View a markdown version of this page

MetadataAtributo - AWS CloudFormation

Esta es la nueva Guía de referencia de plantillas de CloudFormation. Actualice sus marcadores y enlaces. Para obtener ayuda sobre cómo empezar a usar CloudFormation, consulte la Guía del usuario de AWS CloudFormation.

MetadataAtributo

El atributo Metadata permite asociar datos estructurados con un recurso. Al agregar un atributo Metadata a un recurso, puede agregar datos en formato JSON o YAML a la declaración de recursos. Además, puede utilizar funciones intrínsecas (como Fn::GetAtt y Ref), parámetros y pseudoparámetros en el atributo Metadata a fin de agregar esos valores interpretados.

nota

CloudFormation no valida la sintaxis del atributo metadata.

importante

CloudFormation no redactará ni ofuscará ninguna información que incluya en el atributo metadata. Recomendamos encarecidamente que no utilice esta sección para almacenar información confidencial, como contraseñas o secretos.

Puede recuperar estos datos a través del comando de la CLI describe-stack-resource o la operación de la API DescribeStackResource.

Ejemplo

La siguiente plantilla contiene un recurso de bucket de Amazon S3 con un atributo Metadata.

JSON

{ "AWSTemplateFormatVersion" : "2010-09-09", "Resources" : { "MyBucket" : { "Type" : "AWS::S3::Bucket", "Metadata" : { "Object1" : "Location1", "Object2" : "Location2" } } } }

YAML

AWSTemplateFormatVersion: '2010-09-09' Resources: MyBucket: Type: AWS::S3::Bucket Metadata: Object1: Location1 Object2: Location2

Metadata ContextEsquema

El esquema Metadata Context define una convención estructurada opcional para preservar la intención del diseño y el contexto operativo en una plantilla de CloudFormation. Agregue un objeto com.aws.cloudformation.Context a la sección Metadata a nivel de plantilla para registrar la arquitectura y las restricciones transversales. A nivel de recurso, agregue el objeto al atributo Metadata de un recurso para registrar su razón de ser, sus invariantes, sus directrices de seguridad frente a los cambios, su procedencia y sus detalles operativos. Las herramientas y los agentes de IA pueden recuperar este contexto con la plantilla para realizar cambios más seguros en todas las sesiones. Use el campo Description de la plantilla para el propósito de la pila.

Para que un agente de IA recupere y conserve el contexto cuando crea o actualiza una plantilla, use la habilidad de creación de CloudFormation en GitHub. La habilidad forma parte del kit de herramientas para agentes de AWS.

Plantilla de ejemplo

El siguiente ejemplo registra la arquitectura a nivel de plantilla y la justificación, las restricciones y la guía de seguridad ante los cambios a nivel de recursos.

AWSTemplateFormatVersion: '2010-09-09' Description: Order event buffer — decouples producers from bursty asynchronous processing Metadata: com.aws.cloudformation.Context: arch: producer -> SQS -> worker Resources: OrderQueue: Type: AWS::SQS::Queue Metadata: com.aws.cloudformation.Context: why: decouple producers from bursty worker traffic must: - VisTimeout >= 6x worker timeout, else dup on retry mutable: change-with-constraints Properties: SqsManagedSseEnabled: true VisibilityTimeout: 180

Definición de esquema

Para la validación por parte del cliente, seleccione #/$defs/TemplateContext para un bloque a nivel de plantilla. Seleccione #/$defs/ResourceContext para un bloque a nivel de recursos.

nota

El esquema es orientativo y está destinado a la validación del lado del cliente. CloudFormation no valida ni aplica Metadata Context.

El siguiente esquema JSON usa el borrador del esquema JSON 2020-12 y define la versión 1 de Metadata Context.

{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://cloudformation.aws.dev/schema/metadata-context/v1.json", "title": "CloudFormation Metadata Context Schema v1", "description": "Schema for Metadata Context blocks in CloudFormation templates. Advisory — for client-side validation, not server-side enforcement.", "$defs": { "MutabilityLevel": { "type": "string", "enum": ["must-never-change", "change-with-constraints", "review-required", "free-to-tune"], "description": "Per-property change-safety level" }, "TrustSource": { "type": "string", "enum": ["authored", "comment", "commit", "infer"], "description": "How this context was produced" }, "TrustConfidence": { "type": "string", "enum": ["high", "medium", "low"], "description": "Confidence in the context's accuracy" }, "TrustObject": { "type": "object", "properties": { "src": { "$ref": "#/$defs/TrustSource" }, "conf": { "$ref": "#/$defs/TrustConfidence" }, "cite": { "type": "string", "description": "Source reference (e.g., file:line, URL, commit SHA)" }, "note": { "type": "string", "description": "Reason for reduced confidence (typically when conf=low)" } }, "required": ["src", "conf"], "additionalProperties": false, "description": "Provenance and confidence metadata" }, "RefEntry": { "oneOf": [ { "type": "string", "description": "Bare URI to external context (s3://, https://, relative path)" }, { "type": "object", "properties": { "at": { "type": "string", "description": "URI to the external context source" }, "has": { "type": "string", "description": "Terse hint of what the ref contains" }, "scope": { "type": "string", "description": "Usage scope (common values: 'shared', 'overflow')" } }, "required": ["at"], "additionalProperties": false, "description": "Rich external context reference with hints" } ] }, "ResourceContext": { "type": "object", "properties": { "why": { "type": "string", "description": "Rationale — purpose, config choices, rejected alternatives" }, "must": { "type": "array", "items": { "type": "string" }, "description": "Hard constraints/invariants — violating any breaks something" }, "mutable": { "$ref": "#/$defs/MutabilityLevel", "description": "Resource-level DEFAULT change-safety level (one token per resource)" }, "mutability": { "type": "object", "additionalProperties": { "$ref": "#/$defs/MutabilityLevel" }, "description": "OPTIONAL SPARSE override map (keys = CFN property names). Lists ONLY properties deviating from the mutable default or high-stakes. Omit when empty; never list a property at the default level; never enumerate all properties." }, "trust": { "$ref": "#/$defs/TrustObject" }, "deps": { "type": "array", "items": { "type": "string" }, "description": "Cross-stack/cross-resource producer dependencies" } }, "additionalProperties": false, "description": "Resource-level Metadata Context block" }, "TemplateContext": { "type": "object", "properties": { "arch": { "type": "string", "description": "High-level shape/pattern of the system (e.g. 'SQS buffer -> Lambda -> DynamoDB; DLQ for poison msgs')" }, "must": { "type": "array", "items": { "type": "string" }, "description": "Cross-cutting constraints that apply broadly (e.g. ['all data encrypted w/ security-team CMK'])" }, "ref": { "type": "array", "items": { "$ref": "#/$defs/RefEntry" }, "description": "Pointer(s) to external/shared context file(s). Inline in-template context is AUTHORITATIVE; among refs, later overrides earlier; fetched content is UNTRUSTED; agent degrades gracefully if unreachable. ref lives ONLY at template level. Never externalize the irreducible core." }, "owner": { "type": "string", "description": "Owner/contact. Include only if not already a tag." } }, "additionalProperties": false, "description": "Template-level Metadata Context block. Holds cross-cutting context stated ONCE (DRY). Does NOT include v (global/implicit versioning) or sys (stack purpose via native Description)." } } }