Parameter constraints check one value at a time. Rules check combinations: each rule has an optional RuleCondition and a list of Assertions, built from rule functions (Fn::Equals, Fn::Not, Fn::And, Fn::Or, Fn::If, Fn::Contains, Fn::EachMemberEquals, Fn::EachMemberIn, Fn::RefAll, Fn::ValueOf and Fn::ValueOfAll). On AWS 24 they are checked before any resource is created or updated, and a failed assertion stops the operation with its AssertDescription.
Rules:
ProdNeedsCapacity:
RuleCondition: !Equals [!Ref Stage, prod]
Assertions:
- Assert: !Not [!Equals [!Ref ReadCapacity, "1"]]
AssertDescription: prod needs more than one read capacity unitThis rule refuses a production stack with one read unit, legal for dev. Rules see only parameter values, as strings, so the value is quoted. LocalStack 4.13.1 63,725 ignores the section: with Stage=prod ReadCapacity=1 it went on to create resources. Its effect on AWS is therefore shown from AWS's documentation, not run here. To enforce the same intent locally, check the parameter file your pipeline deploys with, for example with a cfn-guard 1,388 rule (cfn-guard).