7 questions foundWhat is AWS CloudFormation and how does infrastructure as code improve the way teams manage their AWS resources?
Beginner AWS CloudFormation lets you define your entire AWS infrastructure, including EC2 instances, VPCs, databases, and security groups, as declarative text based templates, and then automatically creates, updates, or deletes those resources consistently based on that template, providing significant advantages over manually clicking through the console, such as repeatability, version control history, and the ability to review infrastructure changes before they are applied, just like reviewing changes to application code.
aws cloudformation create-stack --stack-name my-stack --template-body file://template.yaml
Real-world example A development team defines their entire application's infrastructure, including a VPC, EC2 instances, and a database, in a single CloudFormation template stored in version control, allowing them to recreate an identical environment for a new project in minutes rather than manually configuring everything again.
Common follow-ups: What is the difference between CloudFormation and other infrastructure as code tools like Terraform?;Can CloudFormation manage resources that were originally created manually?
AWS CLI & SDKs;VPC & Networking
What is a CloudFormation stack, and how does it relate to the resources defined in a template?
Beginner A CloudFormation stack is the actual collection of AWS resources that get created when you deploy a template, and CloudFormation treats all resources within a stack as a single managed unit, meaning if you update the stack, CloudFormation calculates exactly what needs to change, and if you delete the stack, CloudFormation automatically cleans up every resource that was created as part of it, preventing orphaned resources from being accidentally left behind.
aws cloudformation describe-stacks --stack-name my-stack
Real-world example A developer deletes an entire test environment, consisting of a dozen different resources, with a single command by deleting its CloudFormation stack, confident that CloudFormation will properly clean up every associated resource rather than needing to manually track and delete each one individually.
Common follow-ups: What happens if you manually modify a resource that was created by CloudFormation?;How do you protect specific critical resources within a stack from being accidentally deleted?
AWS Config;AWS Organizations & Multi Account Strategy
How does CloudFormation calculate and apply changes when you update an existing stack, and what is a change set?
Intermediate When you update a stack, CloudFormation compares the new template against the currently deployed configuration to determine exactly what resources need to be created, modified, or deleted, and a change set lets you preview this calculated plan before actually applying it, showing you precisely what will happen, which is especially valuable for catching an unexpected or potentially destructive change, such as a resource being replaced entirely rather than simply updated, before it actually occurs in a production environment.
aws cloudformation create-change-set --stack-name my-stack --template-body file://updated-template.yaml --change-set-name my-changes
Real-world example A team reviews a CloudFormation change set before applying an update to their production stack, discovering that a seemingly minor configuration change would actually have caused their database to be completely replaced, and they revise their template to avoid this destructive and unintended change.
Common follow-ups: What types of changes typically require a resource to be replaced rather than simply updated?;How do you approve and execute a reviewed change set?
AWS Config;RDS & Databases
How do CloudFormation parameters and outputs make templates more reusable and flexible across different environments?
Intermediate Parameters let you accept input values when deploying a stack, such as an environment name or instance size, allowing the same template to be reused with different configurations for development, staging, and production environments, while outputs let you export specific values from a stack, such as a database endpoint address, which can then be referenced by other stacks or displayed to the person deploying the template, both features significantly improving a template's flexibility and reusability.
Parameters:
EnvironmentName:
Type: String
Default: development
Outputs:
DatabaseEndpoint:
Value: !GetAtt MyDatabase.Endpoint.Address
Real-world example A single CloudFormation template accepts an EnvironmentName parameter, letting the same template deploy a small development environment or a larger production environment simply by changing that one parameter value at deployment time.
Common follow-ups: How do you reference an output from one stack within a different stack?;What is the difference between a parameter and a mapping in CloudFormation?
AWS Organizations & Multi Account Strategy;RDS & Databases
How do CloudFormation nested stacks and cross stack references help organize very large and complex infrastructure definitions?
Intermediate Nested stacks let you break a large, complex infrastructure definition into smaller, more manageable and reusable individual templates, such as a separate template for networking and another for the application layer, which are then referenced together as one parent stack, while cross stack references let entirely separate, independently managed stacks share specific output values with each other, both approaches helping organize infrastructure code more cleanly as it grows beyond what is practical to manage within a single, massive template file.
Resources:
NetworkStack:
Type: AWS::CloudFormation::Stack
Properties:
TemplateURL: https://s3.amazonaws.com/my-templates/network.yaml
Real-world example A platform team organizes their infrastructure into separate nested stacks for networking, security, and application resources, making each individual template easier to understand, test, and reuse across multiple different projects compared to one enormous combined template.
Common follow-ups: What are the tradeoffs between nested stacks and completely separate independent stacks with cross stack references?;How deep can nested stacks be nested within other nested stacks?
VPC & Networking;IAM
How do CloudFormation StackSets support deploying the same infrastructure template consistently across multiple AWS accounts and regions simultaneously?
Advanced CloudFormation StackSets let you define a template once and deploy it consistently as individual stacks across many different AWS accounts and regions from a single central operation, which is invaluable for enforcing consistent baseline infrastructure, such as a required logging configuration or security guardrail, across an entire AWS Organization, without needing to manually deploy and maintain a separate stack in every individual account and region.
aws cloudformation create-stack-set --stack-set-name baseline-security --template-body file://baseline.yaml --permission-model SERVICE_MANAGED --auto-deployment Enabled=true
Real-world example A large enterprise uses a StackSet to automatically deploy a mandatory CloudTrail logging configuration across all fifty accounts in its AWS Organization, and any newly created account automatically receives that same baseline configuration through the StackSet's auto deployment feature.
Common follow-ups: What is the difference between self managed and service managed permission models for StackSets?;How do you handle a StackSet deployment failure in one specific target account without affecting the others?
AWS Organizations & Multi Account Strategy;AWS CloudTrail & Auditing
How can custom resources in CloudFormation extend its capabilities to manage resources or perform actions that are not natively supported by AWS resource types?
Advanced A custom resource lets you invoke your own Lambda function as part of a CloudFormation stack's create, update, or delete lifecycle, enabling you to perform virtually any custom action, such as calling a third party API to provision a resource outside of AWS, generating a randomly unique value, or performing a complex validation step, all fully integrated into CloudFormation's normal stack lifecycle and rollback behavior as if it were a native, built in resource type.
Resources:
MyCustomResource:
Type: Custom::MyResource
Properties:
ServiceToken: arn:aws:lambda:us-east-1:123456789012:function:CustomResourceHandler
Real-world example A company needing to provision a resource in a third party SaaS platform as part of their infrastructure deployment writes a custom resource backed by a Lambda function, fully integrating that external provisioning step into the same CloudFormation stack lifecycle as their native AWS resources.
Common follow-ups: How does CloudFormation handle rollback if a custom resource's Lambda function fails?;What is the difference between a custom resource and a CloudFormation macro?
Lambda & Serverless;AWS CLI & SDKs