Conversation
CloudFormation accepts Fn::GetStackOutput as the source of Fn::Split (confirmed by deploying a template in the CDK weak cross-stack string-list shape), but the published Fn::Split operand list predates the function and omits it, so the validator reported E1018 on every such template. Add Fn::GetStackOutput to the allowed Split sources in template-model so both engines inherit the fix, add a unit test and a good-corpus fixture in the deploy-verified shape, and regenerate the snapshots (engine parity verified: rego == cel == composite on all 718 templates).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fn::Splitwhose source isFn::GetStackOutputwas reported as E1018 (Fn::Split source must be a string or a string-producing intrinsic), but CloudFormation accepts that nesting. The AWS CDK synthesizes exactly this shape for weak string-list cross-stack references (Fn::Split("||", Fn::GetStackOutput ...)), so every such consumer stack tripped the rule, and the CDK'sCloudFormationValidatePlugincurrently suppresses E1018 outright to work around it.The allowed
Fn::Splitsources mirrored the publishedFn::Splitoperand list, which predatesFn::GetStackOutputand still omits it. This change addsFn::GetStackOutputtoSPLIT_SOURCE_FUNCTIONSintemplate-model, the shared layer both engines use, so the fix applies to Rego and CEL identically.src/template-model/src/intrinsic_arg_shapes.rs: addFN_GET_STACK_OUTPUTtoSPLIT_SOURCE_FUNCTIONS; new unit testsplit_source_get_stack_output_is_allowed.src/resources/templates/good/functions/split_get_stack_output.yaml: good-corpus fixture in the deploy-verified shape (split used as a list property, re-joined into a string withFn::Join, and indexed withFn::Select).src/resources/expected/validation_reports{6,7,8}.json: regenerated; the only new entries are the fixture's three I9040 (INFO, missingTags) findings, the rest is chunk-boundary movement. No existing template's diagnostics changed.With this fix released, the E1018 entry in the CDK plugin's
IGNORE_RULESbecomes unnecessary.Fn::Splitreference lists the same ten source functions as the previous allowlist and predatesFn::GetStackOutput. TheFn::GetStackOutputreference enumerates supported positions (direct property value,Fn::Join,Fn::If,Fn::Select) and known limitations (Fn::Subvariable map,Fn::Base64,Outputs,Fn::Equals,Fn::ImportValue);Fn::Splitappears in neither list, and the deployment shows it is accepted.aws-cdk-libemits this nesting for weak string-list cross-stack references (@aws-cdk/core:defaultCrossStackReferences=weak), and itsCloudFormationValidatePluginlists E1018 inIGNORE_RULESfor that reason.Checklist
selectors agree.
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license.