Review CloudFormation resource update protection

Protect critical stack resources from unintended replacement or removal during updates.

Description

Without a stack policy that provides the required protection, an authorized CloudFormation stack update can modify, replace or remove critical resources. Define update protections for resources such as databases that are costly to recover.

A stack policy restricts actions during stack updates. It is not an authorization policy that blocks DeleteStack or direct changes through service APIs. Omitting a policy from a task also does not establish that an existing stack has no policy.

Potential impact

  • A template change can replace a critical resource, causing an outage or data loss.
  • Incorrect protection rules can also block necessary updates and delay operations.

Remediation

Configure a stack policy for the logical resource IDs requiring protection. Use stack_policy_body for inline JSON and stack_policy for a policy file path. Explicitly allow permitted updates and restrict modification, replacement and removal of critical resources. Review change sets and manage IAM permissions, stack deletion protection and backups separately.

Examples

Use the actual template URL and ensure PrimaryDatabase matches the logical ID requiring protection. disable_rollback separately controls behavior after a failed creation; review it against operational requirements.

Before

yaml
- name: CloudFormation 스택 생성
  amazon.aws.cloudformation:
    stack_name: ansible-cloudformation
    state: present
    region: us-east-1
    disable_rollback: true
    template_url: https://s3.amazonaws.com/my-bucket/cloudformation.template

This task contains no stack policy. Check the policy actually applied to the stack and the protection required for critical resources.

After

yaml
- name: CloudFormation 스택 생성
  amazon.aws.cloudformation:
    stack_name: ansible-cloudformation
    stack_policy_body: |
      {
        "Statement": [
          {
            "Effect": "Allow",
            "Action": "Update:*",
            "Principal": "*",
            "Resource": "*"
          },
          {
            "Effect": "Deny",
            "Action": "Update:*",
            "Principal": "*",
            "Resource": "LogicalResourceId/PrimaryDatabase"
          }
        ]
      }
    state: present
    region: us-east-1
    disable_rollback: true
    template_url: https://s3.amazonaws.com/my-bucket/cloudformation.template

The policy allows general updates but denies all update actions for PrimaryDatabase. With only a Deny and no explicit Allow, other updates are denied by default too; review the complete policy.

References