Class CfnGuardHook
java.lang.Object
software.amazon.jsii.JsiiObject
software.constructs.Construct
software.amazon.awscdk.CfnElement
software.amazon.awscdk.CfnRefElement
software.amazon.awscdk.CfnResource
software.amazon.awscdk.services.cloudformation.CfnGuardHook
- All Implemented Interfaces:
IInspectable,IGuardHookRef,software.amazon.jsii.JsiiSerializable,software.constructs.IConstruct,software.constructs.IDependable
@Generated(value="jsii-pacmak/1.116.0 (build 0eddcff)",
date="2025-10-24T13:34:32.794Z")
@Stability(Stable)
public class CfnGuardHook
extends CfnResource
implements IInspectable, IGuardHookRef
The
AWS::CloudFormation::GuardHook resource creates and activates a Guard Hook.
Using the Guard domain specific language (DSL), you can author Guard Hooks to evaluate your resources before allowing stack operations.
For more information, see Guard Hooks in the AWS CloudFormation Hooks User Guide .
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import software.amazon.awscdk.services.cloudformation.*;
CfnGuardHook cfnGuardHook = CfnGuardHook.Builder.create(this, "MyCfnGuardHook")
.alias("alias")
.executionRole("executionRole")
.failureMode("failureMode")
.hookStatus("hookStatus")
.ruleLocation(S3LocationProperty.builder()
.uri("uri")
// the properties below are optional
.versionId("versionId")
.build())
.targetOperations(List.of("targetOperations"))
// the properties below are optional
.logBucket("logBucket")
.options(OptionsProperty.builder()
.inputParams(S3LocationProperty.builder()
.uri("uri")
// the properties below are optional
.versionId("versionId")
.build())
.build())
.stackFilters(StackFiltersProperty.builder()
.filteringCriteria("filteringCriteria")
// the properties below are optional
.stackNames(StackNamesProperty.builder()
.exclude(List.of("exclude"))
.include(List.of("include"))
.build())
.stackRoles(StackRolesProperty.builder()
.exclude(List.of("exclude"))
.include(List.of("include"))
.build())
.build())
.targetFilters(TargetFiltersProperty.builder()
.targets(List.of(HookTargetProperty.builder()
.action("action")
.invocationPoint("invocationPoint")
.targetName("targetName")
.build()))
// the properties below are optional
.actions(List.of("actions"))
.invocationPoints(List.of("invocationPoints"))
.targetNames(List.of("targetNames"))
.build())
.build();
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classA fluent builder forCfnGuardHook.static interfaceHook targets are the destination where hooks will be invoked against.static interfaceSpecifies the input parameters for a Guard Hook.static interfaceSpecifies the S3 location where your Guard rules or input parameters are located.static interfaceTheStackFiltersproperty type specifies stack level filters for a Hook.static interfaceSpecifies the stack names for theStackFiltersproperty type to include or exclude specific stacks from Hook invocations.static interfaceSpecifies the stack roles for theStackFiltersproperty type to include or exclude specific stacks from Hook invocations based on their associated IAM roles.static interfaceTheTargetFiltersproperty type specifies the target filters for the Hook.Nested classes/interfaces inherited from class software.amazon.jsii.JsiiObject
software.amazon.jsii.JsiiObject.InitializationModeNested classes/interfaces inherited from interface software.constructs.IConstruct
software.constructs.IConstruct.Jsii$DefaultNested classes/interfaces inherited from interface software.amazon.awscdk.services.cloudformation.IGuardHookRef
IGuardHookRef.Jsii$Default, IGuardHookRef.Jsii$ProxyNested classes/interfaces inherited from interface software.amazon.awscdk.IInspectable
IInspectable.Jsii$Default, IInspectable.Jsii$Proxy -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe CloudFormation resource type name for this resource class. -
Constructor Summary
ConstructorsModifierConstructorDescriptionprotectedCfnGuardHook(software.amazon.jsii.JsiiObject.InitializationMode initializationMode) protectedCfnGuardHook(software.amazon.jsii.JsiiObjectRef objRef) CfnGuardHook(software.constructs.Construct scope, String id, CfnGuardHookProps props) -
Method Summary
Modifier and TypeMethodDescriptiongetAlias()The type name alias for the Hook.Returns the ARN of a Guard Hook.The IAM role that the Hook assumes to retrieve your Guard rules from S3 and optionally write a detailed Guard output report back.Specifies how the Hook responds when rules fail their evaluation.A reference to a GuardHook resource.Specifies if the Hook isENABLEDorDISABLED.Specifies the name of an S3 bucket to store the Guard output report.Specifies the S3 location of your input parameters.Specifies the S3 location of your Guard rules.Specifies the stack level filters for the Hook.Specifies the target filters for the Hook.Specifies the list of operations the Hook is run against.voidinspect(TreeInspector inspector) Examines the CloudFormation resource and discloses attributes.renderProperties(Map<String, Object> props) voidThe type name alias for the Hook.voidsetExecutionRole(String value) The IAM role that the Hook assumes to retrieve your Guard rules from S3 and optionally write a detailed Guard output report back.voidsetFailureMode(String value) Specifies how the Hook responds when rules fail their evaluation.voidsetHookStatus(String value) Specifies if the Hook isENABLEDorDISABLED.voidsetLogBucket(String value) Specifies the name of an S3 bucket to store the Guard output report.voidsetOptions(IResolvable value) Specifies the S3 location of your input parameters.voidSpecifies the S3 location of your input parameters.voidsetRuleLocation(IResolvable value) Specifies the S3 location of your Guard rules.voidSpecifies the S3 location of your Guard rules.voidsetStackFilters(IResolvable value) Specifies the stack level filters for the Hook.voidSpecifies the stack level filters for the Hook.voidsetTargetFilters(IResolvable value) Specifies the target filters for the Hook.voidSpecifies the target filters for the Hook.voidsetTargetOperations(List<String> value) Specifies the list of operations the Hook is run against.Methods inherited from class software.amazon.awscdk.CfnResource
addDeletionOverride, addDependency, addDependsOn, addMetadata, addOverride, addPropertyDeletionOverride, addPropertyOverride, applyRemovalPolicy, applyRemovalPolicy, applyRemovalPolicy, getAtt, getAtt, getCfnOptions, getCfnResourceType, getMetadata, getUpdatedProperites, getUpdatedProperties, isCfnResource, obtainDependencies, obtainResourceDependencies, removeDependency, replaceDependency, shouldSynthesize, toString, validatePropertiesMethods inherited from class software.amazon.awscdk.CfnRefElement
getRefMethods inherited from class software.amazon.awscdk.CfnElement
getCreationStack, getLogicalId, getStack, isCfnElement, overrideLogicalIdMethods inherited from class software.constructs.Construct
getNode, isConstructMethods inherited from class software.amazon.jsii.JsiiObject
jsiiAsyncCall, jsiiAsyncCall, jsiiCall, jsiiCall, jsiiGet, jsiiGet, jsiiSet, jsiiStaticCall, jsiiStaticCall, jsiiStaticGet, jsiiStaticGet, jsiiStaticSet, jsiiStaticSetMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, waitMethods inherited from interface software.constructs.IConstruct
getNodeMethods inherited from interface software.amazon.jsii.JsiiSerializable
$jsii$toJson
-
Field Details
-
CFN_RESOURCE_TYPE_NAME
The CloudFormation resource type name for this resource class.
-
-
Constructor Details
-
CfnGuardHook
protected CfnGuardHook(software.amazon.jsii.JsiiObjectRef objRef) -
CfnGuardHook
protected CfnGuardHook(software.amazon.jsii.JsiiObject.InitializationMode initializationMode) -
CfnGuardHook
@Stability(Stable) public CfnGuardHook(@NotNull software.constructs.Construct scope, @NotNull String id, @NotNull CfnGuardHookProps props) - Parameters:
scope- Scope in which this resource is defined. This parameter is required.id- Construct identifier for this resource (unique in its scope). This parameter is required.props- Resource properties. This parameter is required.
-
-
Method Details
-
inspect
Examines the CloudFormation resource and discloses attributes.- Specified by:
inspectin interfaceIInspectable- Parameters:
inspector- tree inspector to collect and process attributes. This parameter is required.
-
renderProperties
@Stability(Stable) @NotNull protected Map<String,Object> renderProperties(@NotNull Map<String, Object> props) - Overrides:
renderPropertiesin classCfnResource- Parameters:
props- This parameter is required.
-
getAttrHookArn
Returns the ARN of a Guard Hook. -
getCfnProperties
- Overrides:
getCfnPropertiesin classCfnResource
-
getGuardHookRef
A reference to a GuardHook resource.- Specified by:
getGuardHookRefin interfaceIGuardHookRef
-
getAlias
The type name alias for the Hook.This alias must be unique per account and Region.
-
setAlias
The type name alias for the Hook.This alias must be unique per account and Region.
-
getExecutionRole
The IAM role that the Hook assumes to retrieve your Guard rules from S3 and optionally write a detailed Guard output report back. -
setExecutionRole
The IAM role that the Hook assumes to retrieve your Guard rules from S3 and optionally write a detailed Guard output report back. -
getFailureMode
Specifies how the Hook responds when rules fail their evaluation. -
setFailureMode
Specifies how the Hook responds when rules fail their evaluation. -
getHookStatus
Specifies if the Hook isENABLEDorDISABLED. -
setHookStatus
Specifies if the Hook isENABLEDorDISABLED. -
getRuleLocation
Specifies the S3 location of your Guard rules.Returns union: either
IResolvableorCfnGuardHook.S3LocationProperty -
setRuleLocation
Specifies the S3 location of your Guard rules. -
setRuleLocation
Specifies the S3 location of your Guard rules. -
getTargetOperations
Specifies the list of operations the Hook is run against. -
setTargetOperations
Specifies the list of operations the Hook is run against. -
getLogBucket
Specifies the name of an S3 bucket to store the Guard output report. -
setLogBucket
Specifies the name of an S3 bucket to store the Guard output report. -
getOptions
Specifies the S3 location of your input parameters.Returns union: either
IResolvableorCfnGuardHook.OptionsProperty -
setOptions
Specifies the S3 location of your input parameters. -
setOptions
Specifies the S3 location of your input parameters. -
getStackFilters
Specifies the stack level filters for the Hook.Returns union: either
IResolvableorCfnGuardHook.StackFiltersProperty -
setStackFilters
Specifies the stack level filters for the Hook. -
setStackFilters
Specifies the stack level filters for the Hook. -
getTargetFilters
Specifies the target filters for the Hook.Returns union: either
IResolvableorCfnGuardHook.TargetFiltersProperty -
setTargetFilters
Specifies the target filters for the Hook. -
setTargetFilters
Specifies the target filters for the Hook.
-