External stack output resolver
The external stack output resolver reads the parameter value from a stack output of a stack. The source stack does not have to belong to the same Takomo project as the target stack.

Properties

Here are the properties of the external stack output resolver:
Key
Required
Type
Description
resolver
yes
string
Resolver name, this must be external-stack-output.
stack
yes
string
Name of the source stack.
output
yes
string
Name of the stack output whose value is read.
region
no
string
Region of the source stack. Region is optional. By default, the region of the target stack is used.
commandRole
no
string
IAM role used to access the stack output. Command role is optional. By default, credentials associated with the target stack are used.
confidential
no
boolean
Conceal the resolved parameter value from logs, defaults to false
immutable
no
boolean
Mark the parameter as immutable, defaults to false

Example

Say, we have two accounts: 123456789012 and 888888888888.
The account 123456789012 has one stack: src-bucket. It is located in the us-east-1 region and exposes the name of an application source bucket in a stack output named SrcBucketName. The 123456789012 account also has a read-only role that the 888888888888 account can assume.
The 888888888888 account has two stacks: assets-bucket and build-infra. The stacks are located in the us-east-1 and eu-west-1 regions, respectively. The assets-bucket stack exposes the name of an assets bucket in a stack output named AssetsBucket.
Only the build-infra stack is managed in our Takomo project. The two other stacks are configured elsewhere. The build-infra stack has two parameters: SrcBucket and AssetsBucket. To get the values for them, we use the external-stack-output resolver to read the two other stacks' outputs.
The directory structure looks like this:
1
.
2
├─ stacks
3
│ └─ build-infra.yml
4
└─ templates
5
└─ build-infra.yml
Copied!
The configuration of build-infra stack looks like this:
stacks/build-infra.yml
1
regions: us-east-1
2
parameters:
3
SrcBucket:
4
resolver: external-stack-output
5
stack: src-bucket
6
output: SrcBucketName
7
commandRole: arn:aws:iam::123456789012:role/read-only
8
AssetsBucket:
9
resolver: external-stack-output
10
stack: assets-bucket
11
output: AssetsBucketName
12
region: eu-west-1
Copied!
For the SrcBucket parameter, we need to specify the commandRole property because the source stack is located in a different account. We don't need to specify the region because both stacks are located in the same region.
For the AssetsBucket parameter, we must specify the region but not the commandRole because the stacks are located in the same account but different regions.
Last modified 16d ago
Export as PDF
Copy link