AWS::RAM::ResourceShare - AWS CloudFormation

AWS::RAM::ResourceShare

Specifies a resource share.

Syntax

To declare this entity in your AWS CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::RAM::ResourceShare", "Properties" : { "AllowExternalPrincipals" : Boolean, "Name" : String, "PermissionArns" : [ String, ... ], "Principals" : [ String, ... ], "ResourceArns" : [ String, ... ], "Tags" : [ Tag, ... ] } }

YAML

Type: AWS::RAM::ResourceShare Properties: AllowExternalPrincipals: Boolean Name: String PermissionArns: - String Principals: - String ResourceArns: - String Tags: - Tag

Properties

AllowExternalPrincipals

Indicates whether principals outside your organization in AWS Organizations can be associated with a resource share.

Required: No

Type: Boolean

Update requires: No interruption

Name

The name of the resource share.

Required: Yes

Type: String

Update requires: No interruption

PermissionArns

The Amazon Resource Names (ARNs) of the permissions to associate with the resource share. If you do not specify an ARN for the permission, AWS RAM automatically attaches the default version of the permission for each resource type. Only one permission can be associated with each resource type in a resource share.

Required: No

Type: List of String

Update requires: No interruption

Principals

The principals to associate with the resource share. The possible values are:

  • An AWS account ID

  • An Amazon Resource Name (ARN) of an organization in AWS Organizations

  • An ARN of an organizational unit (OU) in AWS Organizations

  • An ARN of an IAM role

  • An ARN of an IAM user

Note

Not all resource types can be shared with IAM roles and IAM users. For more information, see Sharing with IAM roles and IAM users in the AWS Resource Access Manager User Guide.

Required: No

Type: List of String

Update requires: No interruption

ResourceArns

The ARNs of the resources to associate with the resource share.

Required: No

Type: List of String

Update requires: No interruption

Tags

One or more tags.

Required: No

Type: List of Tag

Update requires: No interruption

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the ID of the resource share.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

Arn

The Amazon Resource Name (ARN) of the resource share.

Examples

Creating a Resource Share

The following example demonstrates how to create a resource share.

YAML

AWSTemplateFormatVersion: 2010-09-09 Resources: myresourceshare: Type: "AWS::RAM::ResourceShare" Properties: Name: "My Resource Share" ResourceArns: - "arn:aws:ec2:us-east-1:123456789012:resource-type/12345678-1234-1234-1234-12345678" Principals: - "210987654321" Tags: - Key: "Key1" Value: "Value1" - Key: "Key2" Value: "Value2"

JSON

{ "AWSTemplateFormatVersion": "2010-09-09T00:00:00.000Z", "Resources": { "myresourceshare": { "Type": "AWS::RAM::ResourceShare", "Properties": { "Name": "My Resource Share", "ResourceArns": [ "arn:aws:ec2:us-east-1:123456789012:resource-type/12345678-1234-1234-1234-12345678" ], "Principals": [ "210987654321" ], "Tags": [ { "Key": "Key1", "Value": "Value1" }, { "Key": "Key2", "Value": "Value2" } ] } } } }

See also