This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::RAM::PrincipalAssociation
Associates a specified principal with a resource share.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::RAM::PrincipalAssociation", "Properties" : { "Principal" :String, "ResourceShareArn" :String} }
YAML
Type: AWS::RAM::PrincipalAssociation Properties: Principal:StringResourceShareArn:String
Properties
Principal-
Specifies the principal to associate with the resource share. The possible values are:
-
An AWS account ID
-
An Amazon Resource Name (ARN) of an organization in AWS Organizations
-
An ARN of an organizational unit (OU) in AWS Organizations
-
An ARN of an IAM role
-
An ARN of an IAM user
Required: Yes
Type: String
Update requires: Replacement
-
-
Specifies the Amazon Resource Name (ARN) of the resource share.
Required: Yes
Type: String
Update requires: Replacement
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the resource share ARN and principal in the format resource-share-arn|principal. For example: arn:aws:ram:us-east-1:999999999999:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2|arn:aws:organizations::999999999999:ou/o-12345abcde/ou-12ab-1234abcd.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
AssociationType-
The type of entity included in this association. This value is always
PRINCIPALfor this resource type. CreationTime-
The date and time when the association was created.
External-
Indicates whether the principal belongs to the same organization in AWS Organizations as the AWS account that owns the resource share.
LastUpdatedTime-
The date and time when the association was last updated.
Status-
The current status of the association. Possible values include
ASSOCIATING,ASSOCIATED,FAILED,DISASSOCIATING,DISASSOCIATED,SUSPENDED,SUSPENDING, andRESTORING.
Examples
Associating a principal with a resource share
The following example associates a principal with a resource share.
YAML
AWSTemplateFormatVersion: '2010-09-09' Resources: MyPrincipalAssociation: Type: AWS::RAM::PrincipalAssociation Properties: ResourceShareArn: !Sub arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2 Principal: arn:aws:organizations::999999999999:ou/o-12345abcde/ou-12ab-1234abcd
JSON
{ "AWSTemplateFormatVersion": "2010-09-09", "Resources": { "MyPrincipalAssociation": { "Type": "AWS::RAM::PrincipalAssociation", "Properties": { "ResourceShareArn": { "Fn::Sub": "arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2" }, "Principal": "arn:aws:organizations::999999999999:ou/o-12345abcde/ou-12ab-1234abcd" } } } }
See also
-
AssociateResourceShare in the AWS Resource Access Manager API Reference