AWS Service Catalog AppRegistry will no longer be open to new customers starting July 30, 2026. If you would like to use the service, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see AWS Service Catalog AppRegistry availability change.
This topic includes policy templates that you can use to control how tag key-value pairs are associated to applications.
The following policy templates are organized by scenario and include values that can be replaced with your information.
Sample policy: Stack only association
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": "servicecatalog:AssociateResource",
"Resource": "arn:aws:servicecatalog:*:*:*",
"Condition": {
"StringNotEquals": {
"servicecatalog:ResourceType": "CFN_STACK"
}
}
}
]
}
Sample policy: Stack association that allows a specific stack name
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"servicecatalog:ResourceType": "CFN_STACK"
}
}
}
]
}
Sample policy: Stack association that allows multiple specific stack names
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"servicecatalog:ResourceType": "CFN_STACK"
}
}
}
]
}
Sample policy: Tag value association that denies a specific tag query value while allowing other tag queries
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"servicecatalog:ResourceType": "TAG_QUERY"
}
}
}
]
}
Sample policy: Allow tag query association only
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"servicecatalog:ResourceType": "TAG_QUERY"
}
}
}
]
}
Sample policy: Allow tag query association/deny specific tag query values
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"servicecatalog:ResourceType": "CFN_STACK"
}
}
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"servicecatalog:ResourceType": ["TAG_QUERY"]
}
}
}
]
}
Sample policy: Allow specific tag query value and specific stack
- JSON
-
-
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"servicecatalog:*",
"cloudformation:DescribeStacks",
"resource-groups:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"servicecatalog:AssociateResource"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"servicecatalog:ResourceType": "CFN_STACK"
}
}
}
]
}