AWS
CloudFormation
Your stacks, what changed, whether anyone edited things by hand, and AI explanations of templates.
CloudFormation lets you describe AWS resources in a file and have AWS build them. A deployed copy of such a file is a stack.
If nobody at your company uses CloudFormation, this screen will be empty and you can ignore it.
Stacks
Every stack in the region, with its status and when it was last updated.
Statuses in plain words:
| Status | Means |
|---|---|
CREATE_COMPLETE / UPDATE_COMPLETE | Healthy |
*_IN_PROGRESS | Working. Wait |
ROLLBACK_COMPLETE | It failed and AWS undid it. The stack events say why |
UPDATE_ROLLBACK_FAILED | It failed and could not undo cleanly. Needs attention |
DELETE_FAILED | Something is blocking deletion, often a non-empty S3 bucket |
Open a stack for its resources, its events (the timeline — where the reason for any failure is), its parameters and outputs, and its template.
Change sets
A change set is a preview: "if I applied this template, here is exactly what would be created, changed and destroyed."
Always look at the change set before an update, especially the Replacement: True rows. Replacement means the resource is destroyed and recreated — which for a database means downtime and, without a snapshot, data loss.
You can create, inspect and execute change sets here.
Drift detection
Drift is when someone changes a resource by hand in the console, so reality no longer matches the template. The next stack update may overwrite their change without warning, or fail confusingly.
Run drift detection and you get a list of what differs. Worth doing before any update to a stack that has been alive for a while.
Template catalogue
A small catalogue of ready-made templates to start from.
Explain with AI
Templates are long and hard to read. Explain produces a plain-English summary of what a template actually creates, what it will cost, and anything worth questioning. Useful before running a template someone handed you.
Safety
Executing a change set or deleting a stack are real changes to your infrastructure.
- Only Owners and Admins can delete a stack.
- Through the assistant, stack deletion always asks for approval even with auto-approve on.
Permissions
Read-only viewing needs the CloudFormation Describe*, Get* and List*
calls. Creating and executing change sets needs write permissions plus the
permissions for whatever the template itself creates. See
AWS permissions.
