A stack policy is a JSON document that says which update actions (Update:Modify, Update:Replace, Update:Delete, Update:*) are allowed on which logical IDs, for every caller and during updates only. Once a stack has one, whatever is not allowed is denied, and Deny beats Allow. This one protects the catalog table:
{
"Statement": [
{"Effect": "Allow", "Action": "Update:*", "Principal": "*", "Resource": "*"},
{"Effect": "Deny", "Action": "Update:*", "Principal": "*",
"Resource": "LogicalResourceId/BooksTable"}
]
}aws cloudformation set-stack-policy --stack-name booknest-fn \
--stack-policy-body file://stack-policy.json 2>&1 | fold -s -w 90aws: [ERROR]: An error occurred (InternalFailure) when calling the SetStackPolicy operation: Sorry, the SetStackPolicy operation on the cloudformation service is not currently supported by LocalStack.
LocalStack 4.13.1 63,725 has no stack policies, so the rest is AWS 24 's documented behavior, not run here. With the policy set, the stage switch of Previewing Changes would be refused for BooksTable and the update rolled back. To change a protected resource on purpose, pass a temporary override for one update, update-stack --stack-policy-during-update-body file://allow-all.json; the stored policy is unchanged afterwards. A policy cannot be removed, only replaced, and a Condition on ResourceType protects every resource of a type. Prefer Deny statements to NotResource, which AWS warns does not reliably protect a resource. Who may update stacks at all is IAM's job (IAM for CloudFormation).