Review protection policies for Alibaba Cloud ROS stack updates

Define the resources and operations that need protection during stack updates.

Description

A ROS stack policy controls resource operations allowed during stack updates. Without one, a user with update permissions may unintentionally modify or delete important resources.

Potential impact

  • An incorrect update can change or delete important resources.
  • Restoring services and data may require additional work.

Remediation

Set the required base protection policy with stack_policy_body or stack_policy_url. Use an approved stack_policy_during_update override only when a specific update requires it. Manage RAM permissions and deletion and backup procedures separately.

Examples

The template excerpt shows only the format version; actual resource definitions are omitted. The after policy permits other update operations while withholding permission to delete resources during an update.

Before

hcl
resource "alicloud_ros_stack" "stack" {
  stack_name    = "tf-testaccstack"
  template_body = <<EOF
{
  "ROSTemplateFormatVersion": "2015-09-01"
}
EOF
}

After

hcl
resource "alicloud_ros_stack" "stack" {
  stack_name    = "tf-testaccstack"
  template_body = <<EOF
{
  "ROSTemplateFormatVersion": "2015-09-01"
}
EOF

  stack_policy_body = <<EOF
{
  "Statement": [{
    "NotAction": "Update:Delete",
    "Resource": "*",
    "Effect": "Allow",
    "Principal": "*"
  }]
}
EOF
}

The Allow statement with NotAction: Update:Delete excludes Update:Delete from its allowed operations. A temporary update policy is optional; use it only for necessary changes so that it does not undermine the base protections.

References