This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::NetworkSecurityManager::Template
The AWS::NetworkSecurityManager::Template resource specifies an AWS Network Security Manager template. A template groups one or more rules so that you can reuse the same set of protections across policies. You can also associate rules with a policy directly, without using a template.
You reference a template from a policy, then roll the protections out to the accounts and resources selected by a scope. Templates created with this resource are always published in ACTIVE state; CloudFormation does not create templates in DRAFT state.
For conceptual information and guidance on writing rule configurations, see the AWS Network Security Manager Developer Guide. For the default quotas that apply to your account, see Quotas.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::NetworkSecurityManager::Template", "Properties" : { "AssociatedRuleList" :[ AssociatedRule, ... ], "FirewallType" :String, "Tags" :[ Tag, ... ], "TemplateDescription" :String, "TemplateName" :String} }
YAML
Type: AWS::NetworkSecurityManager::Template Properties: AssociatedRuleList:- AssociatedRuleFirewallType:StringTags:- TagTemplateDescription:StringTemplateName:String
Properties
AssociatedRuleList-
The rules associated with the template.
This property is required when you create a template. You must associate at least one rule; AWS Network Security Manager rejects a template that has no associated rules.
Required: Conditional
Type: Array of AssociatedRule
Minimum:
1Maximum:
50Update requires: No interruption
FirewallType-
The type of firewall that the template configures.
WAFspecifies an AWS WAF template. All rules that you associate with the template must use the same firewall type.This property is required when you create a template. You can't change the firewall type after you create the template.
Required: Conditional
Type: String
Allowed values:
WAF | NETWORK_FIREWALL | NETWORK_FIREWALL_V2 | IGW_FIREWALLUpdate requires: Replacement
-
The tags to assign to the template. Each tag is a key-value pair. You can add tags when you create the template and change them afterward without replacing the template. You can assign up to 200 tags to a template.
For more information, see Tag.
Required: No
Type: Array of Tag
Update requires: No interruption
TemplateDescription-
A description of the template.
Required: No
Type: String
Pattern:
[a-zA-Z0-9 _.:/=+\-@]*Minimum:
0Maximum:
256Update requires: No interruption
TemplateName-
The name of the template.
You can't change the name of a template after you create it.
Required: Yes
Type: String
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*Minimum:
1Maximum:
128Update requires: Replacement
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the template. For example:
{ "Ref": "myTemplate" }
For a template named common-waf-baseline, Ref returns a value similar to arn:aws:network-security-manager:us-east-1:123456789012:template:a1b2c3d4e5f6.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
Status-
The current status of the template. Templates created with this resource are always published, so this value is always
ACTIVE.Allowed Values:
DRAFT|ACTIVE TemplateArn-
The Amazon Resource Name (ARN) of the template.
TemplateId-
The service-generated id of the template.
UpdatedAt-
The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.
Version-
The version of the template. AWS Network Security Manager assigns version
1when it publishes the template and increments the version each time the template is published again, including each time CloudFormation updates it.
Examples
Group a rule into a reusable template
YAML
AWSTemplateFormatVersion: "2010-09-09" Description: Groups Network Security Manager rules into a reusable template. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' BaselineTemplate: Type: AWS::NetworkSecurityManager::Template Properties: TemplateName: waf-baseline TemplateDescription: Baseline web ACL settings for every account. FirewallType: WAF AssociatedRuleList: - RuleArn: !GetAtt AllowByDefaultRule.RuleArn Outputs: TemplateArn: Value: !GetAtt BaselineTemplate.TemplateArn