SimAWSby ShahriarLabs
Search

Infrastructure as code · Chapter 1 of 1

How CloudFormation manages infrastructure as state

Describing infrastructure in code ensures consistency, but executing updates requires evaluating changesets to prevent accidental resource deletion.

FoundationsBuilds the idea from nothing. No prior AWS assumed.

Declarative infrastructure and state management

What is the advantage of declaring infrastructure in a template?

UploadPreviewPreviewDeveloperTemplate EditCloudFormationChange Set EngineDatabase (RDS)Live ProductionSecurity GroupEC2 SecurityCloudFormation change sets allow you to preview stack updates before executing them, highlighting changes that cause resource replacement and subsequent data loss.

A developer edits a CloudFormation template to update security rules and change the database configuration.

1/6
  1. 01

    The problem with manual configuration

    Building environments by clicking in the AWS console leaves no record of changes, makes duplicating environments impossible, and results in configuration drift.

  2. 02

    Declarative desired state

    A CloudFormation template describes the resources you want and their properties. CloudFormation compares this template to your live environment, executing the API calls to match the desired state.

  3. 03

    The risk of resources out of management

    If an engineer modifies a CloudFormation-managed resource manually, the stack enters a state of drift. Future template updates can fail or overwrite manual changes unexpectedly.

Check yourself

What does configuration drift mean in a CloudFormation stack?

Under the hoodThe same thing from underneath: limits, failure modes, numbers.

Changesets rollbacks and resource replacement

Why can updating a template attribute delete your database?

UploadPreviewPreviewDeveloperTemplate EditCloudFormationChange Set EngineDatabase (RDS)Live ProductionSecurity GroupEC2 SecurityCloudFormation change sets allow you to preview stack updates before executing them, highlighting changes that cause resource replacement and subsequent data loss.

A developer edits a CloudFormation template to update security rules and change the database configuration.

1/6
  1. 01

    The danger of resource replacement

    When you update a property, CloudFormation evaluates whether it can update the resource in place. If the change requires a replacement, CloudFormation deletes the resource and creates a new one.

  2. 02

    Inspecting changes with changesets

    To prevent accidental deletions, you must generate a changeset before executing an update. A changeset details whether each resource will be modified, added, or replaced.

  3. 03

    Rollback behaviour on failure

    If any resource fails to create or update during a deployment, CloudFormation automatically rolls back the entire stack, deleting newly created resources to restore the last stable state.

The numbers

Maximum resources per stack
500 resourcesThe limit on the number of resources in a single template. Can be extended using nested stacks.
Maximum template size
51,200 bytesThe limit for templates passed directly to the API, or 1 MB when uploaded to S3.
Default stack timeout
No default timeoutUpdates run until completion or failure, but you can configure a timeout to force rollbacks.

Check yourself

You change the database engine property in your template and update the stack. Why is this update extremely risky?

Official references & further reading

These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.

Report an error or suggest a clearer explanation →