All Products
Search
Document Center

Resource Orchestration Service:ALIYUN::OSS::BucketOverwriteConfig

Last Updated:Jul 05, 2026

Use ALIYUN::OSS::BucketOverwriteConfig to configure overwrite prevention rules for an OSS bucket.

Syntax

{
  "Type": "ALIYUN::OSS::BucketOverwriteConfig",
  "Properties": {
    "Bucket": String,
    "Rule": List
  }
}

Properties

Parameter

Type

Required

Updatable

Description

Constraints

Bucket

String

Yes

No

The name of the bucket.

None

Rule

List

No

Yes

A list of overwrite prevention rules.

Minimum length: 0. Maximum length: 100. For more information, see Rule properties.

Rule syntax

"Rule": [
  {
    "Action": String,
    "Suffix": String,
    "Principals": Map,
    "Prefix": String,
    "Id": String
  }
]

Rule properties

Parameter

Type

Required

Updatable

Description

Constraints

Action

String

No

Yes

The operation type.

Valid value:

  • forbid

Id

String

No

Yes

The rule ID.

None

Prefix

String

No

Yes

The object name prefix.

Filters objects based on their name prefix.

Principals

Map

No

Yes

A list of authorized principals.

This property functions like the Principal element in a Bucket Policy. You can specify primary accounts, sub-accounts, or roles. If this property is empty or unspecified, overwrites for all users on objects that match the specified prefix and suffix are forbidden. For more information, see Principals properties.

Suffix

String

No

Yes

The object name suffix.

Filters objects based on their name suffix.

Principals syntax

"Principals": {
  "Principal": List
}

Principals properties

Parameter

Type

Required

Updatable

Description

Constraints

Principal

List

No

Yes

The list of authorized principals.

Minimum length: 0. Maximum length: 100. You can specify a list of primary accounts, sub-accounts, or roles. An empty string is not a valid value.

Return values

Fn::GetAtt

Rule: The list of overwrite prevention rules.

Examples

ROSTemplateFormatVersion: '2015-09-01'
Parameters:
  Bucket:
    Type: String
    Description:
      en: The name of the bucket.
    Required: true
  Rule:
    Description:
      en: A list of overwrite prevention rules.
    Required: false
    Default: Null
    Type: Json
    MinLength: 0
    MaxLength: 100
    AssociationProperty: List[Parameter]
    AssociationPropertyMetadata:
      Parameter:
        Description:
          en: An overwrite prevention rule.
        Required: false
        Default: Null
        Type: Json
        AssociationPropertyMetadata:
          Parameters:
            Action:
              Type: String
              Description:
                en: The operation type. Currently, only "forbid" is supported.
              AllowedValues:
                - forbid
              Default: Null
              Required: false
            Prefix:
              Type: String
              Description:
                en: The prefix of the object name, used to filter the objects to which the rule applies.
              Default: Null
              Required: false
            Principals:
              Description:
                en: A list of authorized principals, similar to the Principal element in a Bucket Policy. You can enter the primary account, sub-account, or role. If this parameter is empty or unspecified, overwriting is forbidden for all users on objects that match the specified prefix and suffix.
              Required: false
              Default: Null
              Type: Json
              AssociationPropertyMetadata:
                Parameters:
                  Principal:
                    Description:
                      en: An authorized principal, which can be a primary account, sub-account, or role. An empty string is not a valid value.
                    Required: false
                    Default: Null
                    Type: Json
                    MinLength: 0
                    MaxLength: 100
                    AssociationProperty: List[Parameter]
                    AssociationPropertyMetadata:
                      Parameter:
                        Type: String
                        Description:
                          en: An authorized principal.
                        Default: Null
                        Required: false
            Suffix:
              Type: String
              Description:
                en: The suffix of the object name, used to filter the objects to which the rule applies.
              Default: Null
              Required: false
            Id:
              Type: String
              Description:
                en: Rule ID.
              Default: Null
              Required: false
Resources:
  ExtensionResource:
    Type: ALIYUN::OSS::BucketOverwriteConfig
    Properties:
      Bucket:
        Ref: Bucket
      Rule:
        Ref: Rule
Outputs:
  Rule:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - Rule
    Description: The overwrite prevention rules.
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Parameters": {
    "Bucket": {
      "Type": "String",
      "Description": {
        "en": "The name of the bucket."
      },
      "Required": true
    },
    "Rule": {
      "Description": {
        "en": "A list of overwrite prevention rules."
      },
      "Required": false,
      "Default": null,
      "Type": "Json",
      "MinLength": 0,
      "MaxLength": 100,
      "AssociationProperty": "List[Parameter]",
      "AssociationPropertyMetadata": {
        "Parameter": {
          "Description": {
            "en": "An overwrite prevention rule."
          },
          "Required": false,
          "Default": null,
          "Type": "Json",
          "AssociationPropertyMetadata": {
            "Parameters": {
              "Action": {
                "Type": "String",
                "Description": {
                  "en": "The operation type. Currently, only \"forbid\" is supported."
                },
                "AllowedValues": [
                  "forbid"
                ],
                "Default": null,
                "Required": false
              },
              "Prefix": {
                "Type": "String",
                "Description": {
                  "en": "The prefix of the object name, used to filter the objects to which the rule applies."
                },
                "Default": null,
                "Required": false
              },
              "Principals": {
                "Description": {
                  "en": "A list of authorized principals, similar to the Principal element in a Bucket Policy. You can enter the primary account, sub-account, or role. If this parameter is empty or unspecified, overwriting is forbidden for all users on objects that match the specified prefix and suffix."
                },
                "Required": false,
                "Default": null,
                "Type": "Json",
                "AssociationPropertyMetadata": {
                  "Parameters": {
                    "Principal": {
                      "Description": {
                        "en": "An authorized principal, which can be a primary account, sub-account, or role. An empty string is not a valid value."
                      },
                      "Required": false,
                      "Default": null,
                      "Type": "Json",
                      "MinLength": 0,
                      "MaxLength": 100,
                      "AssociationProperty": "List[Parameter]",
                      "AssociationPropertyMetadata": {
                        "Parameter": {
                          "Type": "String",
                          "Description": {
                            "en": "An authorized principal."
                          },
                          "Default": null,
                          "Required": false
                        }
                      }
                    }
                  }
                }
              },
              "Suffix": {
                "Type": "String",
                "Description": {
                  "en": "The suffix of the object name, used to filter the objects to which the rule applies."
                },
                "Default": null,
                "Required": false
              },
              "Id": {
                "Type": "String",
                "Description": {
                  "en": "Rule ID."
                },
                "Default": null,
                "Required": false
              }
            }
          }
        }
      }
    }
  },
  "Resources": {
    "ExtensionResource": {
      "Type": "ALIYUN::OSS::BucketOverwriteConfig",
      "Properties": {
        "Bucket": {
          "Ref": "Bucket"
        },
        "Rule": {
          "Ref": "Rule"
        }
      }
    }
  },
  "Outputs": {
    "Rule": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "Rule"
        ]
      },
      "Description": "The overwrite prevention rules."
    }
  }
}