aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap

AWS::EC2::SecurityGroup doesn't support ssm-secure to retrieve SecureString values from SSM.

Open
#1,821 0 comments 0 reactions 0 assignees View on GitHub
Coverage
Dominant language
No language data
Stars
1.1k
Forks
62
PR merge metrics
No merged PRs in 30d

Description

### Name of the resource

AWS::EC2::SecurityGroup

### Resource name

_No response_

### Description

We would like to retrieve a ```SecureString``` SSM parameter value for the `VpcId` property within the [AWS::EC2::SecurityGroup](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-ec2-security-group.html#cfn-ec2-securitygroup-vpcid) but failed with SSM Secure reference is not supported in: [AWS::EC2::SecurityGroup/Properties/VpcId].

We are aware of this resource type is not supported for dynamic parameter patterns for secure strings from the [list](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/dynamic-references.html#template-parameters-dynamic-patterns-resources)

However, we would like you to add 'AWS::EC2::SecurityGroup' to the list so we can retrieve values from SSM as 'SecureString'.

### Other Details

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the AWS::EC2::SecurityGroup VpcId documentation and the dynamic-reference supported-resource list linked in the issue. Confirm how ssm-secure references are handled for SecureString parameters; done means this resource is supported and the documented limitation is updated.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.