since launch templates are immutable, the only property returned in the describe call that indicates any changes have been made is LatestVersionNumber.
according to the current discussion on the GitHub ticket, since LatestVersionNumber is a readOnly property in the resource schema, Cloudformation does not include this property in drift detection.
although technically correct, i feel the comment is also very valid. a customer should not need to need to go to such lengths to learn why modified resources are not reporting as drifted, despite the official docs explicitly stating it is supported.
i feel this is a good opportunity to improve the general experience for all. when detecting drift on a Launch Template, from the customer's perspective Cloudformation should be "smart" enough to see the LatestVersionNumber has changed, and to then drill deeper into the various properties to compare with that of the previous version.
Different perspectives are appreciated and welcomed. and i'll be happy to provide any further clarity and context if needed.
Name of the resource
AWS::EC2::LaunchTemplate
Resource name
No response
Description
Cloudformation drift detection is reporting AWS::EC2::LaunchTemplate as IN_SYNC, despite having been modified directly by out-of-band changes.
For the full discussion and my replication, kindly refer to the associated issue (AWS::EC2::LaunchTemplate) Implement Drift Detection #1682
Snippet of Cloudformation template
Above is a snippet of the Cloudformation template deployed during testing. a describe call returns the following properties...
since launch templates are immutable, the only property returned in the describe call that indicates any changes have been made is
LatestVersionNumber
.according to the current discussion on the GitHub ticket, since
LatestVersionNumber
is areadOnly
property in the resource schema, Cloudformation does not include this property in drift detection.excerpt of schema
although technically correct, i feel the comment is also very valid. a customer should not need to need to go to such lengths to learn why modified resources are not reporting as drifted, despite the official docs explicitly stating it is supported.
i feel this is a good opportunity to improve the general experience for all. when detecting drift on a Launch Template, from the customer's perspective Cloudformation should be "smart" enough to see the
LatestVersionNumber
has changed, and to then drill deeper into the various properties to compare with that of the previous version.Different perspectives are appreciated and welcomed. and i'll be happy to provide any further clarity and context if needed.
Other Details
No response