# P11 CloudFormation automation lab pack

This pack supports AWS219–222. The default track is local and read-only:
inspect, parse and validate without creating resources. Deployment is optional
and requires account-owner approval because the template can create an S3
bucket, CloudWatch Logs log group, and an alarm.

## Files and integrity

- `template.yaml` is the authoritative reviewed CloudFormation template.
- `read-service-status.yaml` is the reviewed read-only SSM Command document
  used by AWS224.
- Download URL: `/downloads/aws-academy/p11-cloudformation-automation/template.yaml`
- Command-document URL: `/downloads/aws-academy/p11-cloudformation-automation/read-service-status.yaml`
- Never deploy a copy whose content differs from the reviewed course hash.

## Local structural checks

```bash
test -s template.yaml
rg -n 'DeletionPolicy|UpdateReplacePolicy|PublicAccessBlock|BucketEncryption|Condition:|!Sub|!Ref|!GetAtt|!If' template.yaml
```

If `cfn-lint` is installed, run `cfn-lint template.yaml`. Do not install
software into a managed workstation without approval.

## AWS semantic validation without deployment

`validate-template` checks syntax and some structure. It does not prove IAM
least privilege, security, cost, quota, replacement behavior, runtime success,
or that a later deployment will be safe.

```bash
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws cloudformation validate-template --template-body file://template.yaml --output json
aws cloudformation get-template-summary --template-body file://template.yaml --output json
```

## Optional deployment gate

Record account, Region, caller, price review, stack owner, timer, unique stack
name, parameter values, and retained-resource cleanup owner. The template
intentionally applies `DeletionPolicy: Retain` and `UpdateReplacePolicy:
Retain` to both data resources, so stack deletion does not delete them.

```bash
stack_name="nw-p11-cloudformation-lab"
aws cloudformation deploy --stack-name "$stack_name" \
  --template-file template.yaml \
  --parameter-overrides Environment=lab LogRetentionDays=7 CreateIngestionAlarm=false \
  --tags Project=NitWings-P11 Environment=lab Cleanup=manual \
  --no-fail-on-empty-changeset
aws cloudformation describe-stacks --stack-name "$stack_name" --output json
aws cloudformation describe-stack-events --stack-name "$stack_name" \
  --max-items 50 --output table
```

No `CAPABILITY_IAM` flag is needed because this template creates no IAM
resource. Do not add that flag by habit.

## Cleanup contract

First record exact stack outputs. Empty every version of the owned bucket before
deleting it manually; deleting only current objects leaves versions and delete
markers. Delete the retained log group manually only after exporting required
evidence. Never delete similarly named resources not proven by outputs and tags.

```bash
aws cloudformation delete-stack --stack-name "$stack_name"
aws cloudformation wait stack-delete-complete --stack-name "$stack_name"

# Inventory checks only; replace with previously recorded exact output names.
aws s3api get-bucket-tagging --bucket exact-recorded-bucket-name
aws logs list-tags-for-resource --resource-arn exact-recorded-log-group-arn
```

The optional alarm is stack-owned and deletes with the stack. The retained
bucket and log group require separate owner-approved cleanup. Objects, object
versions, log events and exported evidence have separate retention obligations.
