Description
A ROS stack policy controls resource operations allowed during stack updates. Without one, a user with update permissions may unintentionally modify or delete important resources.
Potential impact
- An incorrect update can change or delete important resources.
- Restoring services and data may require additional work.
Remediation
Set the required base protection policy with stack_policy_body or stack_policy_url. Use an approved stack_policy_during_update override only when a specific update requires it. Manage RAM permissions and deletion and backup procedures separately.
Examples
The template excerpt shows only the format version; actual resource definitions are omitted. The after policy permits other update operations while withholding permission to delete resources during an update.
Before
resource "alicloud_ros_stack" "stack" {
stack_name = "tf-testaccstack"
template_body = <<EOF
{
"ROSTemplateFormatVersion": "2015-09-01"
}
EOF
}
After
resource "alicloud_ros_stack" "stack" {
stack_name = "tf-testaccstack"
template_body = <<EOF
{
"ROSTemplateFormatVersion": "2015-09-01"
}
EOF
stack_policy_body = <<EOF
{
"Statement": [{
"NotAction": "Update:Delete",
"Resource": "*",
"Effect": "Allow",
"Principal": "*"
}]
}
EOF
}
The Allow statement with NotAction: Update:Delete excludes Update:Delete from its allowed operations. A temporary update policy is optional; use it only for necessary changes so that it does not undermine the base protections.