This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::RAM::PermissionAssociation
Associates a specified AWS RAM permission with a resource share. You can only associate one permission with each resource type in a resource share.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::RAM::PermissionAssociation", "Properties" : { "PermissionArn" :String, "Replace" :Boolean, "ResourceShareArn" :String} }
YAML
Type: AWS::RAM::PermissionAssociation Properties: PermissionArn:StringReplace:BooleanResourceShareArn:String
Properties
PermissionArn-
Specifies the Amazon Resource Name (ARN) of the AWS RAM permission to associate with the resource share.
Required: Yes
Type: String
Update requires: Replacement
Replace-
Specifies whether to replace the existing permission on the resource share. Use
trueto replace the current permission. Usefalseto add the permission when no permission is currently associated. The default value isfalse.Required: No
Type: Boolean
Update requires: No interruption
-
Specifies the Amazon Resource Name (ARN) of the resource share.
Required: Yes
Type: String
Update requires: Replacement
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the resource share ARN and permission ARN in the format resource-share-arn|permission-arn. For example: arn:aws:ram:us-east-1:999999999999:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2|arn:aws:ram::aws:permission/AWSRAMPermissionGlueDatabaseReadWrite.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
AssociationStatus-
The current status of the association between the permission and the resource share. Possible values include
ASSOCIATING,ASSOCIATED,FAILED,DISASSOCIATING,DISASSOCIATED,SUSPENDED,SUSPENDING, andRESTORING. FeatureSet-
The feature set of the resource share. Possible values include
STANDARD,CREATED_FROM_POLICY, andPROMOTING_TO_STANDARD. IsDefault-
Indicates whether the associated resource share is using the default version of the permission.
LastUpdatedTime-
The date and time when the association between the permission and the resource share was last updated.
PermissionVersion-
The version of the permission currently associated with the resource share.
ResourceType-
The resource type to which the permission applies.
Examples
Associating a permission with a resource share
The following example associates a permission with a resource share.
YAML
AWSTemplateFormatVersion: '2010-09-09' Resources: MyPermissionAssociation: Type: AWS::RAM::PermissionAssociation Properties: PermissionArn: arn:aws:ram::aws:permission/AWSRAMPermissionGlueDatabaseReadWrite ResourceShareArn: !Sub arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2
JSON
{ "AWSTemplateFormatVersion": "2010-09-09", "Resources": { "MyPermissionAssociation": { "Type": "AWS::RAM::PermissionAssociation", "Properties": { "PermissionArn": "arn:aws:ram::aws:permission/AWSRAMPermissionGlueDatabaseReadWrite", "ResourceShareArn": { "Fn::Sub": "arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2" } } } } }
See also
-
AssociateResourceSharePermission in the AWS Resource Access Manager API Reference