AWS CloudFormation
AWS CloudFormation is Amazon's native infrastructure as code service. You describe AWS resources — VPCs, IAM roles, Lambda functions, databases, queues — in a JSON or YAML template, and CloudFormation creates, updates, and deletes them together as a stack. Because it's part of AWS, there's no state file to host, updates roll back automatically on failure, and new AWS services often gain CloudFormation support quickly.
Many teams now write CloudFormation indirectly through the AWS Cloud Development Kit (CDK), which generates templates from TypeScript, Python, Java, C#, or Go code. Others choose Terraform or OpenTofu for multi-cloud reach. Understanding CloudFormation's model is useful either way, because the CDK and many AWS tools (SAM, Amplify, Control Tower) are built on it.
TL;DR
- A template declares resources; deploying it creates a stack that AWS manages as one unit.
- Use parameters for inputs, outputs and exports to share values, and intrinsic functions (
!Ref,!GetAtt,!Sub) to wire resources. - Preview updates with change sets — watch for resources marked Replacement: True.
- Failed updates roll back automatically; protect critical data with
DeletionPolicy: RetainorSnapshot. - Detect manual console changes with drift detection.
- Scale out with nested stacks, StackSets (many accounts/regions), or the CDK.
Quick Example
A template that creates an encrypted, private S3 bucket and an SQS queue with a dead-letter queue, parameterized by environment:
Deploy it with a change set preview:
Core Concepts
Template Anatomy
Intrinsic Functions
!Ref— a parameter's value or a resource's primary identifier.!GetAtt— a resource attribute, such as an ARN or endpoint.!Sub— string interpolation with${}references.!If,!Equals,!Select,!Split,!Join— logic and string manipulation.!ImportValue— read another stack's export.
Stacks, Updates, and Rollback
CloudFormation calculates the dependency graph from references and creates resources in order, in parallel where possible. If any resource fails, the stack rolls back to its last good state. Update behavior depends on the property changed: no interruption, some interruption, or replacement (delete and recreate — dangerous for databases and buckets with data).
Change Sets
A change set shows exactly what an update will add, modify, or replace before you execute it. Reviewing change sets in pull requests or pipelines is the CloudFormation equivalent of terraform plan.
Drift Detection
Drift detection compares actual resource configuration with the template and flags manual changes. It doesn't fix drift — you reconcile by updating the template or reverting the change.
Organizing Many Stacks
AWS CDK and SAM
The CDK lets you define infrastructure with programming-language constructs, loops, and types, then synthesizes CloudFormation templates. SAM (Serverless Application Model) is a transform with shorthand resources for Lambda, API Gateway, and DynamoDB, plus local testing tools.
Best Practices
Always Review Change Sets
Pay special attention to replacements. Renaming a logical ID or changing certain properties can silently delete and recreate a database.
Protect Stateful Resources
Set DeletionPolicy and UpdateReplacePolicy to Retain or Snapshot on databases, buckets, and file systems, and enable termination protection on production stacks.
Validate Templates in CI
Run cfn-lint for correctness and cfn-guard or Checkov for policy (encryption, public access, tagging) on every pull request.
Keep Stacks Small and Focused
Split by lifecycle and ownership — networking, data, application — so a routine application deploy can't touch the VPC.
Use Stack Policies and IAM Service Roles
A stack policy can block updates to critical resources; a dedicated service role limits what CloudFormation can do on a stack's behalf.
Avoid Hardcoded Names
Let CloudFormation generate physical names where possible. Hardcoded names prevent replacements and make multiple environments collide.
Common Mistakes
Editing Resources in the Console
Manual changes cause drift and can make the next update fail or revert them unexpectedly.
Tight Coupling Through Exports
An exported value can't be changed or removed while another stack imports it, which can block updates. Use exports sparingly or pass values through SSM Parameter Store.
Ignoring UPDATE_ROLLBACK_FAILED
A stack stuck in this state blocks further updates. Resolve the underlying resource issue and use "continue update rollback."
Secrets in Templates or Parameters
Plaintext passwords end up in templates and stack events. Use dynamic references to Secrets Manager ({{resolve:secretsmanager:...}}).
One Giant Stack
Hitting the 500-resource limit or waiting 40 minutes for every change is a sign the stack should be split.
Comparison
FAQ
What is AWS CloudFormation used for?
Defining and provisioning AWS infrastructure from templates so environments are reproducible, reviewable, and changed through code rather than the console.
What's the difference between a template and a stack?
A template is the declaration of resources. A stack is a deployed instance of a template that CloudFormation manages as one unit; you can deploy the same template as many stacks.
Should I use CloudFormation or Terraform?
Choose CloudFormation (often via CDK) for AWS-only environments where you want AWS-managed state and automatic rollback. Choose Terraform or OpenTofu for multi-cloud or when you manage many non-AWS resources.
What is the AWS CDK?
The Cloud Development Kit lets you write infrastructure in general-purpose languages. It synthesizes CloudFormation templates and deploys them as stacks.
How do I avoid accidentally deleting a database?
Set DeletionPolicy: Snapshot or Retain, enable termination protection, review change sets for replacements, and use stack policies on critical resources.
Related Topics
- Infrastructure as Code — Principles behind CloudFormation
- Terraform — The multi-cloud alternative
- Pulumi — IaC in general-purpose languages
- AWS — The services CloudFormation provisions
- CI/CD — Deploying stacks from pipelines