AWS 220: Parameters, outputs and intrinsic functions
Why this lesson matters
Parameters are an input API, intrinsic functions form a dependency-aware expression language, and outputs are a visible stack interface. Poor contracts allow invalid deployments, leak sensitive values, or lock many stacks to one export. This lesson reads every P11 expression and predicts its resolved value without creating resources.
What you will be able to do
By the end, you can:
- choose String, Number, list, AWS-specific and SSM parameter types;
- apply defaults, allowed values/patterns, ranges and useful constraint messages;
- distinguish parameters, mappings, pseudo parameters, conditions and dynamic references;
- explain
Ref,GetAtt,Sub,Join,Split,Select,IfandImportValue; - predict implicit dependencies created by resource references;
- explain
NoEcholimitations and keep secrets out of outputs/identifiers; - decide when exports are appropriate and when they create harmful coupling;
- verify P11's effective input/output contract with
get-template-summary.
The five value sources
| Source | Resolved from | Best use | Main risk |
|---|---|---|---|
| Parameter | operator/pipeline at stack operation | bounded environment-specific input | unconstrained input or exposed secret |
| Mapping | static values versioned in template | small controlled lookup | stale Region/AMI catalogue |
| Pseudo parameter | CloudFormation context | account, Region, partition, stack identity | assuming the standard aws partition |
| Resource reference | created/imported resource | dependency-aware physical ID/attribute | replacement coupling |
| Dynamic reference | Systems Manager or Secrets Manager at operation time | external configuration/secret resolution | permissions, version rotation and unsupported-context constraints |
Do not turn every property into a parameter. Parameterize values that legitimately vary between deployments and have an owner. Keep invariant security requirements - encryption and public blocking in P11 - inside reviewed code.
Parameter types and validation
CloudFormation supports primitive String and Number, list forms such as CommaDelimitedList and List<Number>, AWS-specific types such as AWS::EC2::VPC::Id, and Systems Manager parameter value types. AWS-specific types let the Console validate and present values available to the caller in the current account/Region. They do not prove ownership, routing suitability or authorization.
Use:
AllowedValuesfor a closed vocabulary;AllowedPatternfor a full-string regular expression on String values;MinLength/MaxLengthfor strings;MinValue/MaxValuefor numbers;ConstraintDescriptionfor a human correction instead of only a regex error;- defaults only when the default is safe in every intended deployment.
P11 restricts Environment, LogRetentionDays, and the string Boolean CreateIngestionAlarm. CloudFormation has no Boolean parameter type, so quoted 'true' and 'false' are strings.
Secret rules
NoEcho: true masks a parameter in common stack descriptions, but it does not make the template a secret-management system. It does not mask values copied into Metadata, Outputs, resource metadata, or identifiers that another service exposes. Parameters can also appear in deployment commands and shell history.
Prefer a Secrets Manager or secure Systems Manager reference where the target resource property supports it. Keep secret values out of outputs, tags, names, logs and primary identifiers. The execution role needs access to resolve the secret. Plan rotation behavior: changing a secret in its store does not necessarily cause CloudFormation to update an unchanged resource automatically.
Intrinsic functions by behavior
| Function | Result |
|---|---|
Ref | Parameter value or resource-specific return value, often a physical name/ID |
Fn::GetAtt | Documented resource attribute such as the P11 bucket ARN |
Fn::Sub | String interpolation of parameters, pseudo parameters, attributes and a variable map |
Fn::Join | Concatenate list values with a delimiter |
Fn::Split | Split one string into a list |
Fn::Select | Select a zero-based list item; invalid index/null fails |
Fn::FindInMap | Read a static mapping key |
Fn::If | Select values based on a declared condition; usable in supported property/metadata/update-policy/output contexts |
Fn::ImportValue | Read an export from another stack in the same account and Region |
| condition functions | Equals, And, Or, Not build deployment-time Boolean conditions |
Short-form YAML is convenient, but nested short forms have grammar limits. For example, do not nest short-form !ImportValue directly around short-form !Sub; use a full function name for one layer.
Resolve P11 by hand
Assume:
- account
111122223333; - Region
ap-south-1; Environment=lab;LogRetentionDays=7;CreateIngestionAlarm=false.
Then:
| Expression | Resolved result/effect |
|---|---|
!Equals [!Ref CreateIngestionAlarm, 'true'] | AlarmEnabled=false |
!Equals [!Ref Environment, prod] | IsProduction=false |
bucket !Sub with variable map | nw-p11-lab-111122223333-ap-south-1 |
!Sub /nw/p11/${Environment}/application | /nw/p11/lab/application |
alarm Condition: AlarmEnabled | resource omitted entirely |
!Ref ArtifactBucket | physical bucket name |
!GetAtt ArtifactBucket.Arn | bucket ARN |
!If [AlarmEnabled, 'true', 'false'] | output string false |
data-classification !If | fake-lab-data-only |
Change only Environment=prod and CreateIngestionAlarm=true: names/tags change, the alarm enters the graph, and classification becomes production-review-required. This is an analysis result, not permission to deploy production.
Conditions and AWS::NoValue
A resource-level Condition includes or excludes the whole resource. Within supported properties, Fn::If can choose a value; returning AWS::NoValue removes the property rather than setting an empty string. Conditions can refer to parameters, mappings and other conditions, but not directly to runtime resource attributes.
Changing a condition during update can create or delete its resource. Evaluate the same deletion/replacement and data-retention risks as any other update.
Outputs and exports
Outputs are visible through the Console/API and during stack workflows, so they must be non-secret. They are unavailable while a stack operation is in progress. A plain output is a convenient interface for humans and automation without cross-stack locking.
Adding Export: Name: creates a same-account, same-Region shared contract. Export names must be unique there. Once another stack imports an export, CloudFormation prevents deleting or changing the exported value until imports are removed. Neither the export name nor imported value can depend on a resource expression in ways CloudFormation disallows. Prefer SSM parameters, service discovery, event interfaces or deployment-pipeline composition when consumers need looser lifecycle coupling.
Local and AWS checks
curl -sS -o template.yaml \
http://xupdate.nitwings.com/downloads/aws-academy/p11-cloudformation-automation/template.yaml
test -s template.yaml
rg -n '^Parameters:|^Conditions:|^Outputs:|!Ref|!GetAtt|!Sub|!If' template.yaml
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws cloudformation validate-template --template-body file://template.yaml --output json
aws cloudformation get-template-summary --template-body file://template.yaml \
--query '{Parameters:Parameters,Types:ResourceTypes,Capabilities:Capabilities}' \
--output json
The summary should show three parameters, three resource types, and no IAM capability. It cannot show the runtime physical bucket name before account/Region/parameters are resolved, nor prove the globally unique bucket name is available.
Refactoring exercise
Copy P11 locally and make these changes without deployment:
- Add
OwnerTeamas a String with an allowed pattern and a clear constraint message. - Add the owner tag to all resources that support tags.
- Add a mapping from environment to a retention default only as an exercise; then explain why a parameter default cannot itself use an intrinsic function.
- Build a non-secret
OperationalNameoutput withSub. - Draft - but do not add - a cross-stack export and identify the coupling it creates.
- Test invalid environment, invalid retention and invalid owner values using template-summary/Console parameter validation where available.
Diagnose this topic
| Symptom | Likely boundary | Correction |
|---|---|---|
| Parameter rejected before creation | type/constraint mismatch | use an allowed value; do not weaken the contract blindly |
Fn::Select failure | list shorter/null or wrong index | validate list length and zero-based index |
unresolved Sub variable | misspelled parameter/logical ID or missing map key | trace each placeholder to its source |
| import not found | wrong account/Region/name or exporter absent | verify list-exports; do not hard-code stale value |
| exporter cannot update/delete | active importing stack | migrate consumers first |
| secret visible | value copied into an exposed field | rotate it, remove exposure, use supported dynamic reference |
| condition deletes resource | parameter changed condition truth | review change set and retention before execution |
Cost and cleanup
Parameters and expressions have no separate charge, but the values they select control resource cost and retention. A single Boolean can create a billable alarm; a retention parameter changes log storage; an environment value can select production-sized resources in other designs.
This lesson creates no AWS resource. Remove local copies if unnecessary. If using an existing stack read-only, make no parameter update. P11 deployment and retained-resource cleanup remain governed by its runbook.
Knowledge check
- Why quote P11's Boolean-looking values?
CloudFormation parameters have no Boolean type; they are bounded strings.
- What does
Refreturn for a resource?
The resource type's documented reference value, not always its ARN.
- Why is
NoEchoinsufficient for secrets?
It masks limited views but not values copied into exposed fields or command history.
- What lifecycle risk does
ImportValueadd?
The exporter cannot change/delete an imported export until consumers detach.
- Does an omitted conditional resource have a physical ID?
No; it is not included in that stack deployment.
Lesson acceptance
- All P11 parameters and conditions are resolved correctly for lab and production examples.
- At least eight intrinsic/condition functions are distinguished by input and result.
NoEcho, dynamic-reference and output secret boundaries are explained.- Ref/GetAtt return values and implicit dependency effects are identified.
- Export scope, uniqueness and consumer lock-in are documented.
- The refactored local template has bounded owner input and no secret or unreviewed deployment.