Review the template configuration for Alibaba Cloud ROS stacks

Specify the ROS template that defines the resources to deploy.

Description

A ROS stack needs a template defining its resources. A stack name or policy without a template does not provide a complete definition for creation.

Potential impact

  • Stack creation can fail or leave the required infrastructure undeployed.
  • Missing deployment details can complicate code review and operational automation.

Remediation

Provide a reviewed template through template_body or template_url. Validate its resources and parameters and track changes. Separately check that the stack policy matches the deployment and protection requirements.

Examples

The before example is incomplete because it has no template. The after template_body is an excerpt showing only the format version; an actual deployment also needs its resource definitions.

Before

hcl
resource "alicloud_ros_stack" "example" {
  stack_name = "tf-testaccstack"

  stack_policy_body = <<EOF
{
  "Statement": [{
    "Action": "Update:Delete",
    "Resource": "*",
    "Effect": "Allow",
    "Principal": "*"
  }]
}
EOF
}

After

hcl
resource "alicloud_ros_stack" "example" {
  stack_name    = "tf-testaccstack"
  template_body = <<EOF
{
  "ROSTemplateFormatVersion": "2015-09-01"
}
EOF
}

A stack policy does not replace a template. Supplying template_body alone does not establish that resource configuration is correct or that the protection policy is sufficient.

References