Skip to content

feat(cloudformation): exports, deletion policies and DELETE_FAILED (CFN-5) - #1376

Merged
NitinKumar004 merged 1 commit into
developmentfrom
feat/aws-cfn-exports-deletion-policy
Sep 27, 2026
Merged

NitinKumar004 merged 1 commit into
developmentfrom
feat/aws-cfn-exports-deletion-policy

Conversation

@NitinKumar004

Copy link
Copy Markdown
Collaborator

Summary

CFN-5: stack exports and imports, DeletionPolicy and UpdateReplacePolicy, DELETE_FAILED with RetainResources, termination protection, CreateStack failure options, and the account operations. It builds on the CFN-4 converge and change set engine.

Exports and Fn::ImportValue

  • Fn::ImportValue resolves exports in long and short form. An import of a missing export fails the stack with "No export named X found." and follows the failure mode.
  • An import name that depends on a resource, an attribute, another import or Fn::GetAZs is a template error.
  • Export names are unique per region. A second stack exporting a taken name fails with "Export with name X is already exported by stack Y."
  • An export another stack imports cannot be dropped or changed by an update, which rolls back with "Export X cannot be deleted as it is in use by Y" or "Export X cannot be updated as it is in use by Y".
  • DeleteStack of an exporter whose export is in use ends DELETE_FAILED with "Cannot delete export X as it is in use by Y" and deletes nothing.
  • New ListExports and ListImports, both paged. ListImports of an export nothing imports is "Export 'X' is not imported by any stack.".
  • The registry is derived from stack outputs. Each stack records the names it imports, and that list is persisted.

DeletionPolicy and UpdateReplacePolicy

  • Parsed and validated on every resource. Delete, Retain, RetainExceptOnCreate and Snapshot are accepted. Snapshot on a type without snapshots falls back to Delete, as the AWS reference says.
  • Retain keeps the resource on stack delete and on removal in an update, with a DELETE_SKIPPED event. It also keeps it on a create rollback.
  • RetainExceptOnCreate deletes on the rollback of the operation that created the resource. The RetainExceptOnCreate flag on CreateStack, UpdateStack and ExecuteChangeSet also deletes new Retain resources on that rollback (the UpdateStack part of CFN-X9).
  • UpdateReplacePolicy Retain leaves the old resource of a replacement in place, outside the stack.
  • A change to only a DeletionPolicy is an update, not "No updates are to be performed.".
  • Change sets report PolicyAction Retain, Snapshot, ReplaceAndRetain and ReplaceAndSnapshot.
  • The per-resource policies are persisted.

DELETE_FAILED and RetainResources

  • A resource that fails to delete, such as a bucket that still holds objects, stays in the stack as DELETE_FAILED. The stack ends DELETE_FAILED with "The following resource(s) failed to delete: [X].". A create rollback that cannot delete ends ROLLBACK_FAILED.
  • DeleteStack RetainResources is accepted only from DELETE_FAILED, with the real "Invalid operation on stack" error otherwise. DeletionMode FORCE_DELETE_STACK keeps whatever still fails to delete.

Termination protection and CreateStack failure options

  • EnableTerminationProtection on CreateStack, the new UpdateTerminationProtection, and the DeleteStack refusal "Stack [X] cannot be deleted while TerminationProtection is enabled".
  • CreateStack honours OnFailure ROLLBACK, DO_NOTHING and DELETE and DisableRollback (CFN-X11). The two together are refused.

Account operations

  • DescribeAccountLimits returns StackLimit 2000, StackOutputsLimit 200 and ConcurrentResourcesLimit 2500. CreateStack past the stack limit is LimitExceededException, and a template with more than 200 outputs is a template format error.
  • EstimateTemplateCost checks the template and returns a calculator link whose id is a hash of the input.

DescribeStacks now reports EnableTerminationProtection, RetainExceptOnCreate, DeletionMode and DeletionTime. API.DeleteStack takes a DeleteStackInput.

Not in this PR

  • A stack importing its own export is reported as a missing export. The real error text is not known.
  • The "Unrecognized DeletionPolicy" text for a bad value is the best known form and is not measured.

Testing

  • Provider tests for the export guards, paging, policies on delete, removal, create rollback and update rollback, replace policy, DELETE_FAILED and RetainResources, force delete, termination protection, failure options, the stack limit and snapshot round trip. They fail with the guards and policies disabled.
  • Service tests for policy parsing, the outputs limit and ImportValue.
  • Real SDK tests for every new operation and error, plus the compat suite rows for the five new operations.
  • CLI e2e against cloudemu serve: exporter plus importer, blocked update and delete of the exporter, duplicate export, list-imports, a Retain DynamoDB table whose item survives the stack delete, a non-empty bucket ending DELETE_FAILED then deleted with --retain-resources, termination protection, and --on-failure DO_NOTHING and DELETE and --disable-rollback.
  • Terraform aws_cloudformation_stack exporter plus importer: apply, plan clean, update both, plan clean, destroy in dependency order.

@NitinKumar004
NitinKumar004 marked this pull request as ready for review September 27, 2026 15:57
@NitinKumar004
NitinKumar004 merged commit 267c7b8 into development Sep 27, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant