AWS CloudFormation Resource Types: Difference between revisions

From NovaOrdis Knowledge Base
Jump to navigation Jump to search
 
(62 intermediate revisions by the same user not shown)
Line 1: Line 1:
=External=
* https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-template-resource-type-ref.html
=Internal=
=Internal=


* [[AWS_CloudFormation_Concepts#Resource_Types|AWS CloudFormation Concepts]]
* [[AWS_CloudFormation_Concepts#Resource_Types|AWS CloudFormation Concepts]]
=AWS::ApiGateway=
{{Internal|Amazon_API_Gateway_Deployment_with_CloudFormation#Resource_Types|Amazon API Gateway Deployment with CloudFormation}}


=AWS::CloudFormation=
=AWS::CloudFormation=
Line 14: Line 22:


==AWS::CodeBuild::Project==
==AWS::CodeBuild::Project==
Note that if the "Name" property is used, the physical ID of the created CodeBuild project will use that value, otherwise the name will be generated with the pattern ''CodeBuildProjectLogicalID''-apCFy5I1KyH8. Recommended name:
Resources:
  CodeBuildProject:
    Type: AWS::CodeBuild::Project
    Properties:
      Name: !Ref AWS::StackName
For an example of a CodeBuild build project that integrates with a CodePipeline see: {{Internal|AWS_CodePipeline-Driven_CodeBuild_Builds#Create_the_CodeBuild_Build_Project|CodePipeline-Driven CodeBuild Builds}}
=AWS::CodePipeline=
==AWS::CodePipeline::Pipeline==
{{External|[https://docs.aws.amazon.com/codepipeline/latest/userguide/reference-pipeline-structure.html Pipeline Structure]}}
Creates a CodePipeline [[AWS_CodePipeline_Concepts#Pipeline|pipeline]]. Other pipeline examples:
{{Internal|AWS_CodePipeline-Driven_CodeBuild_Builds#Create_the_Pipeline_that_Delegates_the_Build_to_the_CodeBuild_Build_Project|Pipeline that Delegates the Build to the CodeBuild Build Project}}
Note that if the "Name" property is used, the physical ID of the created pipeline will use that value, otherwise the name will be generated with the pattern ''stack-name''-Pipeline-24RCYXM52UE6A. Recommended name:
Resources:
  Pipeline:
    Type: AWS::CodePipeline::Pipeline
    Properties:
      Name: !Ref AWS::StackName
=AWS::DynamoDB=
{{Internal|Amazon DynamoDB Operations#CloudFormation_Support|Amazon DynamoDB Operations}}
=AWS::EC2=
==AWS::EC2::SecurityGroup==
{{Internal|AWS_Security_Operations#Create_a_Security_Group_with_CloudFormation|Create a Security Group with CloudFormation}}
==AWS::EC2::VPC==
{{Internal|Amazon_VPC_Operations#Create_a_VPC_with_CloudFormation|Amazon VPC Operations}}
==AWS::EC2::Instance==
{{Internal|Amazon_EC2_Operations#Create_an_EC2_Instance_with_CloudFormation|Create an EC2 Instance with CloudFormation}}


=AWS::ECR=
=AWS::ECR=
Line 19: Line 69:
==AWS::ECR::Repository==
==AWS::ECR::Repository==


<syntaxhighlight lang='yaml'>
{{External|[https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-ecr-repository.html AWS::ECR::Repository]}}
Resources:
 
  Repository:
Resources:
    Type: AWS::ECR::Repository
  Repository:
    Properties:
    Type: AWS::ECR::Repository
      RepositoryName: some-docker-repository-name
    Properties:
</syntaxhighlight>
      RepositoryName: some-docker-repository-name
 
=<span id='#AWS::ECS::TaskDefinition'></span><span id='#AWS::ECS::Service'></span>AWS::ECS=
 
{{Internal|Amazon ECS Deployment with CloudFormation|Amazon ECS Deployment with CloudFormation}}
 
=AWS::ElasticLoadBalancingV2=
{{Internal|AWS Elastic Load Balancing V2 Deployment with CloudFormation|AWS Elastic Load Balancing V2 Deployment with CloudFormation}}


=AWS::IAM=
=AWS::IAM=


==AWS::IAM::Role==
==AWS::IAM::Role==
{{External|[https://docs.aws.amazon.com/IAM/latest/APIReference/API_Role.html Role]}}
The following sequence creates an [[Amazon_AWS_Security_Concepts#IAM_Role|IAM Role]]:


  Resources:
  Resources:
Line 35: Line 96:
     Type: AWS::IAM::Role
     Type: AWS::IAM::Role
     Properties:
     Properties:
       ...
       RoleName: !Sub '${AWS::StackName}-codebuild-service-role'
      Description: A description of the role.
      Path: '/service-role/'
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: 'Allow'
            Principal:
              Service:
                - "codebuild.amazonaws.com"
            Action:
              - "sts:AssumeRole"
      Policies:
        - PolicyName: 'aggregated-inline-policy'
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: 'Allow'
                Action:
                  - 's3:ListBucket'
                Resource:
                  - '*'
 
'''Naming'''. If this role is declared by a "thalarion" stack, then, after successful creation, the role's physical ID will be "thalarion-CodeBuildServiceRole-A479B6WNRHSSG". A custom name can be forced with the "RoleName", as shown above.
 
=AWS::Kinesis=
{{Internal|Amazon Kinesis Operations#CloudFormation_Support|Amazon Kinesis Operations}}
 
=AWS::KMS=
{{Internal|Amazon KMS Operations#CloudFormation|Amazon KMS Operations}}
 
=AWS::Lambda=
 
{{Internal|AWS Lambda Create a Lambda Function with CloudFromation|AWS Lambda Create a Lambda Function with CloudFromation}}


If this role is declared by an "example" stack, then, after successful creation, its ARN will be arn:aws:iam::''AccountID'':role/service-role/example-CodeBuildServiceRole-1V7H0HL94BUX6
=AWS::Logs=
==AWS::Logs::LogGroup==


=AWS::S3=
{{Internal|Amazon CloudWatch Operations|CloudWatch Operations}}


==AWS::S3::Bucket==
=<span id='AWS::S3::Bucket'></span>AWS::S3=


Resources:
{{Internal|Amazon_S3_Operations#Create_an_S3_Bucket_With_CloudFormation|S3 Operations}}
  BuildBucket:
 
    Type: AWS::S3::Bucket
=AWS::Serverless=
    Properties:
 
      AccessControl: BucketOwnerFullControl
=AWS::ServiceDiscovery=
==AWS::ServiceDiscovery::Service==

Latest revision as of 21:10, 27 April 2019

External

Internal

AWS::ApiGateway

Amazon API Gateway Deployment with CloudFormation

AWS::CloudFormation

AWS::CloudFormation::Stack

https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-stack.html

AWS::CloudFormation::Stack enables nesting another stack as a resource within a template.

AWS::CodeBuild

AWS::CodeBuild::Project

Note that if the "Name" property is used, the physical ID of the created CodeBuild project will use that value, otherwise the name will be generated with the pattern CodeBuildProjectLogicalID-apCFy5I1KyH8. Recommended name:

Resources:
  CodeBuildProject:
    Type: AWS::CodeBuild::Project
    Properties:
      Name: !Ref AWS::StackName

For an example of a CodeBuild build project that integrates with a CodePipeline see:

CodePipeline-Driven CodeBuild Builds

AWS::CodePipeline

AWS::CodePipeline::Pipeline

Pipeline Structure

Creates a CodePipeline pipeline. Other pipeline examples:

Pipeline that Delegates the Build to the CodeBuild Build Project

Note that if the "Name" property is used, the physical ID of the created pipeline will use that value, otherwise the name will be generated with the pattern stack-name-Pipeline-24RCYXM52UE6A. Recommended name:

Resources:
  Pipeline:
    Type: AWS::CodePipeline::Pipeline
    Properties:
      Name: !Ref AWS::StackName

AWS::DynamoDB

Amazon DynamoDB Operations

AWS::EC2

AWS::EC2::SecurityGroup

Create a Security Group with CloudFormation

AWS::EC2::VPC

Amazon VPC Operations

AWS::EC2::Instance

Create an EC2 Instance with CloudFormation

AWS::ECR

AWS::ECR::Repository

AWS::ECR::Repository
Resources:
  Repository:
    Type: AWS::ECR::Repository
    Properties:
      RepositoryName: some-docker-repository-name

AWS::ECS

Amazon ECS Deployment with CloudFormation

AWS::ElasticLoadBalancingV2

AWS Elastic Load Balancing V2 Deployment with CloudFormation

AWS::IAM

AWS::IAM::Role

Role

The following sequence creates an IAM Role:

Resources:
  CodeBuildServiceRole:
    Type: AWS::IAM::Role
    Properties:
      RoleName: !Sub '${AWS::StackName}-codebuild-service-role'
      Description: A description of the role.
      Path: '/service-role/'
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: 'Allow'
            Principal:
              Service:
                - "codebuild.amazonaws.com"
            Action:
              - "sts:AssumeRole"
      Policies:
        - PolicyName: 'aggregated-inline-policy'
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: 'Allow'
                Action:
                  - 's3:ListBucket'
                Resource:
                  - '*'

Naming. If this role is declared by a "thalarion" stack, then, after successful creation, the role's physical ID will be "thalarion-CodeBuildServiceRole-A479B6WNRHSSG". A custom name can be forced with the "RoleName", as shown above.

AWS::Kinesis

Amazon Kinesis Operations

AWS::KMS

Amazon KMS Operations

AWS::Lambda

AWS Lambda Create a Lambda Function with CloudFromation

AWS::Logs

AWS::Logs::LogGroup

CloudWatch Operations

AWS::S3

S3 Operations

AWS::Serverless

AWS::ServiceDiscovery

AWS::ServiceDiscovery::Service