aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap

Rebuild Specific Stack Resources Individually

Open
#1,276 0 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
No language data
Stars
1.1k
Forks
62
PR merge metrics
No merged PRs in 30d

Description

### Name of the resource

AWS::CloudFormation::Stack

### Resource name

_No response_

### Description

## Summary
I would like to be able to mark the VPN instance as protected, with a feature that allows destroying and rebuilding all non-protected resources within the stack.

## Situation
User desires the ability to reset a stack instance with the ability to retain the state of certain resources while rebuilding others from scratch in accordance with their template. This could be accomplished by allowing certain resources to be tagged as protected (with cascading effects to their dependencies) and functionality to allow all but the protected instances to be destroyed and rebuilt without completely destroying the stack instance.

## Use Case
Using CloudFormation Stacks to facilitate user-driven lab environments for training purposes. A user is given a public VPN and a configuration file to access the generated network. Sometimes, the user may accidentally perform a destructive action on a lab machine, causing the lab to cease functioning properly. My current understanding of the CloudFormation functionality is that I must destroy the stack and build a new one in order to reset a single machine. This is okay, but not preferable because it requires the user of the lab environment to rebuild their VPN server. This requires them to replace their VPN configuration file, which is acceptable but not a preferred user experience.

### Other Details

_No response_

Contributor guide

Open the contributing guide

Research direction

No repository files, tests, or implementation entry points are named. Start by reviewing the AWS::CloudFormation::Stack behavior described in the issue, especially protected resources and dependency cascading. Done means defining and implementing a way to rebuild non-protected stack resources while retaining protected resources and their state.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.