Description
Creating a new CloudFormation stack through Ansible requires a template that defines its resources. A new stack cannot be created without one.
Updating an existing stack is different. amazon.aws.cloudformation can reuse the previous template when no new template input is supplied, and stack deletion does not require a new template.
Potential impact
- A failed stack creation can interrupt the deployment pipeline.
- Unintended reuse of an existing template can leave expected resource changes unapplied.
Remediation
- For a new stack, supply one template input supported by the installed module, such as
template_bodyortemplate_url. Do not supply competing template sources. - For an existing stack, decide whether to reuse or replace the template and review the changes. Also provide the required template input when creating a new StackSet.
Examples
These existing examples assume a new stack. Replace the URL with an accessible actual template, and adapt the example parameters and values to that template and environment.
Before
- name: CloudFormation 스택 생성
amazon.aws.cloudformation:
stack_name: ansible-cloudformation
state: present
region: us-east-1
disable_rollback: true
template_parameters:
KeyName: jmartin
DiskType: ephemeral
InstanceType: m1.small
ClusterSize: 3
tags:
Stack: ansible-cloudformation
A new stack cannot be created without a template input. An existing stack can reuse its template, so check the operation’s purpose.
After
- name: CloudFormation 스택 생성
amazon.aws.cloudformation:
stack_name: ansible-cloudformation
state: present
region: us-east-1
disable_rollback: true
template_url: https://s3.amazonaws.com/my-bucket/cloudformation.template
template_parameters:
KeyName: jmartin
DiskType: ephemeral
InstanceType: m1.small
ClusterSize: 3
tags:
Stack: ansible-cloudformation
template_url selects the template. Also verify its validity and access permissions.