Logical and Physical IDs

Resources, Logical IDs and Physical IDs

Each resource has a logical ID, the key you choose under Resources, unique within the template. The service returns a physical ID, the real name or ARN; unless you set a name yourself, CloudFormation 24 generates one from the stack name, the logical ID and a random suffix. This section's examples use infra/graph.yaml:

infra/graph.yaml: four resources that reference each otherYAML
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  FrontEndBucket:
    Type: AWS::S3::Bucket
  BooksTable:
    Type: AWS::DynamoDB::Table
    Properties:
      BillingMode: PAY_PER_REQUEST
      AttributeDefinitions: [{AttributeName: id, AttributeType: N}]
      KeySchema: [{AttributeName: id, KeyType: HASH}]
  ApiRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - {Effect: Allow, Principal: {Service: lambda.amazonaws.com}, Action: sts:AssumeRole}
      Policies:
        - PolicyName: read-books
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - {Effect: Allow, Action: dynamodb:Scan, Resource: !GetAtt BooksTable.Arn}
  ApiRoleParam:
    Type: AWS::SSM::Parameter
    Properties: {Name: /booknest/api-role-arn, Type: String, Value: !GetAtt ApiRole.Arn}
Deploying the stack and listing its logical and physical IDsShell
cd ~/v5-ch7/booknest/infra
aws cloudformation deploy --stack-name booknest-graph --template-file graph.yaml \
  --capabilities CAPABILITY_IAM
aws cloudformation describe-stack-resources --stack-name booknest-graph --output text \
  --query 'StackResources[].[LogicalResourceId,PhysicalResourceId]'
Output
Waiting for changeset to be created..
Waiting for stack create/update to complete
Successfully created/updated stack - booknest-graph
BooksTable   booknest-graph-BooksTable-03e7f80f
ApiRole   booknest-graph-ApiRole-fefe8b0c
ApiRoleParam   /booknest/api-role-arn
FrontEndBucket   booknest-graph-frontendbucket-7123a31b

CAPABILITY_IAM acknowledges that the stack creates IAM resources (IAM for CloudFormation). Generated names let two stacks share a template and let CloudFormation replace a resource (new one first, then delete the old) when a property cannot change in place; fixed names block that. Renaming a logical ID is itself a replacement.