This is the new AWS CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::EC2::IPAM
IPAM is a VPC feature that you can use to automate your IP address management workflows including assigning, tracking, troubleshooting, and auditing IP addresses across AWS Regions and accounts throughout your AWS Organization. For more information, see What is IPAM? in the Amazon VPC IPAM User Guide.
There are AWS Identity and Access Management (IAM) permissions required to fully manage an IPAM in CloudFormation. For more information, see Example policy in the Amazon VPC IPAM User Guide.
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::EC2::IPAM", "Properties" : { "DefaultResourceDiscoveryOrganizationalUnitExclusions" :[ IpamOrganizationalUnitExclusion, ... ], "Description" :String, "EnablePrivateGua" :Boolean, "MeteredAccount" :String, "OperatingRegions" :[ IpamOperatingRegion, ... ], "Tags" :[ Tag, ... ], "Tier" :String} }
YAML
Type: AWS::EC2::IPAM Properties: DefaultResourceDiscoveryOrganizationalUnitExclusions:- IpamOrganizationalUnitExclusionDescription:StringEnablePrivateGua:BooleanMeteredAccount:StringOperatingRegions:- IpamOperatingRegionTags:- TagTier:String
Properties
DefaultResourceDiscoveryOrganizationalUnitExclusions-
If your IPAM is integrated with AWS Organizations, you can exclude an organizational unit (OU) from being managed by IPAM. When you exclude an OU, IPAM will not manage the IP addresses in accounts in that OU. For more information, see Exclude organizational units from IPAM in the Amazon Virtual Private Cloud IP Address Manager User Guide.
Required: No
Type: Array of IpamOrganizationalUnitExclusion
Update requires: No interruption
Description-
The description for the IPAM.
Required: No
Type: String
Update requires: No interruption
EnablePrivateGua-
Enable this option to use your own GUA ranges as private IPv6 addresses. This option is disabled by default.
Required: No
Type: Boolean
Update requires: No interruption
MeteredAccount-
A metered account is an AWS account that is charged for active IP addresses managed in IPAM. For more information, see Enable cost distribution in the Amazon VPC IPAM User Guide.
Possible values:
-
ipam-owner(default): The AWS account which owns the IPAM is charged for all active IP addresses managed in IPAM. -
resource-owner: The AWS account that owns the IP address is charged for the active IP address.
Required: No
Type: String
Allowed values:
ipam-owner | resource-ownerUpdate requires: No interruption
-
OperatingRegions-
The operating Regions for an IPAM. Operating Regions are AWS Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the AWS Regions you select as operating Regions.
For more information about operating Regions, see Create an IPAM in the Amazon VPC IPAM User Guide.
Required: No
Type: Array of IpamOperatingRegion
Update requires: No interruption
-
The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key
Ownerand the valueTeamA, specifytag:Ownerfor the filter name andTeamAfor the filter value.Required: No
Type: Array of Tag
Update requires: No interruption
Tier-
IPAM is offered in a Free Tier and an Advanced Tier. For more information about the features available in each tier and the costs associated with the tiers, see the VPC IPAM product pricing page
. Required: No
Type: String
Allowed values:
free | advancedUpdate requires: No interruption
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the IPAM ID.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
Arn-
The ARN of the IPAM.
DefaultResourceDiscoveryAssociationId-
The ID of the default resource discovery association.
DefaultResourceDiscoveryId-
The ID of the default resource discovery.
IpamId-
The ID of the IPAM.
PrivateDefaultScopeId-
The ID of the default private scope.
PublicDefaultScopeId-
The ID of the default public scope.
ResourceDiscoveryAssociationCount-
The number of resource discovery associations.
ScopeCount-
The number of scopes.