Lesson 220 · AWS Learning Path

AWS 220: Parameters, outputs and intrinsic functions

· Published · 7 min read

Labelled process diagram for AWS 220: Reviewed input contract to Intrinsic resolution to Resource properties to Safe output or cross-stack interface, with decision, proof and rejection evidence.

Why this lesson matters

Parameters are an input API, intrinsic functions form a dependency-aware expression language, and outputs are a visible stack interface. Poor contracts allow invalid deployments, leak sensitive values, or lock many stacks to one export. This lesson reads every P11 expression and predicts its resolved value without creating resources.

What you will be able to do

By the end, you can:

  • choose String, Number, list, AWS-specific and SSM parameter types;
  • apply defaults, allowed values/patterns, ranges and useful constraint messages;
  • distinguish parameters, mappings, pseudo parameters, conditions and dynamic references;
  • explain Ref, GetAtt, Sub, Join, Split, Select, If and ImportValue;
  • predict implicit dependencies created by resource references;
  • explain NoEcho limitations and keep secrets out of outputs/identifiers;
  • decide when exports are appropriate and when they create harmful coupling;
  • verify P11's effective input/output contract with get-template-summary.

The five value sources

SourceResolved fromBest useMain risk
Parameteroperator/pipeline at stack operationbounded environment-specific inputunconstrained input or exposed secret
Mappingstatic values versioned in templatesmall controlled lookupstale Region/AMI catalogue
Pseudo parameterCloudFormation contextaccount, Region, partition, stack identityassuming the standard aws partition
Resource referencecreated/imported resourcedependency-aware physical ID/attributereplacement coupling
Dynamic referenceSystems Manager or Secrets Manager at operation timeexternal configuration/secret resolutionpermissions, version rotation and unsupported-context constraints

Do not turn every property into a parameter. Parameterize values that legitimately vary between deployments and have an owner. Keep invariant security requirements - encryption and public blocking in P11 - inside reviewed code.

Parameter types and validation

CloudFormation supports primitive String and Number, list forms such as CommaDelimitedList and List<Number>, AWS-specific types such as AWS::EC2::VPC::Id, and Systems Manager parameter value types. AWS-specific types let the Console validate and present values available to the caller in the current account/Region. They do not prove ownership, routing suitability or authorization.

Use:

  • AllowedValues for a closed vocabulary;
  • AllowedPattern for a full-string regular expression on String values;
  • MinLength/MaxLength for strings;
  • MinValue/MaxValue for numbers;
  • ConstraintDescription for a human correction instead of only a regex error;
  • defaults only when the default is safe in every intended deployment.

P11 restricts Environment, LogRetentionDays, and the string Boolean CreateIngestionAlarm. CloudFormation has no Boolean parameter type, so quoted 'true' and 'false' are strings.

Secret rules

NoEcho: true masks a parameter in common stack descriptions, but it does not make the template a secret-management system. It does not mask values copied into Metadata, Outputs, resource metadata, or identifiers that another service exposes. Parameters can also appear in deployment commands and shell history.

Prefer a Secrets Manager or secure Systems Manager reference where the target resource property supports it. Keep secret values out of outputs, tags, names, logs and primary identifiers. The execution role needs access to resolve the secret. Plan rotation behavior: changing a secret in its store does not necessarily cause CloudFormation to update an unchanged resource automatically.

Intrinsic functions by behavior

FunctionResult
RefParameter value or resource-specific return value, often a physical name/ID
Fn::GetAttDocumented resource attribute such as the P11 bucket ARN
Fn::SubString interpolation of parameters, pseudo parameters, attributes and a variable map
Fn::JoinConcatenate list values with a delimiter
Fn::SplitSplit one string into a list
Fn::SelectSelect a zero-based list item; invalid index/null fails
Fn::FindInMapRead a static mapping key
Fn::IfSelect values based on a declared condition; usable in supported property/metadata/update-policy/output contexts
Fn::ImportValueRead an export from another stack in the same account and Region
condition functionsEquals, And, Or, Not build deployment-time Boolean conditions

Short-form YAML is convenient, but nested short forms have grammar limits. For example, do not nest short-form !ImportValue directly around short-form !Sub; use a full function name for one layer.

Resolve P11 by hand

Assume:

  • account 111122223333;
  • Region ap-south-1;
  • Environment=lab;
  • LogRetentionDays=7;
  • CreateIngestionAlarm=false.

Then:

ExpressionResolved result/effect
!Equals [!Ref CreateIngestionAlarm, 'true']AlarmEnabled=false
!Equals [!Ref Environment, prod]IsProduction=false
bucket !Sub with variable mapnw-p11-lab-111122223333-ap-south-1
!Sub /nw/p11/${Environment}/application/nw/p11/lab/application
alarm Condition: AlarmEnabledresource omitted entirely
!Ref ArtifactBucketphysical bucket name
!GetAtt ArtifactBucket.Arnbucket ARN
!If [AlarmEnabled, 'true', 'false']output string false
data-classification !Iffake-lab-data-only

Change only Environment=prod and CreateIngestionAlarm=true: names/tags change, the alarm enters the graph, and classification becomes production-review-required. This is an analysis result, not permission to deploy production.

Conditions and AWS::NoValue

A resource-level Condition includes or excludes the whole resource. Within supported properties, Fn::If can choose a value; returning AWS::NoValue removes the property rather than setting an empty string. Conditions can refer to parameters, mappings and other conditions, but not directly to runtime resource attributes.

Changing a condition during update can create or delete its resource. Evaluate the same deletion/replacement and data-retention risks as any other update.

Outputs and exports

Outputs are visible through the Console/API and during stack workflows, so they must be non-secret. They are unavailable while a stack operation is in progress. A plain output is a convenient interface for humans and automation without cross-stack locking.

Adding Export: Name: creates a same-account, same-Region shared contract. Export names must be unique there. Once another stack imports an export, CloudFormation prevents deleting or changing the exported value until imports are removed. Neither the export name nor imported value can depend on a resource expression in ways CloudFormation disallows. Prefer SSM parameters, service discovery, event interfaces or deployment-pipeline composition when consumers need looser lifecycle coupling.

Local and AWS checks

curl -sS -o template.yaml \
  http://xupdate.nitwings.com/downloads/aws-academy/p11-cloudformation-automation/template.yaml
test -s template.yaml
rg -n '^Parameters:|^Conditions:|^Outputs:|!Ref|!GetAtt|!Sub|!If' template.yaml

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws cloudformation validate-template --template-body file://template.yaml --output json
aws cloudformation get-template-summary --template-body file://template.yaml \
  --query '{Parameters:Parameters,Types:ResourceTypes,Capabilities:Capabilities}' \
  --output json

The summary should show three parameters, three resource types, and no IAM capability. It cannot show the runtime physical bucket name before account/Region/parameters are resolved, nor prove the globally unique bucket name is available.

Refactoring exercise

Copy P11 locally and make these changes without deployment:

  1. Add OwnerTeam as a String with an allowed pattern and a clear constraint message.
  2. Add the owner tag to all resources that support tags.
  3. Add a mapping from environment to a retention default only as an exercise; then explain why a parameter default cannot itself use an intrinsic function.
  4. Build a non-secret OperationalName output with Sub.
  5. Draft - but do not add - a cross-stack export and identify the coupling it creates.
  6. Test invalid environment, invalid retention and invalid owner values using template-summary/Console parameter validation where available.

Diagnose this topic

SymptomLikely boundaryCorrection
Parameter rejected before creationtype/constraint mismatchuse an allowed value; do not weaken the contract blindly
Fn::Select failurelist shorter/null or wrong indexvalidate list length and zero-based index
unresolved Sub variablemisspelled parameter/logical ID or missing map keytrace each placeholder to its source
import not foundwrong account/Region/name or exporter absentverify list-exports; do not hard-code stale value
exporter cannot update/deleteactive importing stackmigrate consumers first
secret visiblevalue copied into an exposed fieldrotate it, remove exposure, use supported dynamic reference
condition deletes resourceparameter changed condition truthreview change set and retention before execution

Cost and cleanup

Parameters and expressions have no separate charge, but the values they select control resource cost and retention. A single Boolean can create a billable alarm; a retention parameter changes log storage; an environment value can select production-sized resources in other designs.

This lesson creates no AWS resource. Remove local copies if unnecessary. If using an existing stack read-only, make no parameter update. P11 deployment and retained-resource cleanup remain governed by its runbook.

Knowledge check

  1. Why quote P11's Boolean-looking values?

CloudFormation parameters have no Boolean type; they are bounded strings.

  1. What does Ref return for a resource?

The resource type's documented reference value, not always its ARN.

  1. Why is NoEcho insufficient for secrets?

It masks limited views but not values copied into exposed fields or command history.

  1. What lifecycle risk does ImportValue add?

The exporter cannot change/delete an imported export until consumers detach.

  1. Does an omitted conditional resource have a physical ID?

No; it is not included in that stack deployment.

Lesson acceptance

  • All P11 parameters and conditions are resolved correctly for lab and production examples.
  • At least eight intrinsic/condition functions are distinguished by input and result.
  • NoEcho, dynamic-reference and output secret boundaries are explained.
  • Ref/GetAtt return values and implicit dependency effects are identified.
  • Export scope, uniqueness and consumer lock-in are documented.
  • The refactored local template has bounded owner input and no secret or unreviewed deployment.

Official sources

Advertisement