<!DOCTYPE html>
    <html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>Cloud Control API resource operations - Cloud Control API</title><meta name="viewport" content="width=device-width,initial-scale=1" /><meta name="assets_root" content="/assets" /><meta name="target_state" content="resource-operations" /><meta name="default_state" content="resource-operations" /><link rel="icon" type="image/ico" href="/assets/images/favicon.ico" /><link rel="shortcut icon" type="image/ico" href="/assets/images/favicon.ico" /><link rel="canonical" href="https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-operations.html" /><meta name="description" content="Use Cloud Control API to do or other command verb construction -L operations on resources in your AWS account." /><meta name="deployment_region" content="IAD" /><meta name="product" content="Cloud Control API" /><meta name="guide" content="User Guide" /><meta name="abstract" content="Insert abstract text" /><meta name="guide-locale" content="en_us" /><meta name="tocs" content="toc-contents.json" /><link rel="canonical" href="https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-operations.html" /><link rel="alternate" href="https://docs.aws.amazon.com/id_id/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="id-id" /><link rel="alternate" href="https://docs.aws.amazon.com/id_id/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="id" /><link rel="alternate" href="https://docs.aws.amazon.com/de_de/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="de-de" /><link rel="alternate" href="https://docs.aws.amazon.com/de_de/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="de" /><link rel="alternate" href="https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="en-us" /><link rel="alternate" href="https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="en" /><link rel="alternate" href="https://docs.aws.amazon.com/es_es/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="es-es" /><link rel="alternate" href="https://docs.aws.amazon.com/es_es/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="es" /><link rel="alternate" href="https://docs.aws.amazon.com/fr_fr/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="fr-fr" /><link rel="alternate" href="https://docs.aws.amazon.com/fr_fr/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="fr" /><link rel="alternate" href="https://docs.aws.amazon.com/it_it/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="it-it" /><link rel="alternate" href="https://docs.aws.amazon.com/it_it/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="it" /><link rel="alternate" href="https://docs.aws.amazon.com/ja_jp/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="ja-jp" /><link rel="alternate" href="https://docs.aws.amazon.com/ja_jp/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="ja" /><link rel="alternate" href="https://docs.aws.amazon.com/ko_kr/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="ko-kr" /><link rel="alternate" href="https://docs.aws.amazon.com/ko_kr/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="ko" /><link rel="alternate" href="https://docs.aws.amazon.com/pt_br/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="pt-br" /><link rel="alternate" href="https://docs.aws.amazon.com/pt_br/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="pt" /><link rel="alternate" href="https://docs.aws.amazon.com/zh_cn/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="zh-cn" /><link rel="alternate" href="https://docs.aws.amazon.com/zh_tw/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="zh-tw" /><link rel="alternate" href="https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-operations.html" hreflang="x-default" /><meta name="feedback-item" content="CloudFormation" /><meta name="this_doc_product" content="Cloud Control API" /><meta name="this_doc_guide" content="User Guide" /><head xmlns="http://www.w3.org/1999/xhtml"> <script defer="" src="/assets/r/awsdocs-doc-page.2.0.0.js"></script><link href="/assets/r/awsdocs-doc-page.2.0.0.css" rel="stylesheet"/></head>
<script defer="" id="awsc-panorama-bundle" type="text/javascript" src="https://prod.pa.cdn.uis.awsstatic.com/panorama-nav-init.js" data-config="{'appEntity':'aws-documentation','region':'us-east-1','service':'cloudcontrolapi'}"></script><meta id="panorama-serviceSubSection" value="User Guide" /><meta id="panorama-serviceConsolePage" value="Cloud Control API resource operations" /></head><body class="awsdocs awsui"><div class="awsdocs-container"><p><a href="resource-operations.md">View a markdown version of this page</a></p><awsdocs-header></awsdocs-header><awsui-app-layout id="app-layout" class="awsui-util-no-gutters" ng-controller="ContentController as $ctrl" header-selector="awsdocs-header" navigation-hide="false" navigation-width="$ctrl.navWidth" navigation-open="$ctrl.navOpen" navigation-change="$ctrl.onNavChange($event)" tools-hide="$ctrl.hideTools" tools-width="$ctrl.toolsWidth" tools-open="$ctrl.toolsOpen" tools-change="$ctrl.onToolsChange($event)"><div id="guide-toc" dom-region="navigation"><awsdocs-toc></awsdocs-toc></div><div id="main-column" dom-region="content" tabindex="-1"><awsdocs-view class="awsdocs-view"><div id="awsdocs-content"><head><title>Cloud Control API resource operations - Cloud Control API</title><meta name="pdf" content="/pdfs/cloudcontrolapi/latest/userguide/cloudapi-service.pdf#resource-operations" /><meta name="rss" content="cloudapi-service.rss" /><meta name="forums" content="https://repost.aws/tags/TArPmMO7eHRYympxY7eh_tXA" /><meta name="feedback" content="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=CloudFormation&amp;topic_url=https://docs.aws.amazon.com/en_us/cloudcontrolapi/latest/userguide/resource-operations.html" /><meta name="feedback-yes" content="feedbackyes.html?topic_url=https://docs.aws.amazon.com/en_us/cloudcontrolapi/latest/userguide/resource-operations.html" /><meta name="feedback-no" content="feedbackno.html?topic_url=https://docs.aws.amazon.com/en_us/cloudcontrolapi/latest/userguide/resource-operations.html" /><meta name="keywords" content="Cloud Control API,cloudapi" /><link rel="alternate" type="text/markdown" href="resource-operations.md" title="Markdown version" /><script type="application/ld+json">
{
    "@context" : "https://schema.org",
    "@type" : "BreadcrumbList",
    "itemListElement" : [
      {
        "@type" : "ListItem",
        "position" : 1,
        "name" : "AWS",
        "item" : "https://aws.amazon.com"
      },
      {
        "@type" : "ListItem",
        "position" : 2,
        "name" : "AWS Cloud Control API",
        "item" : "https://docs.aws.amazon.com/cloudcontrolapi/index.html"
      },
      {
        "@type" : "ListItem",
        "position" : 3,
        "name" : "User Guide",
        "item" : "https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide"
      },
      {
        "@type" : "ListItem",
        "position" : 4,
        "name" : "Cloud Control API resource operations",
        "item" : "https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-operations.html"
      }
    ]
}
</script></head><body><div id="main"><div style="display: none"><a href="/pdfs/cloudcontrolapi/latest/userguide/cloudapi-service.pdf#resource-operations" target="_blank" rel="noopener noreferrer" title="Open PDF"></a></div><div id="breadcrumbs" class="breadcrumb"><a href="/index.html">Documentation</a><a href="/cloudcontrolapi/index.html">AWS Cloud Control API</a><a href="what-is-cloudcontrolapi.html">User Guide</a></div><div id="page-toc-src"><a href="#resource-operations-prerequisites">Prerequisites</a><a href="#resource-operations-permissions">Specifying credentials</a><a href="#resource-operations-idempotency">Ensuring requests are unique</a><a href="#resource-operations-considerations">Considerations</a></div><div id="main-content" class="awsui-util-container"><div id="main-col-body"><awsdocs-language-banner data-service="$ctrl.pageService"></awsdocs-language-banner><h1 class="topictitle" id="resource-operations">Cloud Control API resource operations</h1><div class="awsdocs-page-header-container"><awsdocs-page-header></awsdocs-page-header><awsdocs-filter-selector id="awsdocs-filter-selector"></awsdocs-filter-selector></div><p>Use AWS Cloud Control API to do or other command verb construction create, read, update, remove, and list (-L) operations
  on resources in your AWS account.</p><div class="highlights"><h6>Contents</h6><ul><li><p><a href="#resource-operations-prerequisites">Prerequisites</a></p></li><li><p><a href="#resource-operations-permissions">Specifying credentials</a></p></li><li><p><a href="#resource-operations-idempotency">Ensuring requests are unique</a></p></li><li><p><a href="#resource-operations-considerations">Considerations</a></p></li><li><p><a href="./resource-operations-create.html">Creating a resource</a></p></li><li><p><a href="./resource-operations-update.html">Updating a resource</a></p></li><li><p><a href="./resource-operations-delete.html">Deleting a resource</a></p></li><li><p><a href="./resource-operations-list.html">Discovering resources</a></p></li><li><p><a href="./resource-operations-read.html">Reading a resource</a></p></li><li><p><a href="./resource-operations-manage-requests.html">Managing resource requests</a></p></li><li><p><a href="./resource-identifier.html">Identifying resources with AWS Cloud Control API</a></p></li></ul></div>
  <h2 id="resource-operations-prerequisites">Prerequisites for using resources with Cloud Control API</h2>
  <p>To provision a specific resource using Cloud Control API, that resource type must support Cloud Control API and be available for use
   in your AWS account.</p>
  <div class="itemizedlist">
    
    
  <ul class="itemizedlist"><li class="listitem">
    <p><b>Resources available for use in your AWS account</b></p>
    <p>To be available for use in your account, public resource types must be activated, and private resource types
     must be registered. Supported AWS resource types are public and always activated. For more information, see <a href="./resource-types.html">Using Cloud Control API resource types</a>.</p>
   </li><li class="listitem">
    <p><b>Resources that support Cloud Control API</b></p>
    <p>For a list of AWS resource types that support Cloud Control API, see <a href="./supported-resources.html">Resource types that support Cloud Control API</a>.</p>
    
    
    <p>Third-party resource types, both public and private, support Cloud Control API.</p>
    <p>For details about how to determine if a specific resource type supports Cloud Control API, see <a href="./resource-types.html#resource-types-determine-support">Determining if a resource type supports Cloud Control API</a>.</p>
   </li></ul></div>
  <p>For information about using resource types, see <a href="./resource-types.html">Using Cloud Control API resource types</a>.</p>
  
        <h2 id="resource-operations-permissions">Specifying credentials for Cloud Control API</h2>
     <p>As part of performing operations on AWS resources on your behalf, Cloud Control API must make calls to the underlying
   AWS services that actually provision those resources. To do so, Cloud Control API requires the necessary credentials to
   access those services. There are two ways for you to enable Cloud Control API to acquire those credentials:</p>
        <div class="itemizedlist">
             
             
        <ul class="itemizedlist"><li class="listitem">
                <p><b>User credentials</b></p>
                <p>By default, Cloud Control API creates a temporary session using your AWS user
                    credentials, and uses that to make any necessary calls to downstream AWS
                    services. This session lasts up to 24 hours, after which any remaining calls to
                    AWS by Cloud Control API will fail.</p>
            </li><li class="listitem">
                <p><b>Service role credentials</b></p>
             <p>You can also specify a service role for Cloud Control API to assume during a resource operation, when you make
     the resource request. Among other advantages, specifying a service role enables Cloud Control API to make calls to underlying
     AWS services for up to 36 hours.</p>
             <p>To use a service role, specify the <code class="code">RoleArn</code> parameter of the resource operation
     request.</p>
             <p>Because the Cloud Control API actions are part of the CloudFormation service, the service role you specify is assumed by
     the CloudFormation service (<code class="code">cloudformation.amazonaws.com</code>). For more information, see <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-iam-servicerole.html">CloudFormation service
      role</a> in the <em>AWS CloudFormation User Guide</em>.</p>
            </li></ul></div>
     <p>The permissions required for each resource handler are defined in the <code class="code">handlers</code> section of that
   resource type's schema. For more information about viewing the resource schema, see .<a href="./resource-types.html#resource-types-schemas">Viewing resource type schemas</a> The <code class="code">handlers</code> section is
   defined in the <a href="https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-schema.html#schema-properties-handlers">resource type
    definition schema</a>.</p>
     
        <h2 id="resource-operations-idempotency">Ensuring resource operation requests are unique when using Cloud Control API</h2>
     <p>As a best practice, we strongly recommend you specify an idempotency token with create, delete, and update
   resource operation requests. Preferably, specify a token that will be unique for every request, such as an
   universally unique identifier (UUID). Such a token ensures requests can be disambiguated in cases where a request
   must be retried.</p>
     <p>The <code class="code">create-resource</code>, <code class="code">delete-resource</code>, and <code class="code">update-resource</code> operations
   all take a <code class="code">client-token</code> parameter, which can be set to an idempotency token.</p>
     
        <h2 id="resource-operations-considerations">Considerations when using Cloud Control API</h2>
        <p>We recommend that you take the following service behavior into account when performing resource operations
   using Cloud Control API:</p>
        <div class="itemizedlist">
             
             
             
             
        <ul class="itemizedlist"><li class="listitem">
                <p>Cloud Control API performs each resource operation individually and independently of any other resource
     operations.</p>
            </li><li class="listitem">
             <p>A single resource operation request to Cloud Control API might actually consist of multiple calls to the
     underlying service that provisions the resource. Because of this, a resource request might fail when only partially
     completed, resulting in only some of the requested changes being applied to the resource.</p>
            </li><li class="listitem">
                <p>If a resource operation fails at any point, Cloud Control API doesn't roll back the resource to its previous
     state.</p>
            </li><li class="listitem">
             <p>You can only perform one resource operation at a time on a given resource using Cloud Control API. However, the
     resource can still be operated on directly, through the underlying service that provisioned it. We strongly
     recommend against this approach because it may lead to unpredictable behavior.</p>
            </li></ul></div>
    <awsdocs-copyright class="copyright-print"></awsdocs-copyright><awsdocs-thumb-feedback right-edge="{{$ctrl.thumbFeedbackRightEdge}}"></awsdocs-thumb-feedback></div><noscript><div><div><div><div id="js_error_message"><p><img src="https://d1ge0kk1l5kms0.cloudfront.net/images/G/01/webservices/console/warning.png" alt="Warning" /> <strong>Javascript is disabled or is unavailable in your browser.</strong></p><p>To use the Amazon Web Services Documentation, Javascript must be enabled. Please refer to your browser's Help pages for instructions.</p></div></div></div></div></noscript><div id="main-col-footer" class="awsui-util-font-size-0"><div id="doc-conventions"><a target="_top" href="/general/latest/gr/docconventions.html">Document Conventions</a></div><div class="prev-next"><div id="previous" class="prev-link" accesskey="p" href="./getting-started.html">Getting started</div><div id="next" class="next-link" accesskey="n" href="./resource-operations-create.html">Creating a resource</div></div></div><awsdocs-page-utilities></awsdocs-page-utilities></div><div id="quick-feedback-yes" style="display: none;"><div class="title">Did this page help you? - Yes</div><div class="content"><p>Thanks for letting us know we're doing a good job!</p><p>If you've got a moment, please tell us what we did right so we can do more of it.</p><p><awsui-button id="fblink" rel="noopener noreferrer" target="_blank" text="Feedback" click="linkClick($event)" href="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=CloudFormation&amp;topic_url=https://docs.aws.amazon.com/en_us/cloudcontrolapi/latest/userguide/resource-operations.html"></awsui-button></p></div></div><div id="quick-feedback-no" style="display: none;"><div class="title">Did this page help you? - No</div><div class="content"><p>Thanks for letting us know this page needs work. We're sorry we let you down.</p><p>If you've got a moment, please tell us how we can make the documentation better.</p><p><awsui-button id="fblink" rel="noopener noreferrer" target="_blank" text="Feedback" click="linkClick($event)" href="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=CloudFormation&amp;topic_url=https://docs.aws.amazon.com/en_us/cloudcontrolapi/latest/userguide/resource-operations.html"></awsui-button></p></div></div></div></body></div></awsdocs-view><div class="page-loading-indicator" id="page-loading-indicator"><awsui-spinner size="large"></awsui-spinner></div></div><div id="tools-panel" dom-region="tools"><awsdocs-tools-panel id="awsdocs-tools-panel"></awsdocs-tools-panel></div></awsui-app-layout><awsdocs-cookie-banner class="doc-cookie-banner"></awsdocs-cookie-banner></div></body></html>