cfn-lint Setup

Installing and Configuring cfn-lint

cfn-lint 2,641 (github.com/aws-cloudformation/cfn-lint (https://github.com/aws-cloudformation/cfn-lint 2,641 ), MIT-0, from AWS 24 ) validates templates against the registry schemas of every region, plus rules of its own: bad attribute names, unused parameters, circular dependencies, invalid property values. It needs no account. Install it with pipx 21,050 install cfn-lint==1.57.0, which gives it its own virtual environment, and add the graph extra with pipx inject cfn-lint pydot if you want --build-graph (Dependency Graph). Pinning the version keeps findings stable across a team, because each release adds rules:

Checking the installed cfn-lintYAML
pipx list --short | grep cfn-lint
cfn-lint --version
Output
cfn-lint 1.57.0
cfn-lint 1.57.0

A .cfnlintrc.yaml in the repository root sets the defaults, so a bare cfn-lint checks the whole project:

.cfnlintrc.yaml: BookNest's cfn-lint settingsYAML
templates:
  - infra/*.yaml
ignore_templates:
  - infra/rollback-demo.yaml
regions:
  - us-east-1
  - eu-west-1
Linting every template, then asking for informational findings tooShell
cd ~/v5-ch7/booknest
cfn-lint && echo "cfn-lint: no findings"
cfn-lint --include-checks I -- infra/catalog.yaml | sed 's/ (.*//'
Output
cfn-lint: no findings
I3011 'DeletionPolicy' is a required property
infra/catalog.yaml:3:3
I3011 'UpdateReplacePolicy' is a required property
infra/catalog.yaml:3:3

rollback-demo.yaml is excluded because it fails on purpose (Rollback). Listing two regions catches a resource type or property that one region lacks. Findings are E (errors), W (warnings) and, on request, I (informational), and the exit code is a bitmask (2 errors, 4 warnings, 8 informational), so scripts can decide what blocks a build; --format switches to parseable, json, junit or sarif for CI. Deletion Policies takes the I3011 advice.