AWS::CloudHSM::ClusterCreates and manages an AWS CloudHSM cluster.
6 configurable properties. 1 required. Click a row to see details.
| Property | Type | Flags |
|---|---|---|
HsmType | string | RequiredCreate-only |
BackupRetentionPolicy | object | |
Mode | string | Create-only |
NetworkType | string | Create-only |
SubnetIds | Array<string> | Create-onlyWrite-only |
Tags | Array<object> |
Values returned after the resource is created. Access these with Fn::GetAtt.
| Attribute | Type | Description |
|---|---|---|
Arn | string | The Amazon Resource Name (ARN) of the cluster. |
BackupPolicy | string | The cluster's backup policy. |
ClusterId | string | The cluster's identifier (ID). |
SecurityGroup | string | The identifier (ID) of the cluster's security group. |
State | string | The cluster's state. |
SubnetMapping | object | A map from availability zone to the cluster's subnet in that availability zone. |
VpcId | string | The identifier (ID) of the virtual private cloud (VPC) that contains the cluster. |
A minimal template with required properties and common optional ones.
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample template for AWS::CloudHSM::Cluster
Resources:
MyResource:
Type: AWS::CloudHSM::Cluster
Properties:
HsmType: "value"
Tags:
- Key: Environment
Value: ProductionPermissions CloudFormation needs in your IAM role to manage this resource.
cloudhsm:CreateClustercloudhsm:DescribeClusterscloudhsm:TagResourcecloudhsm:ListTagsec2:CreateSecurityGroupec2:AuthorizeSecurityGroupIngressec2:AuthorizeSecurityGroupEgressec2:RevokeSecurityGroupEgressec2:CreateNetworkInterfaceec2:DescribeNetworkInterfacesec2:DescribeSubnetsec2:DescribeVpcsec2:DescribeSecurityGroupsiam:CreateServiceLinkedRolecloudhsm:DescribeClusterscloudhsm:ListTagscloudhsm:ModifyClustercloudhsm:DescribeClusterscloudhsm:TagResourcecloudhsm:UntagResourcecloudhsm:ListTagscloudhsm:DeleteClustercloudhsm:DescribeClustersec2:DeleteSecurityGroupcloudhsm:DescribeClustersOur bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to NewsletterArnThese properties cannot be changed after the resource is created. Updating them triggers a replacement.
SubnetIdsNetworkTypeModeHsmType