View a markdown version of this page

AWS::RAM::PermissionAssociation - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::RAM::PermissionAssociation

Associates a specified AWS RAM permission with a resource share. You can only associate one permission with each resource type in a resource share.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::RAM::PermissionAssociation", "Properties" : { "PermissionArn" : String, "Replace" : Boolean, "ResourceShareArn" : String } }

YAML

Type: AWS::RAM::PermissionAssociation Properties: PermissionArn: String Replace: Boolean ResourceShareArn: String

Properties

PermissionArn

Specifies the Amazon Resource Name (ARN) of the AWS RAM permission to associate with the resource share.

Required: Yes

Type: String

Update requires: Replacement

Replace

Specifies whether to replace the existing permission on the resource share. Use true to replace the current permission. Use false to add the permission when no permission is currently associated. The default value is false.

Required: No

Type: Boolean

Update requires: No interruption

ResourceShareArn

Specifies the Amazon Resource Name (ARN) of the resource share.

Required: Yes

Type: String

Update requires: Replacement

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the resource share ARN and permission ARN in the format resource-share-arn|permission-arn. For example: arn:aws:ram:us-east-1:999999999999:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2|arn:aws:ram::aws:permission/AWSRAMPermissionGlueDatabaseReadWrite.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

AssociationStatus

The current status of the association between the permission and the resource share. Possible values include ASSOCIATING, ASSOCIATED, FAILED, DISASSOCIATING, DISASSOCIATED, SUSPENDED, SUSPENDING, and RESTORING.

FeatureSet

The feature set of the resource share. Possible values include STANDARD, CREATED_FROM_POLICY, and PROMOTING_TO_STANDARD.

IsDefault

Indicates whether the associated resource share is using the default version of the permission.

LastUpdatedTime

The date and time when the association between the permission and the resource share was last updated.

PermissionVersion

The version of the permission currently associated with the resource share.

ResourceType

The resource type to which the permission applies.

Examples

Associating a permission with a resource share

The following example associates a permission with a resource share.

YAML

AWSTemplateFormatVersion: '2010-09-09' Resources: MyPermissionAssociation: Type: AWS::RAM::PermissionAssociation Properties: PermissionArn: arn:aws:ram::aws:permission/AWSRAMPermissionGlueDatabaseReadWrite ResourceShareArn: !Sub arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2

JSON

{ "AWSTemplateFormatVersion": "2010-09-09", "Resources": { "MyPermissionAssociation": { "Type": "AWS::RAM::PermissionAssociation", "Properties": { "PermissionArn": "arn:aws:ram::aws:permission/AWSRAMPermissionGlueDatabaseReadWrite", "ResourceShareArn": { "Fn::Sub": "arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2" } } } } }

See also