This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::NetworkSecurityManager::Scope
The AWS::NetworkSecurityManager::Scope resource specifies an AWS Network Security Manager scope. A scope selects the accounts and the resources that a deployment applies to.
You define reusable rules and templates, combine them into policies, then use a scope to choose where those protections apply. For more information, see the AWS Network Security Manager Developer Guide.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::NetworkSecurityManager::Scope", "Properties" : { "ScopeConfiguration" :String, "ScopeDescription" :String, "ScopeName" :String, "Tags" :[ Tag, ... ]} }
YAML
Type: AWS::NetworkSecurityManager::Scope Properties: ScopeConfiguration:StringScopeDescription:StringScopeName:StringTags:- Tag
Properties
ScopeConfiguration-
The configuration that defines which accounts and resources are in scope, as a JSON string.
Note
Unlike the AWS Network Security Manager API, which takes this configuration as a structure, the AWS CloudFormation property takes the serialized JSON document. Because the value is an opaque string, AWS CloudFormation does not validate its contents when it validates your template. An invalid configuration is reported when the stack is provisioned.
The JSON document supports the following top-level members:
-
AccountFilter -
The account filter that determines which accounts are in scope. Set exactly one of
IncludeAll,Include, orExclude. UseIncludeAllto apply no account filtering,Includeto select only the specified accounts and organizational units, orExcludeto select every account except those specified.The
IncludeandExcludemembers each take a set of accounts and organizational units, withAccountIdsfor AWS account IDs andOrganizationalUnitsfor AWS Organizations organizational units (OUs). -
ResourceScopes -
The resource-level scoping configuration, keyed by resource type, that defines which resources within the selected accounts are in scope. For each resource type, set exactly one of
IncludeAll,Include, orExclude.The
IncludeandExcludemembers each take a set of resources defined byExplicitArns, by anExpression, or by both. An expression combines leaf conditions with theAnd,Or, andNotoperators. A leaf condition matches resources by tag key-value pairs or by resource-type-specific configuration.
Required: No
Type: String
Update requires: No interruption
-
ScopeDescription-
A description of the scope.
Required: No
Type: String
Pattern:
[a-zA-Z0-9 _.:/=+\-@]*Minimum:
0Maximum:
256Update requires: No interruption
ScopeName-
The name of the scope.
To change the name of a scope, AWS CloudFormation deletes the existing scope and creates a new one, which also changes the values returned for
ScopeIdandScopeArn.Required: Yes
Type: String
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*Minimum:
1Maximum:
128Update requires: Replacement
-
The tags to assign to the scope.
Required: No
Type: Array of Tag
Update requires: No interruption
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the scope. For example:
{ "Ref": "MyScope" }
For a scope named ScopeName, Ref returns a value such as arn:aws:network-security-manager:us-east-1:123456789012:scope:abcd1234-5678-90ab-cdef-EXAMPLE11111.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
ScopeArn-
The Amazon Resource Name (ARN) of the scope. For example:
arn:aws:network-security-manager:us-east-1:123456789012:scope:abcd1234-5678-90ab-cdef-EXAMPLE11111. ScopeId-
The service-generated unique identifier of the scope. For example:
abcd1234-5678-90ab-cdef-EXAMPLE11111. Status-
The current status of the scope.
Note
Scopes that you manage with AWS CloudFormation are always published, so this attribute returns
ACTIVE. The AWS Network Security Manager API also supports an unpublishedDRAFTstatus, which AWS CloudFormation does not use.Allowed Values:
ACTIVE UpdatedAt-
The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.
Version-
The version of the scope. AWS Network Security Manager increments this value each time it publishes a new version of the scope. For example:
1.
Examples
Select every CloudFront distribution in the organization
YAML
AWSTemplateFormatVersion: "2010-09-09" Description: Selects the accounts and resources that a Network Security Manager deployment protects. Resources: AllDistributionsScope: Type: AWS::NetworkSecurityManager::Scope Properties: ScopeName: all-cloudfront-distributions ScopeDescription: Every CloudFront distribution in every account in the organization. ScopeConfiguration: '{"AccountFilter":{"IncludeAll":true},"ResourceScopes":{"AWS::CloudFront::Distribution":{"IncludeAll":true}}}' Outputs: ScopeArn: Value: !GetAtt AllDistributionsScope.ScopeArn