Pseudo parameters are predefined, read with Ref or inside Fn::Sub, and never declared. They keep one template portable across accounts, regions and partitions, the separate AWS 24 worlds such as China (aws-cn) and GovCloud (aws-us-gov) whose ARNs and domains differ. The last slice of functions.yaml reads them:
AccountId: {Value: !Ref AWS::AccountId}
Region: {Value: !Ref AWS::Region}
Partition: {Value: !Ref AWS::Partition}
UrlSuffix: {Value: !Ref AWS::URLSuffix}
BuiltArn:
Value: !Sub
- arn:${AWS::Partition}:dynamodb:${AWS::Region}:${AWS::AccountId}:table/${Name}
- Name: !Ref BooksTable| Pseudo parameter | LocalStack 4.13.1 | Real AWS |
|---|---|---|
| AWS::AccountId | 000000000000 | Your 12-digit account |
| AWS::Region | us-east-1, from the CLI | The stack's region |
| AWS::Partition | aws | aws, aws-cn, aws-us-gov |
| AWS::URLSuffix | localhost.localstack.cloud | amazonaws.com, amazonaws.com.cn |
| AWS::NotificationARNs | Empty, even with --notification-arns | The stack's SNS topics |
AWS::StackName, AWS::StackId and AWS::NoValue behave as on AWS. Hard-code none of these values: arn:aws: breaks in China, an account number breaks in the next account, and amazonaws.com breaks under LocalStack. BuiltArn matches TableArn in Ref and GetAtt's output, but only to show the parts: where a type publishes Arn, use !GetAtt. Building ARNs belongs in patterns such as arn:${AWS::Partition}:s3:::booknest-* in an IAM policy (IAM for CloudFormation).