CloudFormation stack policy missing

Use a stack policy to protect resources during stack updates.

Description

A stack policy restricts resource modification, replacement, or deletion during CloudFormation updates. For important resources, check that the policy provides the update protection you need.

Potential impact

Without protection, an accidental stack update can change critical resources and cause downtime or data loss.

Remediation

Apply a policy through policy_body or policy_url that restricts the relevant update actions. A stack policy differs from termination protection, which prevents deletion of the stack itself.

Examples

The examples accept a URL for a valid stack policy. The stack template is omitted, and merely specifying a policy does not block every update.

Before

hcl
resource "aws_cloudformation_stack" "example" {
  name = "networking-stack"

  parameters = {
    VPCCidr = "10.0.0.0/16"
  }
}

After

hcl
resource "aws_cloudformation_stack" "example" {
  name = "networking-stack"

  parameters = {
    VPCCidr = "10.0.0.0/16"
  }

  policy_url = var.stack_policy_url
}

References