeInSeconds`| 60 to 86,400, default 300| 86,400 seconds +`BatchConfiguration.MaxBatchSize`| 1 to 500| 500 +`BatchConfiguration.MaxBatchWindowInSeconds`| 0 to 300, default 0| 300 seconds +`InvocationTimeoutSeconds` on Lambda, Step Functions, and HTTP targets| 1 to 30, default 30| 30 seconds +Entries per `PutEvents` or `PutRawEvents` request| 1 to 100| 100 +Deduplication window| Not configurable| 300 seconds +JSONata expression in a `Transformer` or a target parameter| Not configurable| 8,192 characters +JSONata expression in a universal target's `Input`| Not configurable| 262,144 characters +Filters in one `FilterConfiguration`| Up to 3, one per scope| 4,096 bytes across all filters; 1,000 `$or` combinations +Filter changes per subscriber| Not configurable| 24 in any rolling 24 hours; see [Updating, pausing, and resuming a subscriber](./eb-custom-bus-update.html) +Subscriber creates or deletes in progress on one bus| Not configurable| 1 across all accounts; a second call fails with `ConcurrentModificationException` +Subscribers replaying from a past position at the same time| Not configurable| Limited per bus; `CreateSubscriber` fails with `LimitExceededException` when reached +`errorMessage` in a dead-letter record| Not configurable| 1,024 characters + +## Custom Event Bus - Classic quotas + +Custom Event Bus - Classic has the following quotas. The Service Quotas table also lists the API destination, connection, and global endpoint quotas, which are account-level resources. @@ -59,0 +111,4 @@ Connections (Private) | Each supported Region: 20 | The maximum number of priva +## API destinations and connections + +API destinations and connections belong to your account, not to a bus, and both buses use them: a Custom Event Bus - Classic rule targets an API destination, and a Custom Event Bus subscriber delivers to one through `HttpParameters`. A Custom Event Bus producer that publishes Avro or Protobuf with a Confluent schema registry also names a connection. One set of quotas covers all of that use. In the Service Quotas table in Custom Event Bus - Classic quotas, the rows _Api destinations_ , _Connections_ , and _Rate of invocations per API destination_ are the account-wide values; the invocation rate is shared by every rule and subscriber that targets the same API destination. The fixed table in the same section lists the private connection limit. + @@ -126 +181 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -Troubleshooting +Tags