View a markdown version of this page

AWS::NetworkSecurityManager::Deployment - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::NetworkSecurityManager::Deployment

The AWS::NetworkSecurityManager::Deployment resource specifies an AWS Network Security Manager deployment. A deployment is the object that puts protections into effect: it ties one or more policies, which describe the protections to apply, to a single scope, which selects the accounts and resources to apply them to.

Because a deployment only references policies and scopes, you create those resources first. A policy in turn references a template or a rule, so a complete stack builds the objects in this order: AWS::NetworkSecurityManager::Rule, AWS::NetworkSecurityManager::Template, AWS::NetworkSecurityManager::Policy, AWS::NetworkSecurityManager::Scope, and then AWS::NetworkSecurityManager::Deployment. Use Fn::GetAtt to pass each policy and scope ARN into the deployment so that CloudFormation infers this order for you.

Deployments that CloudFormation creates are always published, so the deployment begins applying its policies as soon as the stack operation completes. For conceptual information about deployments, see What is AWS Network Security Manager? in the AWS Network Security Manager Developer Guide.

Note

Network Security Manager uses optimistic concurrency control on deployments. If the deployment is modified outside of CloudFormation between the time CloudFormation reads it and the time CloudFormation writes to it, the stack operation fails with a conflict error. Manage a deployment either through CloudFormation or through the console and API, not both.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::NetworkSecurityManager::Deployment", "Properties" : { "AssociatedPolicyList" : [ AssociatedPolicy, ... ], "AssociatedScopeList" : [ AssociatedScope, ... ], "DeploymentConfiguration" : DeploymentConfiguration, "DeploymentDescription" : String, "DeploymentName" : String, "Tags" : [ Tag, ... ] } }

Properties

AssociatedPolicyList

The policies that the deployment applies. Specify one or two policies. Each entry references an AWS::NetworkSecurityManager::Policy resource by ARN.

This property is required when you create a deployment. Network Security Manager rejects a deployment that has no associated policy.

Required: Conditional

Type: Array of AssociatedPolicy

Minimum: 1

Maximum: 2

Update requires: No interruption

AssociatedScopeList

The scope that selects the accounts and resources the deployment protects. A deployment has exactly one scope, so specify a list with a single entry that references an AWS::NetworkSecurityManager::Scope resource by ARN.

This property is required when you create a deployment. Network Security Manager rejects a deployment that has no associated scope.

Required: Conditional

Type: Array of AssociatedScope

Minimum: 1

Maximum: 1

Update requires: No interruption

DeploymentConfiguration

The configuration settings for the deployment.

Required: No

Type: DeploymentConfiguration

Update requires: No interruption

DeploymentDescription

A description of the deployment.

Required: No

Type: String

Pattern: [a-zA-Z0-9 _.:/=+\-@]*

Minimum: 0

Maximum: 256

Update requires: No interruption

DeploymentName

The name of the deployment. The name must be unique within your AWS account and Region.

You can't change the name of a deployment after you create it. Specifying a different name replaces the deployment, which removes the protections applied by the original deployment while the replacement is created.

Required: Yes

Type: String

Pattern: [a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*

Minimum: 1

Maximum: 128

Update requires: Replacement

Tags

The tags to assign to the deployment. Each tag is a key-value pair. You can add tags when you create the deployment and change them afterward without replacing the deployment.

For more information, see Tag.

Required: No

Type: Array of Tag

Update requires: No interruption

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the deployment. For example:

{ "Ref": "myDeployment" }

For a deployment whose logical ID is myDeployment, Ref returns a value similar to arn:aws:network-security-manager:us-east-1:123456789012:deployment:a1b2c3d4e5f6.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

DeploymentArn

The Amazon Resource Name (ARN) of the deployment. For example: arn:aws:network-security-manager:us-east-1:123456789012:deployment:a1b2c3d4e5f6.

This is also the value returned by Ref for this resource.

DeploymentId

The unique identifier that Network Security Manager generates for the deployment. This value is unique within your AWS account and Region. For example: a1b2c3d4e5f6.

Status

The current status of the deployment. Deployments that CloudFormation manages are always published, so this attribute returns ACTIVE.

Allowed Values: DRAFT | ACTIVE

UpdatedAt

The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.

Version

The version of the deployment. Network Security Manager assigns version 1 when the deployment is created and increments it each time the deployment is published again, including on stack updates. For example: 3.

Examples

Put a policy into effect against a scope

YAML

AWSTemplateFormatVersion: "2010-09-09" Description: >- Puts Network Security Manager protections into effect by tying a policy to a scope. CloudFormation builds the resources in dependency order: rule, template, policy, scope, deployment. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' BaselineTemplate: Type: AWS::NetworkSecurityManager::Template Properties: TemplateName: waf-baseline FirewallType: WAF AssociatedRuleList: - RuleArn: !GetAtt AllowByDefaultRule.RuleArn BaselinePolicy: Type: AWS::NetworkSecurityManager::Policy Properties: PolicyName: waf-baseline-policy FirewallType: WAF Priority: 100 AssociatedTemplateAndRuleList: - TemplateArn: !GetAtt BaselineTemplate.TemplateArn PolicyConfiguration: RemediationEnabled: true ResourcesCleanUp: false WafConfig: ExistingCustomerWebACLResolution: RETROFIT ConflictResolution: MERGE_WHERE_APPLICABLE AllDistributionsScope: Type: AWS::NetworkSecurityManager::Scope Properties: ScopeName: all-cloudfront-distributions ScopeConfiguration: '{"AccountFilter":{"IncludeAll":true},"ResourceScopes":{"AWS::CloudFront::Distribution":{"IncludeAll":true}}}' BaselineDeployment: Type: AWS::NetworkSecurityManager::Deployment Properties: DeploymentName: waf-baseline-deployment DeploymentDescription: Applies the baseline policy to every CloudFront distribution. AssociatedPolicyList: - PolicyArn: !GetAtt BaselinePolicy.PolicyArn AssociatedScopeList: - ScopeArn: !GetAtt AllDistributionsScope.ScopeArn DeploymentConfiguration: EnableCrossAccountVisibility: true Outputs: DeploymentArn: Value: !GetAtt BaselineDeployment.DeploymentArn