Estoy tratando de crear un script de CloudFormation que habilitará CloudTrail y le dará al usuario la opción de crear un nuevo depósito S3 y usarlo, o usar un depósito S3 existente actualmente. Soy nuevo en AWS, así que estoy un poco perdido. Aquí hay un código que he tomado y modificado, hasta ahora sin agregar condicionales y demás.
{ "AWSTemplateFormatVersion" : "2010-09-09", "Description" : "CloudTrail", "Parameters" : { "UseExisitingBucket" : { "Description" : "Yes/No", "Default" : "Yes", "Type" : "String", "AllowedValues" : [ "yes", "no"] }, "BucketName" : { "Description" : "Name of the S3 bucket.", "Type" : "String" }, "TopicName" : { "Description" : "Name of the SNS topic.", "Type" : "String", "Default" : "" }, "IncludeGlobalServiceEvents" : { "Description" : "Indicates whether the trail is publishing events from global services, such as IAM, to the log files.", "Type" : "String", "Default" : "false", "AllowedValues" : [ "true", "false" ] } }, "Conditions" : { "UseSNSTopic" : { "Fn::Not" : [ { "Fn::Equals" : [ { "Ref" : "TopicName" }, "" ] } ] } }, "Resources" : { "Trail" : { "Type" : "AWS::CloudTrail::Trail", "Properties" : { "IncludeGlobalServiceEvents" : { "Ref" : "IncludeGlobalServiceEvents" }, "S3BucketName" : { "Ref" : "BucketName" }, "SnsTopicName" : { "Fn::If" : [ "UseSNSTopic", { "Ref" : "TopicName" }, { "Ref" : "AWS::NoValue" } ] }, "IsLogging" : true } } }}
Está muy cerca, le sugiero que elimine el parámetro UseExisitingBucket . Luego agregue Default a BucketName para que se vea así:
"ExistingBucketName" : { "Description" : "Name of the S3 bucket.", "Type" : "String", "Default": "None" },Agregue condiciones de pareja para verificar si se proporcionó un depósito o si necesita crear uno nuevo:
"Conditions": { "CreateNewBucket": { "Fn::Equals": [ { "Ref": "ExistingBucketName" }, "None" ] }, "UseExistingBucket": { "Fn::Not": [ { "Fn::Equals": [ { "Ref": "ExistingBucketName" }, "None" ] } ] } }Luego cree el recurso S3 Bucket con la condición anterior, algo así como:
"S3Bucket": { "Condition": "CreateNewBucket", ... ... }Agregue 2 recursos de cloudtrail, uno con la condición "CreateNewBucket" y pase el recurso "S3Bucket" y el otro con "UseExistingBucket" y pase "ExistingBucketName"