This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::NetworkSecurityManager::Deployment
The AWS::NetworkSecurityManager::Deployment resource specifies an AWS Network Security Manager deployment. A deployment is the object that puts protections into effect: it ties one or more policies, which describe the protections to apply, to a single scope, which selects the accounts and resources to apply them to.
Because a deployment only references policies and scopes, you create those resources first. A policy in turn references a template or a rule, so a complete stack builds the objects in this order: AWS::NetworkSecurityManager::Rule, AWS::NetworkSecurityManager::Template, AWS::NetworkSecurityManager::Policy, AWS::NetworkSecurityManager::Scope, and then AWS::NetworkSecurityManager::Deployment. Use Fn::GetAtt to pass each policy and scope ARN into the deployment so that CloudFormation infers this order for you.
Deployments that CloudFormation creates are always published, so the deployment begins applying its policies as soon as the stack operation completes. For conceptual information about deployments, see What is AWS Network Security Manager? in the AWS Network Security Manager Developer Guide.
Note
Network Security Manager uses optimistic concurrency control on deployments. If the deployment is modified outside of CloudFormation between the time CloudFormation reads it and the time CloudFormation writes to it, the stack operation fails with a conflict error. Manage a deployment either through CloudFormation or through the console and API, not both.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::NetworkSecurityManager::Deployment", "Properties" : { "AssociatedPolicyList" :[ AssociatedPolicy, ... ], "AssociatedScopeList" :[ AssociatedScope, ... ], "DeploymentConfiguration" :DeploymentConfiguration, "DeploymentDescription" :String, "DeploymentName" :String, "Tags" :[ Tag, ... ]} }
YAML
Type: AWS::NetworkSecurityManager::Deployment Properties: AssociatedPolicyList:- AssociatedPolicyAssociatedScopeList:- AssociatedScopeDeploymentConfiguration:DeploymentConfigurationDeploymentDescription:StringDeploymentName:StringTags:- Tag
Properties
AssociatedPolicyList-
The policies that the deployment applies. Specify one or two policies. Each entry references an AWS::NetworkSecurityManager::Policy resource by ARN.
This property is required when you create a deployment. Network Security Manager rejects a deployment that has no associated policy.
Required: Conditional
Type: Array of AssociatedPolicy
Minimum:
1Maximum:
2Update requires: No interruption
AssociatedScopeList-
The scope that selects the accounts and resources the deployment protects. A deployment has exactly one scope, so specify a list with a single entry that references an AWS::NetworkSecurityManager::Scope resource by ARN.
This property is required when you create a deployment. Network Security Manager rejects a deployment that has no associated scope.
Required: Conditional
Type: Array of AssociatedScope
Minimum:
1Maximum:
1Update requires: No interruption
DeploymentConfiguration-
The configuration settings for the deployment.
Required: No
Type: DeploymentConfiguration
Update requires: No interruption
DeploymentDescription-
A description of the deployment.
Required: No
Type: String
Pattern:
[a-zA-Z0-9 _.:/=+\-@]*Minimum:
0Maximum:
256Update requires: No interruption
DeploymentName-
The name of the deployment. The name must be unique within your AWS account and Region.
You can't change the name of a deployment after you create it. Specifying a different name replaces the deployment, which removes the protections applied by the original deployment while the replacement is created.
Required: Yes
Type: String
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*Minimum:
1Maximum:
128Update requires: Replacement
-
The tags to assign to the deployment. Each tag is a key-value pair. You can add tags when you create the deployment and change them afterward without replacing the deployment.
For more information, see Tag.
Required: No
Type: Array of Tag
Update requires: No interruption
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the deployment. For example:
{ "Ref": "myDeployment" }
For a deployment whose logical ID is myDeployment, Ref returns a value similar to arn:aws:network-security-manager:us-east-1:123456789012:deployment:a1b2c3d4e5f6.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
DeploymentArn-
The Amazon Resource Name (ARN) of the deployment. For example:
arn:aws:network-security-manager:us-east-1:123456789012:deployment:a1b2c3d4e5f6.This is also the value returned by
Reffor this resource. DeploymentId-
The unique identifier that Network Security Manager generates for the deployment. This value is unique within your AWS account and Region. For example:
a1b2c3d4e5f6. Status-
The current status of the deployment. Deployments that CloudFormation manages are always published, so this attribute returns
ACTIVE.Allowed Values:
DRAFT|ACTIVE UpdatedAt-
The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.
Version-
The version of the deployment. Network Security Manager assigns version
1when the deployment is created and increments it each time the deployment is published again, including on stack updates. For example:3.
Examples
Put a policy into effect against a scope
YAML
AWSTemplateFormatVersion: "2010-09-09" Description: >- Puts Network Security Manager protections into effect by tying a policy to a scope. CloudFormation builds the resources in dependency order: rule, template, policy, scope, deployment. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' BaselineTemplate: Type: AWS::NetworkSecurityManager::Template Properties: TemplateName: waf-baseline FirewallType: WAF AssociatedRuleList: - RuleArn: !GetAtt AllowByDefaultRule.RuleArn BaselinePolicy: Type: AWS::NetworkSecurityManager::Policy Properties: PolicyName: waf-baseline-policy FirewallType: WAF Priority: 100 AssociatedTemplateAndRuleList: - TemplateArn: !GetAtt BaselineTemplate.TemplateArn PolicyConfiguration: RemediationEnabled: true ResourcesCleanUp: false WafConfig: ExistingCustomerWebACLResolution: RETROFIT ConflictResolution: MERGE_WHERE_APPLICABLE AllDistributionsScope: Type: AWS::NetworkSecurityManager::Scope Properties: ScopeName: all-cloudfront-distributions ScopeConfiguration: '{"AccountFilter":{"IncludeAll":true},"ResourceScopes":{"AWS::CloudFront::Distribution":{"IncludeAll":true}}}' BaselineDeployment: Type: AWS::NetworkSecurityManager::Deployment Properties: DeploymentName: waf-baseline-deployment DeploymentDescription: Applies the baseline policy to every CloudFront distribution. AssociatedPolicyList: - PolicyArn: !GetAtt BaselinePolicy.PolicyArn AssociatedScopeList: - ScopeArn: !GetAtt AllDistributionsScope.ScopeArn DeploymentConfiguration: EnableCrossAccountVisibility: true Outputs: DeploymentArn: Value: !GetAtt BaselineDeployment.DeploymentArn