This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::ImageBuilder::LifecyclePolicy
Creates a lifecycle policy resource.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::ImageBuilder::LifecyclePolicy", "Properties" : { "Description" :String, "ExecutionRole" :String, "Name" :String, "PolicyDetails" :[ PolicyDetail, ... ], "ResourceSelection" :ResourceSelection, "ResourceType" :String, "Status" :String, "Tags" :{} }Key:Value, ...}
YAML
Type: AWS::ImageBuilder::LifecyclePolicy Properties: Description:StringExecutionRole:StringName:StringPolicyDetails:- PolicyDetailResourceSelection:ResourceSelectionResourceType:StringStatus:StringTags:Key:Value
Properties
Description-
Optional description for the lifecycle policy.
Required: No
Type: String
Minimum:
1Maximum:
1024Update requires: No interruption
ExecutionRole-
The name or Amazon Resource Name (ARN) for the IAM role you create that grants Image Builder access to run lifecycle actions. You must have permission to pass the role, and the role's trust policy must allow the Image Builder service principal to assume it.
Required: Yes
Type: String
Pattern:
^(?:arn:aws(?:-[a-z]+)*:iam::[0-9]{12}:role/)?[a-zA-Z_0-9+=,.@\-_/]+$Minimum:
1Maximum:
2048Update requires: No interruption
Name-
The name of the lifecycle policy to create. Policy names must be unique to your account in each AWS Region. Image Builder generates the policy ARN from a normalized form of the name, so names that differ only in case, spaces, or underscores count as the same name. You can't change the name after creation.
Required: Yes
Type: String
Pattern:
^[-_A-Za-z-0-9][-_A-Za-z0-9 ]{1,126}[-_A-Za-z-0-9]$Update requires: Replacement
PolicyDetails-
Configuration details for the lifecycle policy rules. A policy can contain at most one rule per action type: one
DELETE, oneDEPRECATE, and oneDISABLE.Required: Yes
Type: Array of PolicyDetail
Minimum:
1Maximum:
3Update requires: No interruption
ResourceSelection-
Selection criteria for the resources that the lifecycle policy applies to. You must specify exactly one selection criteria: either recipes or a tag map, not both.
Required: Yes
Type: ResourceSelection
Update requires: No interruption
ResourceType-
The type of Image Builder resource that the lifecycle policy applies to. The resource type determines the allowed rule actions: policies for AMI-based Image Builder images support
DELETE,DEPRECATE, andDISABLE, and policies for container-based Image Builder images support onlyDELETE. You can't change the resource type after creation.Required: Yes
Type: String
Allowed values:
AMI_IMAGE | CONTAINER_IMAGEUpdate requires: No interruption
Status-
Indicates whether the lifecycle policy resource is enabled. If you don't specify a status, it defaults to
ENABLED. Only enabled policies run on their schedule.Required: No
Type: String
Allowed values:
DISABLED | ENABLEDUpdate requires: No interruption
-
Tags to apply to the lifecycle policy resource.
Required: No
Type: Object of String
Pattern:
.{1,}Update requires: No interruption
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the resource ARN, such as
arn:aws:imagebuilder:us-west-2:111122223333:lifecycle-policy/my-example-policy.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
Arn-
The Amazon Resource Name (ARN) of the lifecycle policy resource.
Examples
Create a lifecycle policy that deletes AMIs older than 90 days
The following example creates a lifecycle policy that deletes AMIs older than 90 days, while retaining the three most recent images. The policy applies to images produced by a specific image recipe.
YAML
Resources: LifecyclePolicyExample: Type: AWS::ImageBuilder::LifecyclePolicy Properties: Name: delete-old-amis-policy Description: Delete AMIs older than 90 days Status: ENABLED ResourceType: AMI_IMAGE ExecutionRole: !GetAtt LifecyclePolicyRole.Arn PolicyDetails: - Action: Type: DELETE IncludeResources: Amis: true Snapshots: true Filter: Type: AGE Value: 90 Unit: DAYS RetainAtLeast: 3 ExclusionRules: Amis: IsPublic: true TagMap: DoNotDelete: 'true' ResourceSelection: Recipes: - Name: my-image-recipe SemanticVersion: '1.0.0' Tags: Purpose: cleanup
JSON
{ "Resources": { "LifecyclePolicyExample": { "Type": "AWS::ImageBuilder::LifecyclePolicy", "Properties": { "Name": "delete-old-amis-policy", "Description": "Delete AMIs older than 90 days", "Status": "ENABLED", "ResourceType": "AMI_IMAGE", "ExecutionRole": { "Fn::GetAtt": ["LifecyclePolicyRole", "Arn"] }, "PolicyDetails": [ { "Action": { "Type": "DELETE", "IncludeResources": { "Amis": true, "Snapshots": true } }, "Filter": { "Type": "AGE", "Value": 90, "Unit": "DAYS", "RetainAtLeast": 3 }, "ExclusionRules": { "Amis": { "IsPublic": true, "TagMap": { "DoNotDelete": "true" } } } } ], "ResourceSelection": { "Recipes": [ { "Name": "my-image-recipe", "SemanticVersion": "1.0.0" } ] }, "Tags": { "Purpose": "cleanup" } } } } }
See also
-
Manage image lifecycles in the Image Builder User Guide.