Description
A stack policy restricts resource modification, replacement, or deletion during CloudFormation updates. For important resources, check that the policy provides the update protection you need.
Potential impact
Without protection, an accidental stack update can change critical resources and cause downtime or data loss.
Remediation
Apply a policy through policy_body or policy_url that restricts the relevant update actions. A stack policy differs from termination protection, which prevents deletion of the stack itself.
Examples
The examples accept a URL for a valid stack policy. The stack template is omitted, and merely specifying a policy does not block every update.
Before
hcl
resource "aws_cloudformation_stack" "example" {
name = "networking-stack"
parameters = {
VPCCidr = "10.0.0.0/16"
}
}
After
hcl
resource "aws_cloudformation_stack" "example" {
name = "networking-stack"
parameters = {
VPCCidr = "10.0.0.0/16"
}
policy_url = var.stack_policy_url
}