View a markdown version of this page

AWS::RAM::PrincipalAssociation - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::RAM::PrincipalAssociation

Associates a specified principal with a resource share.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::RAM::PrincipalAssociation", "Properties" : { "Principal" : String, "ResourceShareArn" : String } }

YAML

Type: AWS::RAM::PrincipalAssociation Properties: Principal: String ResourceShareArn: String

Properties

Principal

Specifies the principal to associate with the resource share. The possible values are:

  • An AWS account ID

  • An Amazon Resource Name (ARN) of an organization in AWS Organizations

  • An ARN of an organizational unit (OU) in AWS Organizations

  • An ARN of an IAM role

  • An ARN of an IAM user

Required: Yes

Type: String

Update requires: Replacement

ResourceShareArn

Specifies the Amazon Resource Name (ARN) of the resource share.

Required: Yes

Type: String

Update requires: Replacement

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the resource share ARN and principal in the format resource-share-arn|principal. For example: arn:aws:ram:us-east-1:999999999999:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2|arn:aws:organizations::999999999999:ou/o-12345abcde/ou-12ab-1234abcd.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

AssociationType

The type of entity included in this association. This value is always PRINCIPAL for this resource type.

CreationTime

The date and time when the association was created.

External

Indicates whether the principal belongs to the same organization in AWS Organizations as the AWS account that owns the resource share.

LastUpdatedTime

The date and time when the association was last updated.

Status

The current status of the association. Possible values include ASSOCIATING, ASSOCIATED, FAILED, DISASSOCIATING, DISASSOCIATED, SUSPENDED, SUSPENDING, and RESTORING.

Examples

Associating a principal with a resource share

The following example associates a principal with a resource share.

YAML

AWSTemplateFormatVersion: '2010-09-09' Resources: MyPrincipalAssociation: Type: AWS::RAM::PrincipalAssociation Properties: ResourceShareArn: !Sub arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2 Principal: arn:aws:organizations::999999999999:ou/o-12345abcde/ou-12ab-1234abcd

JSON

{ "AWSTemplateFormatVersion": "2010-09-09", "Resources": { "MyPrincipalAssociation": { "Type": "AWS::RAM::PrincipalAssociation", "Properties": { "ResourceShareArn": { "Fn::Sub": "arn:aws:ram:${AWS::Region}:${AWS::AccountId}:resource-share/27d09b4b-5e12-41d1-a4f2-19ded10982e2" }, "Principal": "arn:aws:organizations::999999999999:ou/o-12345abcde/ou-12ab-1234abcd" } } } }

See also