Each resource has a logical ID, the key you choose under Resources, unique within the template. The service returns a physical ID, the real name or ARN; unless you set a name yourself, CloudFormation 24 generates one from the stack name, the logical ID and a random suffix. This section's examples use infra/graph.yaml:
AWSTemplateFormatVersion: "2010-09-09"
Resources:
FrontEndBucket:
Type: AWS::S3::Bucket
BooksTable:
Type: AWS::DynamoDB::Table
Properties:
BillingMode: PAY_PER_REQUEST
AttributeDefinitions: [{AttributeName: id, AttributeType: N}]
KeySchema: [{AttributeName: id, KeyType: HASH}]
ApiRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- {Effect: Allow, Principal: {Service: lambda.amazonaws.com}, Action: sts:AssumeRole}
Policies:
- PolicyName: read-books
PolicyDocument:
Version: "2012-10-17"
Statement:
- {Effect: Allow, Action: dynamodb:Scan, Resource: !GetAtt BooksTable.Arn}
ApiRoleParam:
Type: AWS::SSM::Parameter
Properties: {Name: /booknest/api-role-arn, Type: String, Value: !GetAtt ApiRole.Arn}cd ~/v5-ch7/booknest/infra
aws cloudformation deploy --stack-name booknest-graph --template-file graph.yaml \
--capabilities CAPABILITY_IAM
aws cloudformation describe-stack-resources --stack-name booknest-graph --output text \
--query 'StackResources[].[LogicalResourceId,PhysicalResourceId]'Output
Waiting for changeset to be created.. Waiting for stack create/update to complete Successfully created/updated stack - booknest-graph BooksTable booknest-graph-BooksTable-03e7f80f ApiRole booknest-graph-ApiRole-fefe8b0c ApiRoleParam /booknest/api-role-arn FrontEndBucket booknest-graph-frontendbucket-7123a31b
CAPABILITY_IAM acknowledges that the stack creates IAM resources (IAM for CloudFormation). Generated names let two stacks share a template and let CloudFormation replace a resource (new one first, then delete the old) when a property cannot change in place; fixed names block that. Renaming a logical ID is itself a replacement.