Skip to main content

Is CloudFormation the Perfect Cloud Deployment Tool for AWS?

AWS CloudFormation lets you create and provision AWS infrastructure deployments predictably and repeatedly using templates.

Cloud deployment, and specifically AWS cloud deployment, can be a daunting task and AWS provides many us with many useful tools. However, this time I am going to focus on my personal favorite cloud deployment option: CloudFormation.

Once you’ve launched a few CloudFormation installations, you can use these templates over again and again, which is extremely helpful if you need to constantly deploy new infrastructure. Best of all AWS has pre-built templates that you can use or modify to your heart’s content.

AWS CloudFormation Best Practices

As with all AWS services, before you start it’s a good idea to do some research. Of course, there AWS’s own documentation, but I’ll offer you a brief CloudFormation best-practice summary:

Planning and organizing

  • Organize your stacks by Lifecycle and Ownership (use the lifecycle and ownership of your AWS resources to help you decide what resources belong in each stack).
  • Reuse Templates to replicate stacks in multiple environments (to make templates reusable, use the parameters, mappings, and conditions sections so that you can customize your stacks when you create them).
  • Verify quotas for all resource types (before launching a stack, ensure that you can create all the resources that you want without hitting your AWS account limits).
  • Use Nested Stacks to reuse common Template patterns (separate out common components and create dedicated templates for them).

Creating templates

  • Do not embed credentials in your Templates (use input parameters to pass in information whenever you create or update a stack).
  • Use AWS-Specific Parameter Types (you can specify a parameter as type AWS::EC2::KeyPair::KeyName).
  • Use Parameter Constraints (describe allowed input values so that AWS CloudFormation catches any invalid values before creating a stack).
  • Use AWS::CloudFormation::Init to deploy software applications on Amazon EC2 instances (install and configure software applications on Amazon EC2 instances by using the cfn-init helper script and the AWS::CloudFormation::Init resource).
  • Validate Templates before using them (validating a template can help you catch syntax and some semantic errors ).

Managing stacks

  • Manage all stack resources through AWS CloudFormation (do not make changes to stack resources outside of AWS CloudFormation).
  • Use Stack Policies (stack policies help protect critical stack resources from unintentional updates).
  • Use AWS CloudTrail to log AWS CloudFormation calls (CloudTrail tracks anyone making AWS CloudFormation API calls in your AWS account).
  • Use code reviews and revision controls to manage your templates (to review changes and to keep an accurate history of your resources).

If you are going to create your own templates then it is in your best interests to try and adhere to these best practices, as they’re based on real-world experience from active AWS CloudFormation users.

What does a template look like?

A CloudFormation template is a JSON-formatted text file that describes your AWS infrastructure. Templates include several major sections. Here are the most common sections that you’re likely to find in a CloudFormation template:

Note: the Resources section is the only section that is actually required!

  "AWSTemplateFormatVersion" : "version date",
  "Description" : "JSON string",
  "Metadata" : {
    //template metadata
  "Parameters" : {
    //set of parameters
  "Mappings" : {
    //set of mappings
  "Conditions" : {
    //set of conditions
  "Resources" : {
    //set of resources
  "Outputs" : {
    //set of outputs

Launching a template

As stated previously, the good news is that AWS has lots of sample templates available for each region.
Because each region might have different requirements, a template that works in one region might not work in another region.

The following example uses the Asia Pacific (Sydney) RegionLet’s choose a template and prepare to launch it.

  • Choose your template. I am going to use the template “Amazon EC2 instance in a security group” which, as you should be able to guess, creates an Amazon EC2 instance in an Amazon EC2 security group. You can view the template here.
  • Click on the “Launch stack” button as shown here:
CloudFormation launch stack
  • On the “Select Template” page just click NEXT as you have already chosen your template.
  • You will now come to “Specify Parameters” page. This presents the template’s parameters:
"Parameters" : {
    "KeyName": {
      "Description" : "Name of an existing EC2 KeyPair to enable SSH access to the instance",
      "Type": "AWS::EC2::KeyPair::KeyName",
      "ConstraintDescription" : "must be the name of an existing EC2 KeyPair."
    "InstanceType" : {
      "Description" : "WebServer EC2 instance type",
      "Type" : "String",
      "Default" : "m1.small",
      "AllowedValues" : [ "t1.micro", "t2.micro", "t2.small", "t2.medium", "m1.small", "m1.medium", "m1.large", "m1.xlarge", "m2.xlarge", "m2.2xlarge", "m2.4xlarge", "m3.medium", "m3.large", "m3.xlarge", "m3.2xlarge", "c1.medium", "c1.xlarge", "c3.large", "c3.xlarge", "c3.2xlarge", "c3.4xlarge", "c3.8xlarge", "c4.large", "c4.xlarge", "c4.2xlarge", "c4.4xlarge", "c4.8xlarge", "g2.2xlarge", "r3.large", "r3.xlarge", "r3.2xlarge", "r3.4xlarge", "r3.8xlarge", "i2.xlarge", "i2.2xlarge", "i2.4xlarge", "i2.8xlarge", "d2.xlarge", "d2.2xlarge", "d2.4xlarge", "d2.8xlarge", "hi1.4xlarge", "hs1.8xlarge", "cr1.8xlarge", "cc2.8xlarge", "cg1.4xlarge"],
      "ConstraintDescription" : "must be a valid EC2 instance type."
    "SSHLocation" : {
      "Description" : "The IP address range that can be used to SSH to the EC2 instances",
      "Type": "String",
      "MinLength": "9",
      "MaxLength": "18",
      "Default": "",
      "AllowedPattern": "(\\d{1,3})\\.(\\d{1,3})\\.(\\d{1,3})\\.(\\d{1,3})/(\\d{1,2})",
      "ConstraintDescription": "must be a valid IP CIDR range of the form x.x.x.x/x."
  • I am going to choose t1.micro, name my key pair, and leave SSH Location as default. Click NEXT.
  • On the options page, I suggest Key=Name and Value={any name you want to describe it}. Click NEXT.
  • Review the Page then click CREATE.
  • Click CREATE STACK in top left corner
  • You should then see CREATE_IN_PROGRESS
  • Refresh screen after a minute or two and you should see CREATE_COMPLETE
  • Click on the stack name and then on the Events tab. You should see a screen similar to this:
CloudFormation Stack


The above is probably the simplest example of a CloudFormation deployment. Here are some more things you could do on AWS with the simple click of a launch button:

  • Create a DynamoDB table with global and local secondary indexes.
  • Create an AWS OpsWorks stack with a load-balanced application that runs inside a designated VPC.
  • Create an Amazon RDS database instance with provisioned IOPs.
  • Create a publicly accessible Amazon S3 bucket that is configured for website access.

Other CloudFormation resources

If you’d like to dig a bit deeper into CloudFormation, try:

Written by

Michael Sheehy

I have been UNIX/Linux System Administrator for the past 15 years and am slowly moving those skills into the AWS Cloud arena. I am passionate about AWS and Cloud Technologies and the exciting future that it promises to bring.

Related Posts

Sanket Dangi
— February 11, 2019

WaitCondition Controls the Pace of AWS CloudFormation Templates

AWS's WaitCondition can be used with CloudFormation templates to ensure required resources are running.As you may already be aware, AWS CloudFormation is used for infrastructure automation by allowing you to write JSON templates to automatically install, configure, and bootstrap your ...

Read more
  • AWS
  • formation
Andrew Larkin
— January 24, 2019

The 9 AWS Certifications: Which is Right for You and Your Team?

As companies increasingly shift workloads to the public cloud, cloud computing has moved from a nice-to-have to a core competency in the enterprise. This shift requires a new set of skills to design, deploy, and manage applications in cloud computing.As the market leader and most ma...

Read more
  • AWS
  • AWS certifications
Andrew Larkin
— November 28, 2018

Two New EC2 Instance Types Announced at AWS re:Invent 2018 – Monday Night Live

The announcements at re:Invent just keep on coming! Let’s look at what benefits these two new EC2 instance types offer and how these two new instances could be of benefit to you. If you're not too familiar with Amazon EC2, you might want to familiarize yourself by creating your first Am...

Read more
  • AWS
  • EC2
  • re:Invent 2018
Guy Hummel
— November 21, 2018

Google Cloud Certification: Preparation and Prerequisites

Google Cloud Platform (GCP) has evolved from being a niche player to a serious competitor to Amazon Web Services and Microsoft Azure. In 2018, research firm Gartner placed Google in the Leaders quadrant in its Magic Quadrant for Cloud Infrastructure as a Service for the first time. In t...

Read more
  • AWS
  • Azure
  • Google Cloud
Khash Nakhostin
Khash Nakhostin
— November 13, 2018

Understanding AWS VPC Egress Filtering Methods

In order to understand AWS VPC egress filtering methods, you first need to understand that security on AWS is governed by a shared responsibility model where both vendor and subscriber have various operational responsibilities. AWS assumes responsibility for the underlying infrastructur...

Read more
  • Aviatrix
  • AWS
  • VPC
Jeremy Cook
— November 10, 2018

S3 FTP: Build a Reliable and Inexpensive FTP Server Using Amazon’s S3

Is it possible to create an S3 FTP file backup/transfer solution, minimizing associated file storage and capacity planning administration headache?FTP (File Transfer Protocol) is a fast and convenient way to transfer large files over the Internet. You might, at some point, have conf...

Read more
  • Amazon S3
  • AWS
Guy Hummel
— October 18, 2018

Microservices Architecture: Advantages and Drawbacks

Microservices are a way of breaking large software projects into loosely coupled modules, which communicate with each other through simple Application Programming Interfaces (APIs).Microservices have become increasingly popular over the past few years. The modular architectural style,...

Read more
  • AWS
  • Microservices
Stuart Scott
— October 2, 2018

What Are Best Practices for Tagging AWS Resources?

There are many use cases for tags, but what are the best practices for tagging AWS resources? In order for your organization to effectively manage resources (and your monthly AWS bill), you need to implement and adopt a thoughtful tagging strategy that makes sense for your business. The...

Read more
  • AWS
  • cost optimization
Stuart Scott
— September 26, 2018

How to Optimize Amazon S3 Performance

Amazon S3 is the most common storage options for many organizations, being object storage it is used for a wide variety of data types, from the smallest objects to huge datasets. All in all, Amazon S3 is a great service to store a wide scope of data types in a highly available and resil...

Read more
  • Amazon S3
  • AWS
Cloud Academy Team
— September 18, 2018

How to Optimize Cloud Costs with Spot Instances: New on Cloud Academy

One of the main promises of cloud computing is access to nearly endless capacity. However, it doesn’t come cheap. With the introduction of Spot Instances for Amazon Web Services’ Elastic Compute Cloud (AWS EC2) in 2009, spot instances have been a way for major cloud providers to sell sp...

Read more
  • AWS
  • Azure
  • Google Cloud
  • SpotInst
Guy Hummel and Jeremy Cook
— August 23, 2018

What are the Benefits of Machine Learning in the Cloud?

A Comparison of Machine Learning Services on AWS, Azure, and Google CloudArtificial intelligence and machine learning are steadily making their way into enterprise applications in areas such as customer support, fraud detection, and business intelligence. There is every reason to beli...

Read more
  • AWS
  • Azure
  • Google Cloud
  • Machine Learning
Stuart Scott
— August 17, 2018

How to Use AWS CLI

The AWS Command Line Interface (CLI) is for managing your AWS services from a terminal session on your own client, allowing you to control and configure multiple AWS services.So you’ve been using AWS for awhile and finally feel comfortable clicking your way through all the services....

Read more
  • AWS