aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap

Support applying account-level data protection policy to all log groups in an account via CFN

Open
#1,731 0 comments 1 reaction 0 assignees View on GitHub
Coverage enhancement
Dominant language
No language data
Stars
1.1k
Forks
62
PR merge metrics
No merged PRs in 30d

Description

### Name of the resource

Other

### Resource name

AWS::Logs::<>

### Description

Account-level data protection policy feature of CloudWatch was announced just recently on: Jun 8, 2023:
https://aws.amazon.com/about-aws/whats-new/2023/06/amazon-cloudwatch-logs-data-protection-policy-configuration/

While there is a way in CFN to set data protection policy for a single log group using the "DataProtectionPolicy" property of resource: AWS::Logs::LogGroup, there seems to be no way currently to set this policy on account-level via CFN, as is possible via Cloudwatch Console, CLI and API.

This request is to support the above feature in CloudFormation.

### Other Details

_No response_

Contributor guide

Open the contributing guide

Research direction

No repository files, tests, or entry points are identified. Start by reviewing the CloudFormation coverage roadmap conventions and the linked CloudWatch account-level data protection policy announcement, then compare the console, CLI, and API behavior with the existing AWS::Logs::LogGroup DataProtectionPolicy support. Done means account-level policy configuration is available through CloudFormation.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.