aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap

Support Rule Ordering configuration

Open
#959 2 comments 2 reactions 0 assignees View on GitHub
enhancement
Dominant language
No language data
Stars
1.1k
Forks
62
PR merge metrics
No merged PRs in 30d

Description

### Name of the resource

AWS::NetworkFirewall::FirewallPolicy

### Resource name

_No response_

### Description

AWS added a new rule ordering option for AWS NetworkFirewall which can't currently be configured using Cloudformation (https://aws.amazon.com/about-aws/whats-new/2021/10/aws-firewall-configuration-rule-ordering-drop/)

This is especially daunting as it can't be adjusted after resource creation. Leaving only the option the manually create everything.

This request applies to:

- AWS::NetworkFirewall::FirewallPolicy
- AWS::NetworkFirewall::RuleGroup

### Other Details

https://docs.aws.amazon.com/network-firewall/latest/APIReference/API_StatefulEngineOptions.html#networkfirewall-Type-StatefulEngineOptions-RuleOrder

Contributor guide

Open the contributing guide

Research direction

Start with the AWS::NetworkFirewall::FirewallPolicy and AWS::NetworkFirewall::RuleGroup resource entry points, then read the linked StatefulEngineOptions API reference and the rule-ordering announcement. Done means CloudFormation can configure the new rule ordering option for both resources, including the creation-time behavior described in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.