# Intrinsic Function in CLoudFormation

In this blog, let’s think about the employee onboarding process. Suppose we have 100 new recruits. A sysadmin usually has to do a lot to onboard the employee. One of the onboarding tasks are giving them access to the cloud resources they require. So in Terms of AWS, let’s try to automate it with cloudformation. For a list of given employees, create iam user, create their s3 bucket and allow permission to their buckets. It becomes havoc when employees join and leave the company; i.e creating and destroying resources for them. Lets see how we can do that with cloudformation.

`AWSTemplateFormatVersion: '2010-09-09'`

`Resources:`

  `MyS3Bucket:`

    `Type: AWS::S3::Bucket`

    `Properties:`

      `BucketName: my-unique-bucket-name`

  

Generally we use the code snippet above to create an s3 bucket named ‘my-unique-bucket-name’. 

  

`AWSTemplateFormatVersion: '2010-09-09'`

`Resources:`

  `MyIAMUser:`

    `Type: AWS::IAM::User`

    `Properties:`

      `UserName: my-iam-user`

  

Also for the Iam user this is how we create. The name for the user is ‘my-iam-user’

  

`AWSTemplateFormatVersion: '2010-09-09'`

`Resources:`

  `MyS3Bucket:`

    `Type: AWS::S3::Bucket`

    `Properties:`

      `BucketName: my-unique-bucket-name`

`   `

  `MyBucketPolicy:`

    `Type: AWS::S3::BucketPolicy`

    `Properties:`

      `Bucket:` 

        `Ref: MyS3Bucket`

      `PolicyDocument:`

        `Statement:`

          `- Sid: PublicReadGetObject`

            `Effect: Allow`

            `Principal: arn:aws:iam::${AWS::AccountId}:user/my-iam-user`

            `Action: s3:GetObject`

            `Resource: arn:aws:s3:::my-unique-bucket-name/*`

  

CloudFormation For the Bucket Policy Allowing only access to the user

  

Now since we have 100 employees, thats a lot of work Lets actually make it six. Six or hundred it’s the same with a loop. Let’s understand the foundation of Intrinsic Functions.

  

`'Fn::ForEach::UniqueLoopName':`

  `- Identifier`

  `- - Value1 # Collection`

    `- Value2`

  `- 'OutputKey':`

      `OutputValue`

  
  

**ForEach** is one of the many intrinsic function in cloudformation. By intrinsic it means they are built in and allows us to perform various operations and transformation on template values of our Infrastructure’s Code. Dynamically generating values and execution time values are major advantages of intrinsic functions. Some examples are ‘Fn::Ref’, ‘Fn::GetAtt’, ‘Fn::Join’, ‘Fn::Sub’, ‘Fn::ImportValue’, ‘Fn::Split’ etc. Combination of these intrinsic functions allow us to deliver significant value with time and cost saving.

  

The Foreach requires a name so that it can be referred to later using references. ::UniqueLoopName. It also requires an Identifier as a loop sentinel. It is this identifier that is used to reference the individual item at the collection just as foreach in most programming languages. The value contains the collection of objects that has to be looped through. The Output section contains key value pair which is stored in the stack as output.

  
  

![](https://lh6.googleusercontent.com/5ZoBiFNk6eLiWRydiZAHidW6Ry33vxKIHqR32xNytHccI8lKals38nMvMnV32L5yA2kz4VJb_nKm20u2MX31caHpshpgy32TMqszhcurXg-9Ax0SHcCutOyE_FbpdSdJ6tp1AfZclBXFuyZoNWy5sBM align="left")

The identifier or variable is named **BucketPolice** instead of BucketPolicy because otherwise it would conflict with the name BucketPolicy which already exists and throws an error. Save the file and upload it to AWS S3.

![](https://lh6.googleusercontent.com/2zU9pcH5LpTNhq6qDE0PwXHUeb1UJRuI6JwnojasOJQTSMCRaKpfvbOMwXjNu0FUWh2UMpilsSkHcSeuS13tsDkAUUkylE0PbgG62FJiasbOvq9zsHAIuiUt_jra8NN16Tzu-729yuzGF645EKClZ1k align="left")

  

Create a stack and either upload the file or paste the s3 url. 

  
  
  

![](https://lh5.googleusercontent.com/HHBmd_-FcGMAiZOxGr1aLQ5Qp-twkMYKXOGs5c5CkAK0rZnc-NtLjwwwpJY0a48OnhcDV5Pv9NoNIBR2llQNkXuQd-ZcU0Y7ip7bBBVfnmxeuqdsqS1RdhCtoUzHSOmXAHkR_C1E-Mi_uVZyX5bYfwI align="left")

Name the stack and the parameters. We have named the stack as `intrinsic-functions` The parameters contains list of 6 employees.

![](https://lh4.googleusercontent.com/EPfGNd8MfUjwN8VlQwsXhoyx-XP5H7uyGSsWJnWpa2H3EzGkoIDYmH45nhFi8f3ceHLkwcsPEXP4nGCr7ppPLYZ-oL0ZaboCIs9FBwdu6r0qS6pRLUZb54T36fq21lQRwvYVi7l_4WlaDvWIOq5PWZ0 align="left")

Accept the agreements and proceed to create the stack according to the yaml file.

  

Creation of the resources has started

  

![](https://lh5.googleusercontent.com/IkmZ3Aqo_7XuSD1gV5KoknKSeI76xLc9I05tYi8DvyLaspMFmdF46BzzArLMxJ9M0xoCiaHA7zRBs0wtowpzUIPFlCTQ5wKjnymVITzk3WcC10VrpNphncT-bJAbafYKeoHzM2tAuBj7bkdgUlYZhAg align="left")

  

![](https://lh4.googleusercontent.com/k1GZyEtg3rvY6xT9u2g5htAFkmlqcFcsn-x9CVZyOjbB0eU56iCAeobAjjnzPdTpp5GF5iutS1QxXLCO6_ZYcxwOOdsXUELPtf2VnYBz2MJKq8Dn5VGFXhPbKjvxI6H6vUEM0f-J5kTc-Mpgbo4qLcw align="left")

Transformation succeeded by the AWS::LanguageExtensions

  

![](https://lh3.googleusercontent.com/knezIbEzqwwBKUfobRfIz291VKXMbO_p1zdU8M9pIsL2_uY2oU5ocacxtno9Iwu0Xsub-4xzlmIoQ76KyndAGVwQUM08x39pt6ILQu53JGWMy676po30E6jLYVC2mgeiqrZIyOM4XXDl_jtzObvs2v4 align="left")

More Resource Creation has been initiated by the cloudformation stack.

  

![](https://lh4.googleusercontent.com/BFPFAFOyPymP728-KQZpFj-SBzRwyABJ2rQ7Dm14Nev90wPAz0zwB_43idROXqbJZ_hONZv7YnbuxRI8UZeg_ZCYDucmTVecXE2X4avWJv2Vua6BPk3FiMMXpopQtQSkvA0QC90dUiRqCn7s3Uz9_Wo align="left")

Some resources have been created and some are in progress. Wait for all resources to be created.

![](https://lh4.googleusercontent.com/5DvMHfaC19IOUmNfSmZ-P-oQWyAUZLEcCSoLvIg3pgrbbR1zRlwrBUfAGLl1Ag3Ya0iZRgRjfyP9yUYN7ckeffXiEzhjBfIJI56hAYK1Djeer_Z6pxQ6Pf0e5cvrawj8AWBvARqTDiF05Pul2dqwOQs align="left")

All the IAM users are created. Remember the  UserName: !Sub  ${UserName}-employee-iam-user" ? the ${UserName} is replaced with each identifier from the list of parameters.

  
  

![](https://lh4.googleusercontent.com/wZi7wFms_Hj1dMKkSoMffaV2Wla1C7-fpJGdIN_8cXLp2OU75I-uznITGw4GIHC_-lecPl4cWilsCfsQtzyl98arHpQjtHOF5MAZ1HJUauJPch-el5_z4E9fTnmRxUK5agGvOAms2_54gvWTJlfP-bE align="left")

All the s3 buckets are created. Remember the  BucketName: !Sub "${BucketName}-employeebucket"? the ${BucketName} is replaced with each identifier from the list of parameters.

![](https://lh4.googleusercontent.com/QbA5TFBxpXlcimy1sqErWq14e7QN31dvXgzp4oxSXLHyBxXyfr2i_FropD2QxZLv4VQwqJ5NF92UPc8sIsKEm73DOD0TcUcz-F1vzU4ohqUn-F9k4-uMvtsxDwIaGv7-f_4bKNXdnRVA2MeWUkOHWU4 align="left")

  

Bucket policies only allow the particular bucket to be accessed by the respective user.

  

![](https://lh4.googleusercontent.com/az1YMBHY2CxU1y-pLKgASnFCoc397ym9hwAtMrnQ-kpfJwem9A4Y7b94HywuQc0wTCkFVXGCEGWC7vKM0tWB0JmXRcMEKZeF5XMdljCaN5dlOYr1KU8BTjLWd8nUOU1c4_6R7FFIWZhSsNdzwQLQFWs align="left")

All the buckets do have the policy assigned according to the policy Document with the principal as the particular user. No other users have access to the bucket.

  

![](https://lh5.googleusercontent.com/Knw6sPgxTOpj2PNHriurdvMsrygw-Wn3pTd5QSzuuFufAzk-GCcGZolp1mUZ-ZtnWQKxNKHvb4XphO7A8pSEkhygmq9_GnCTWbQ7b_Y31D_y3lJY1si7qWXC5n5Wh_pvwBp83lDbfRyun1u6HCaRqYc align="left")

  

And with this the stack creation has been completed.

  

![](https://lh6.googleusercontent.com/k5CisQ0zp7635gPxnEFxrpq2DR6X1_nsW8M_g_CrU1VudB_615QcoNkBfco2eE4xPaEvHwzJY7OAVYTKkM_qDkkBXZlqqaR8hnciYFVA2Y6dRB1iLjxT3uS0LbGduAXem_1HdeGxSs33W3amDQLjqU0 align="left")

Now when the employees have to be offboarded, the stack should be deleted. All the users and the associated resources in the cloudformation IAC will be deleted. Whenever new users or resources have to be created, we have to create a changeset with the modified configuration.

  

![](https://lh5.googleusercontent.com/OitnEunfIPFN937Z9znOGg6Wqaebj10UK8LZASz82dTCD4TDJ-UUx0lstJoKFZ8qqIcNfZ8taoJ9m1hho32jXLnusjaHE-c9oxiiBW-_r7U-6nTLEMt5F_s_dJnO-CmYVAzYY4MK30Vz7wRMt3Be-hA align="left")

Deletion initiated.

![](https://lh6.googleusercontent.com/gWIktpHmyCPWnqb3Bwtv-NtiQfaXJsC9k_FKXEIYsK_549RtI5w7bdHWQTwZca7qMziJfGFMWOAONLdasW8I3G9MJlKPANudsWGHPPX7UXQNpEt1LkWIT26iroq8t0SeqKPpaMVpycDMpxtBzSiaR04 align="left")

We can see no buckets with the suffix ‘-employeebucket’ can be seen in the s3 list after applying the filter

![](https://lh3.googleusercontent.com/9-EGK8diiYge7yJgsjAPkENtlVhFXGwv1jDEpd92OPapSzTo-rFUK6Bbp1K1F5K8QclbWclF10DTUvMr47jOIWB1Rj5CoyZlo91YdCzq53U4G5RBWfucMgkZWEPRaCqo3YlmrPtsrriUzRjsNoCP0ns align="left")

We can see no iam user with the suffix ‘-employee-iam-user’ can be seen in the s3 list after applying the filter.

  

By this the employee onboarding and offboarding process is automated with a simple list of users.
