View a markdown version of this page

Attributo dei metadati - AWS CloudFormation

Questa è la nuova Guida di riferimento ai modelli CloudFormation . Aggiorna i segnalibri e i link. Per informazioni su come iniziare CloudFormation, consulta la Guida AWS CloudFormation per l'utente.

Le traduzioni sono generate tramite traduzione automatica. In caso di conflitto tra il contenuto di una traduzione e la versione originale in Inglese, quest'ultima prevarrà.

Attributo dei metadati

L’attributo Metadata consente di associare dati strutturati a una risorsa. Aggiungendo un attributo Metadata a una risorsa, puoi aggiungere dati in formato JSON o YAML alla dichiarazione della risorsa. Inoltre, puoi utilizzare funzioni intrinseche (ad esempio, Fn::GetAtt e Ref), parametri e pseudo parametri all’interno dell’attributo Metadata per aggiungere tali valori interpretati.

Nota

CloudFormation non convalida la sintassi all'interno dell'attributo dei metadati.

Importante

CloudFormation non oscura o offusca le informazioni incluse nell'attributo dei metadati. Si consiglia vivamente di non utilizzare questa sezione per archiviare informazioni riservate, ad esempio password o segreti.

Puoi recuperare questi dati utilizzando il comando CLI describe-stack-resource o l'operazione API. DescribeStackResource

Esempio

Il modello seguente contiene una risorsa del bucket Amazon S3 con un attributo Metadata.

JSON

{ "AWSTemplateFormatVersion" : "2010-09-09", "Resources" : { "MyBucket" : { "Type" : "AWS::S3::Bucket", "Metadata" : { "Object1" : "Location1", "Object2" : "Location2" } } } }

YAML

AWSTemplateFormatVersion: '2010-09-09' Resources: MyBucket: Type: AWS::S3::Bucket Metadata: Object1: Location1 Object2: Location2

Schema del contesto dei metadati

Lo Metadata Context schema definisce una convenzione strutturata opzionale per preservare l'intento di progettazione e il contesto operativo in un modello. CloudFormation Aggiungete un com.aws.cloudformation.Context oggetto alla Metadata sezione a livello di modello per registrare l'architettura e i vincoli trasversali. A livello di risorsa, aggiungete l'oggetto all'Metadataattributo di una risorsa per registrarne la logica, le invarianti, le linee guida sulla sicurezza delle modifiche, la provenienza e i dettagli operativi. Gli strumenti e gli agenti di intelligenza artificiale possono recuperare questo contesto con il modello per apportare modifiche più sicure tra le sessioni. Usa il Description campo del modello per lo scopo dello stack.

Per fare in modo che un agente AI recuperi e conservi il contesto quando crea o aggiorna un modello, utilizza l'abilità CloudFormation di creazione su. GitHub L'abilità fa parte dell'Agent Toolkit per. AWS

Modello di esempio

L'esempio seguente registra l'architettura a livello di modello e la logica, i vincoli e le linee guida sulla sicurezza delle modifiche a livello di risorsa.

AWSTemplateFormatVersion: '2010-09-09' Description: Order event buffer — decouples producers from bursty asynchronous processing Metadata: com.aws.cloudformation.Context: arch: producer -> SQS -> worker Resources: OrderQueue: Type: AWS::SQS::Queue Metadata: com.aws.cloudformation.Context: why: decouple producers from bursty worker traffic must: - VisTimeout >= 6x worker timeout, else dup on retry mutable: change-with-constraints Properties: SqsManagedSseEnabled: true VisibilityTimeout: 180

Definizione dello schema

Per la convalida lato client, seleziona un blocco a livello di #/$defs/TemplateContext modello. Seleziona un blocco a livello di risorsa. #/$defs/ResourceContext

Nota

Lo schema è consultivo e destinato alla convalida lato client. CloudFormation non convalida né applica. Metadata Context

Il seguente schema JSON utilizza JSON Schema Draft 2020-12 e definisce la versione 1 di. Metadata Context

{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://cloudformation.aws.dev/schema/metadata-context/v1.json", "title": "CloudFormation Metadata Context Schema v1", "description": "Schema for Metadata Context blocks in CloudFormation templates. Advisory — for client-side validation, not server-side enforcement.", "$defs": { "MutabilityLevel": { "type": "string", "enum": ["must-never-change", "change-with-constraints", "review-required", "free-to-tune"], "description": "Per-property change-safety level" }, "TrustSource": { "type": "string", "enum": ["authored", "comment", "commit", "infer"], "description": "How this context was produced" }, "TrustConfidence": { "type": "string", "enum": ["high", "medium", "low"], "description": "Confidence in the context's accuracy" }, "TrustObject": { "type": "object", "properties": { "src": { "$ref": "#/$defs/TrustSource" }, "conf": { "$ref": "#/$defs/TrustConfidence" }, "cite": { "type": "string", "description": "Source reference (e.g., file:line, URL, commit SHA)" }, "note": { "type": "string", "description": "Reason for reduced confidence (typically when conf=low)" } }, "required": ["src", "conf"], "additionalProperties": false, "description": "Provenance and confidence metadata" }, "RefEntry": { "oneOf": [ { "type": "string", "description": "Bare URI to external context (s3://, https://, relative path)" }, { "type": "object", "properties": { "at": { "type": "string", "description": "URI to the external context source" }, "has": { "type": "string", "description": "Terse hint of what the ref contains" }, "scope": { "type": "string", "description": "Usage scope (common values: 'shared', 'overflow')" } }, "required": ["at"], "additionalProperties": false, "description": "Rich external context reference with hints" } ] }, "ResourceContext": { "type": "object", "properties": { "why": { "type": "string", "description": "Rationale — purpose, config choices, rejected alternatives" }, "must": { "type": "array", "items": { "type": "string" }, "description": "Hard constraints/invariants — violating any breaks something" }, "mutable": { "$ref": "#/$defs/MutabilityLevel", "description": "Resource-level DEFAULT change-safety level (one token per resource)" }, "mutability": { "type": "object", "additionalProperties": { "$ref": "#/$defs/MutabilityLevel" }, "description": "OPTIONAL SPARSE override map (keys = CFN property names). Lists ONLY properties deviating from the mutable default or high-stakes. Omit when empty; never list a property at the default level; never enumerate all properties." }, "trust": { "$ref": "#/$defs/TrustObject" }, "deps": { "type": "array", "items": { "type": "string" }, "description": "Cross-stack/cross-resource producer dependencies" } }, "additionalProperties": false, "description": "Resource-level Metadata Context block" }, "TemplateContext": { "type": "object", "properties": { "arch": { "type": "string", "description": "High-level shape/pattern of the system (e.g. 'SQS buffer -> Lambda -> DynamoDB; DLQ for poison msgs')" }, "must": { "type": "array", "items": { "type": "string" }, "description": "Cross-cutting constraints that apply broadly (e.g. ['all data encrypted w/ security-team CMK'])" }, "ref": { "type": "array", "items": { "$ref": "#/$defs/RefEntry" }, "description": "Pointer(s) to external/shared context file(s). Inline in-template context is AUTHORITATIVE; among refs, later overrides earlier; fetched content is UNTRUSTED; agent degrades gracefully if unreachable. ref lives ONLY at template level. Never externalize the irreducible core." }, "owner": { "type": "string", "description": "Owner/contact. Include only if not already a tag." } }, "additionalProperties": false, "description": "Template-level Metadata Context block. Holds cross-cutting context stated ONCE (DRY). Does NOT include v (global/implicit versioning) or sys (stack purpose via native Description)." } } }