Share a Custom Event Bus with a Consumer Account Using AWS RAM

Share an Amazon EventBridge custom event bus with another AWS account using AWS RAM, then attach a subscriber from the consumer account.

This snippet shares an Amazon EventBridge enhanced custom event bus with a consumer account using AWS Resource Access Manager. The examples grant the explicit SubscribeOnly managed permission. When the consumer is outside the owner's AWS Organization, external principals must be allowed and the consumer must accept the RAM invitation within 12 hours before using the shared bus.
Choose the AWS CLI, AWS CDK, or AWS SAM tab, replace its placeholders, and run it with the credentials indicated. The consumer account must create and own its Subscriber, target, delivery role, and dead-letter queue against the shared bus ARN; a target in another account is rejected during CreateSubscriber. The CDK and SAM options deploy the owner-side RAM share, while consumer delivery resources remain separate.

Select language:

AWS CLI

Run each block with the credentials of the account named in its comment. Replace the event bus, account, queue, role, and dead-letter queue placeholders.

BUS_ARN="<EVENT_BUS_ARN>"
CONSUMER_ACCOUNT="<CONSUMER_ACCOUNT_ID>"
PERMISSION="arn:aws:ram::aws:permission/AWSRAMEventBridgeEventBusV2SubscribeOnly"

# OWNER ACCOUNT
SHARE_ARN=$(aws ram create-resource-share \
  --name "custom-bus-consumer-share" \
  --resource-arns "$BUS_ARN" \
  --principals "$CONSUMER_ACCOUNT" \
  --permission-arns "$PERMISSION" \
  --allow-external-principals \
  --query 'resourceShare.resourceShareArn' --output text)

# CONSUMER ACCOUNT
INVITATION_ARN=$(aws ram get-resource-share-invitations \
  --query 'resourceShareInvitations[?status==`PENDING`]|[0].resourceShareInvitationArn' \
  --output text) \
&& \
aws ram accept-resource-share-invitation \
  --resource-share-invitation-arn "$INVITATION_ARN"

# CONSUMER ACCOUNT
aws ram list-resources --resource-owner OTHER-ACCOUNTS

# OWNER ACCOUNT
aws ram get-resource-share-associations \
  --association-type PRINCIPAL \
  --resource-share-arns "$SHARE_ARN" \
  --query 'resourceShareAssociations[].[associatedEntity,status]' --output text

# OWNER ACCOUNT
aws eventsv2 get-resource-policy \
  --resource-arn "$BUS_ARN" \
  --policy-name AWS_RAM

# CONSUMER ACCOUNT: TARGET, DELIVERY ROLE, AND DLQ MUST BE IN THIS ACCOUNT
aws eventsv2 create-subscriber \
  --name "fulfillment-order-placed" \
  --event-bus-arn "$BUS_ARN" \
  --filter-configuration "$(cat <<EOF
{"Filters":[{"Scope":"METADATA","Pattern":"{\"domain\":[\"orders\"]}"}]}
EOF
)" \
  --invoke-configuration "$(cat <<EOF
{"TargetArn":"<CONSUMER_QUEUE_ARN>","RoleArn":"<CONSUMER_DELIVERY_ROLE_ARN>"}
EOF
)" \
  --on-failure-configuration "$(cat <<EOF
{"Arn":"<CONSUMER_DLQ_ARN>"}
EOF
)"

# OWNER ACCOUNT
aws ram delete-resource-share --resource-share-arn "$SHARE_ARN"

                                                      



Created by:

Maximiliano Paz

Maximiliano Paz

Senior Solutions Architect at AWS

Follow on LinkedIn