This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::ObservabilityAdmin::OrganizationCentralizationRule TagPropagationConfiguration
Specifies configuration for propagating resource tags from source log groups to centralized destination log groups. The service uses a customer-managed IAM role in the destination account to add, update, and remove tags on destination log groups.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "DestinationRoleArn" :String, "TagConflictResolutionStrategy" :String}
YAML
DestinationRoleArn:StringTagConflictResolutionStrategy:String
Properties
DestinationRoleArn-
The ARN of a customer-managed IAM role in the destination account. The service assumes this role to propagate tags to destination log groups. You must have
iam:PassRolepermission on this role.Required: Yes
Type: String
Pattern:
^arn:aws[a-zA-Z-]*:iam::\d{12}:role/[\w+=,.@/-]+$Minimum:
20Maximum:
2048Update requires: No interruption
TagConflictResolutionStrategy-
The strategy for resolving conflicts when a tag key exists on both the source and destination log groups. If not specified, defaults to
UPDATE_SYNC.-
ADD_ONLY– Only adds new tags from the source without modifying existing destination tags. -
UPDATE_SYNC– Adds new tags and updates existing tags from the source. Does not remove destination tags that are absent from the source. -
IN_SYNC– Keeps destination tags fully synchronized with source tags, including removing destination tags that do not exist on the source.
Required: No
Type: String
Allowed values:
IN_SYNC | ADD_ONLY | UPDATE_SYNCUpdate requires: No interruption
-