# P11 EventBridge remediation safety lab

AWS230 artifact. The CloudFormation stack deploys disabled by default and its
Lambda records a validated decision only; it cannot mutate a workload.

Files:

- `template.yaml`: exact custom event -> Lambda -> conditional DynamoDB record,
  with bounded retry, standard SQS DLQ, explicit permissions, logs, and alarms;
- `pattern.json`, `test-event.json`, and `negative-event.json`: offline
  `test-event-pattern` fixtures;
- `put-events-entry.json`: one repeatable live custom event whose business token
  can be published twice to prove semantic duplicate suppression;
- `metric-data-queries.json`: reviewed EventBridge delivery metric queries;
- `automation-decision.yaml`: read-only Systems Manager Automation alternative.

Before using the fixtures, replace account `000000000000` with the approved
account. Test the pattern before enabling the rule. Follow AWS230 for deployment,
positive/negative/duplicate tests, failure injection, DLQ evidence, and cleanup.

The primary Lambda uses the caller-provided `requestToken`, not EventBridge's
unique event `id`, as the DynamoDB key. Re-publishing the same business request
with a new EventBridge ID is therefore suppressed. DynamoDB TTL is cleanup, not
an exact deletion schedule; never depend on TTL for immediate correctness.
