AWS Certified SysOps Administrator – Associate flashcards
146 free flashcards. Tap a card to flip it.
CloudFront Origin Access Control (OAC)
Flip cardA CloudFront feature that enhances the security of S3 origins by enabling CloudFront to access the S3 bucket while preventing direct public access to the bucket.
- Replaces and improves upon Origin Access Identity (OAI)
- Supports all S3 buckets, including those with server-side encryption
- Provides more granular permissions for CloudFront to S3
- Ensures content delivery exclusively through CloudFront
Memory trick: OAC is the Only Access Control for CloudFront to S3.
EC2 Enhanced Networking (ENA)
Flip cardA feature that uses single root I/O virtualization (SR-IOV) to provide high-performance networking capabilities on supported EC2 instance types.
- Significantly higher packet per second (PPS) performance
- Lower network latency
- Lower network jitter
- Enabled by Elastic Network Adapter (ENA) or Intel 82599 Virtual Function (VF) interface
Memory trick: ENA is Enhanced Networking, Always Fast.
VPC Endpoint for Systems Manager
Flip cardA VPC Endpoint allows EC2 instances in private subnets to securely communicate with AWS Systems Manager without requiring an internet gateway, NAT device, or public IP addresses.
- Enables private connectivity to AWS services.
- Bypasses the public internet for enhanced security.
- Supports Systems Manager for instance management.
Memory trick: Private instances need a 'private door' to AWS services, not an 'open window'.
AWS Network Troubleshooting Flow
Flip cardA systematic approach to diagnosing network connectivity issues in AWS, typically starting from instance-level security, then subnet-level security, and then routing.
- Start with Security Groups (instance-level, stateful)
- Proceed to Network ACLs (subnet-level, stateless)
- Check Route Tables (traffic direction)
- Verify connectivity components (IGW, NAT Gateway, VPC Endpoints, VPN)
Memory trick: SG-NACL-Route-Connect: See Ghost, N-A-C-L, Route to Connect.
Application Load Balancer (ALB)
Flip cardAn AWS load balancer that operates at the application layer (Layer 7) and supports content-based routing, SSL/TLS termination, and HTTP/HTTPS traffic.
- Ideal for microservices and container-based applications.
- Supports path-based, host-based, and query string parameter-based routing.
- Can route traffic to multiple target groups.
Memory trick: ALB is for Apps, NLB for Nifty Networks, GWLB for Gatekeepers.
AWS Direct Connect
Flip cardA cloud service solution that links your internal network to an AWS Direct Connect location over a standard Ethernet fiber-optic cable.
- Dedicated network connection
- Reduced network costs (for high data transfer)
- Increased bandwidth throughput
- More consistent network experience than internet-based connections
Memory trick: Direct Connect is Dedicated, VPN is Virtual Private Network.
AWS Transit Gateway
Flip cardA network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks.
- Simplifies network topology for complex environments
- Supports routing between attached VPCs and VPNs
- Can serve as a central point for shared services (e.g., NAT, firewall VPCs)
- Scales up to thousands of VPCs
Memory trick: Transit Gateway is the 'central station' for your VPCs and on-prem.
AWS Gateway Load Balancer (GWLB)
Flip cardA load balancer that makes it easy to deploy, scale, and manage your virtual appliances, such as firewalls, intrusion detection and prevention systems.
- Operates at Layer 3 (network layer)
- Transparently inserts virtual appliances into network path
- Uses GWLB endpoints to route traffic to/from appliance VPC
- Supports both north-south and east-west traffic inspection
Memory trick: GWLB is the Gateway to your virtual appliance fleet.
AWS Hybrid Cloud Connectivity
Flip cardServices that enable connecting on-premises data centers to the AWS cloud, facilitating hybrid cloud architectures.
- AWS Site-to-Site VPN uses the public internet, encrypted.
- AWS Direct Connect provides a dedicated private connection.
- Choice depends on performance, reliability, and security needs.
Memory trick: Connect to AWS: VPN for quick, Direct Connect for dedicated.
Network Load Balancer (NLB)
Flip cardA Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP) and is optimized for extreme performance, high throughput, and ultra-low latency, making it suitable for demanding network traffic distribution.
- Supports TCP and UDP protocols.
- Handles millions of requests per second.
- Provides static IP addresses per Availability Zone.
Memory trick: For raw 'Network' (Layer 4) traffic like 'UDP', you need the 'Network Load Balancer'.
ALB Listener Authentication
Flip cardAn Application Load Balancer feature that allows it to authenticate users directly using various Identity Providers (IdPs) before forwarding requests to backend targets.
- Supports Amazon Cognito, OpenID Connect (OIDC), and SAML 2.0
- Offloads authentication logic from backend applications
- Enhances security by ensuring only authenticated requests reach the application
- Configured as part of an ALB listener rule
Memory trick: ALB Authenticates, Listens, Routes, and Balances.
NAT Gateway
Flip cardA NAT Gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Resides in a public subnet.
- Requires an Elastic IP address.
- Private subnets route outbound internet traffic to the NAT Gateway.
Memory trick: Private instances need a 'NAT' to 'navigate' the internet safely and one-way.
Route 53 Geolocation & Failover Routing
Flip cardGeolocation routing directs traffic based on user location, while Failover routing redirects traffic to a secondary resource if the primary becomes unhealthy, often used together for regional resilience.
- Geolocation: Directs users to nearest endpoint.
- Failover: Redirects if primary is unhealthy.
- Combine for location-aware, resilient applications.
Memory trick: To be 'Geo' (location-aware) and 'Failover' (resilient), combine the 'Geolocation' and 'Failover' policies.
Route 53 Routing Policies
Flip cardDifferent strategies used by Amazon Route 53 to determine how DNS queries are responded to, enabling various traffic management capabilities.
- Simple: Default, basic DNS.
- Latency: Routes to region with lowest latency.
- Failover: Routes to primary, falls back to secondary on failure.
- Geolocation: Routes based on user's geographic location.
Memory trick: Route 53: Your DNS traffic cop, policies guide the way.
Route 53 ALIAS Record
Flip cardA Route 53-specific record type that provides a CNAME-like functionality for apex domains (root domains) to AWS resources, such as CloudFront distributions, without the limitations of CNAMEs.
- Can be used for apex domains (e.g., example.com).
- Points to specific AWS resources (CloudFront, ELB, S3 bucket).
- No extra DNS query charges for ALIAS queries.
Memory trick: ALIAS is the special Route 53 record for your root domain's AWS shortcut.
Public-facing Web Architecture
Flip cardA common AWS architecture for hosting web applications that are accessible from the internet, ensuring high availability, scalability, and security.
- Uses Internet Gateway for internet connectivity.
- Employs Load Balancers (ALB for HTTP/HTTPS) for traffic distribution.
- Security Groups protect instances at the network interface level.
Memory trick: Internet Gateway opens the door, ALB directs traffic, Security Group guards the instances.
Transit Gateway Peering
Flip cardTransit Gateway peering allows you to connect two Transit Gateways across different AWS Regions, enabling private communication between their attached VPCs and on-premises networks.
- Connects Transit Gateways across regions.
- Enables private, low-latency cross-region traffic.
- Extends the Transit Gateway network globally.
Memory trick: To 'peer' across 'regions' with Transit Gateway, you need 'Transit Gateway peering'.
Amazon CloudFront
Flip cardA global content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency.
- Caches content at edge locations for improved performance.
- Supports HTTPS for secure content delivery.
- Integrates with S3 for static website hosting.
Memory trick: CloudFront is your global front door for fast content.
AWS VPC Endpoints
Flip cardA feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink.
- Traffic stays within the Amazon network.
- Eliminates need for Internet Gateway or NAT Gateway for service access.
- Two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints (for S3, DynamoDB).
Memory trick: VPC Endpoint is your private tunnel to AWS services.
EC2 Enhanced Networking
Flip cardA feature that provides significantly higher packet per second (PPS) performance, lower network jitter, and lower latency for EC2 instances.
- Uses Elastic Network Adapter (ENA) or Intel 82599 Virtual Function (VF) interface.
- Crucial for high-performance computing (HPC) and network-intensive applications.
- Must be enabled on supported instance types.
Memory trick: ENA is the engine for EC2's network speed and smoothness.
Route 53 Failover Routing Policy
Flip cardA Route 53 routing policy that allows you to route traffic to a primary resource when it's healthy, and to a secondary resource when the primary is unhealthy.
- Requires Route 53 health checks
- Supports active-passive failover configurations
- Ideal for disaster recovery and high availability
Memory trick: Simple is one, Weighted is a slice, Latency is fast, Failover is a backup.
CloudFormation DeletionPolicy
Flip cardA resource attribute in AWS CloudFormation templates that controls what happens to a resource when its containing stack is deleted or the resource is removed from the template.
- Can be set to Retain, Snapshot, or Delete.
- Retain prevents resource deletion.
- Snapshot creates a backup before deletion.
Memory trick: DeletionPolicy dictates destiny.
S3 Event Notifications to Lambda
Flip cardAmazon S3 Event Notifications allow you to configure S3 buckets to send notifications to AWS Lambda functions (or SQS/SNS) when specified events (like object creation or deletion) occur.
- Event types include `s3:ObjectCreated:*`, `s3:ObjectRemoved:*`.
- Lambda function receives event details as input.
- Enables real-time, event-driven processing of S3 objects.
Memory trick: S3 *notifies* Lambda when something new *pops* in.
CloudWatch Agent
Flip cardThe CloudWatch Agent is a unified agent for collecting system-level metrics and application logs from Amazon EC2 instances and on-premises servers, sending them to Amazon CloudWatch.
- Collects both metrics and logs.
- Supports various operating systems (Linux, Windows).
- Configurable via a JSON file to specify log sources and destinations.
Memory trick: The CloudWatch Agent is like a little *log-collecting cloud* on your EC2 instance.
AWS Systems Manager Patch Manager
Flip cardA service that automates the process of patching managed instances with security updates and other types of updates.
- Automates patch scanning and installation.
- Integrates with Maintenance Windows for scheduling.
- Supports Windows and Linux operating systems.
Memory trick: Systems Manager patches, Maintenance Window catches.
Automated Least Privilege Enforcement
Flip cardAutomated least privilege enforcement involves continuously monitoring resource permissions and automatically adjusting them to grant only the necessary access, reducing the attack surface.
- AWS Config monitors resource configurations.
- Custom Config rules can define compliance for IAM roles.
- Remediation actions can automatically adjust non-compliant permissions.
- Helps maintain security posture and compliance.
Memory trick: Config Rules Detect, Remediate Overly Permissive Roles.
RDS Encryption with KMS CMKs
Flip cardAmazon RDS encryption with AWS KMS Customer-Managed Keys (CMKs) enables data at rest encryption for database instances, allowing customers to control key lifecycle, rotation, and audit key usage.
- Encrypts database instances, snapshots, and backups.
- Leverages AWS KMS for key management.
- CMKs allow customer control over key policies and rotation.
- Key usage is auditable via AWS CloudTrail.
Memory trick: RDS Keys: CMK = Control, Managed, Rotated, Auditable.
AWS Secrets Manager
Flip cardAWS Secrets Manager helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Securely stores secrets (credentials, API keys).
- Automates secret rotation natively.
- Integrates with AWS services and applications.
- Provides granular access control.
Memory trick: Secrets Manager: 'S'ecure 'M'anagement 'A'nd 'R'otation.
IAM Identity Federation
Flip cardIAM Identity Federation allows external identities (e.g., from corporate directories, social identity providers) to access AWS resources without creating IAM users for each person.
- Uses temporary security credentials.
- Supports SAML 2.0, OpenID Connect (OIDC), and custom federation.
- Leverages IAM roles with trust policies.
- Enhances security by eliminating long-term credentials.
Memory trick: Federation: Trust an IdP to Give Temporary Role Keys.
AWS Organizations Service Control Policies (SCPs)
Flip cardPolicy type that allows you to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in an organization.
- Apply to all IAM users and roles in affected accounts.
- Are preventative controls (deny actions before they happen).
- Cannot grant permissions; they only filter existing permissions.
Memory trick: SCPs secure the organization, strictly preventing bad behavior.
AWS Systems Manager State Manager
Flip cardA Systems Manager capability that allows you to define and apply a consistent configuration state across your EC2 instances and on-premises servers.
- Enforces desired state configuration.
- Uses documents (e.g., 'AWS-JoinDomain') for tasks.
- Can be scheduled or applied on association.
Memory trick: State Manager ensures domain's embrace.
S3 Public Access Prevention
Flip cardPreventing public access to Amazon S3 buckets is crucial for data security and compliance, often achieved through a combination of preventative and detective controls.
- Amazon S3 Block Public Access settings are the primary control.
- AWS Organizations SCPs can prevent public access at the organizational level.
- AWS Config can detect and remediate non-compliant buckets.
Memory trick: SCP Stops Public S3, Block Public Access Locks It Down.
Service Control Policies (SCPs)
Flip cardSCPs are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in an organization.
- Apply to all IAM users and roles in affected accounts.
- Do not grant permissions directly; they filter permissions.
- Can be used to deny specific actions or resources.
- Preventive security control.
Memory trick: SCPs Secure Cloud Policies.
Amazon GuardDuty
Flip cardAmazon GuardDuty is a fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.
- Uses machine learning, anomaly detection, and threat intelligence.
- Monitors AWS CloudTrail, VPC Flow Logs, and DNS logs.
- Detects unusual API calls, compromised instances, and crypto mining.
- Provides actionable security findings.
Memory trick: GuardDuty Guards Your AWS Accounts with Smart Threat Detection.
S3 Default Encryption
Flip cardAmazon S3 Default Encryption allows you to configure an S3 bucket to automatically encrypt new objects when they are uploaded, ensuring all data at rest in the bucket is encrypted.
- Applies to all new objects uploaded to the bucket.
- Supports SSE-S3 (AES-256) or SSE-KMS.
- Eliminates the need for users to specify encryption headers.
Memory trick: Default Encryption makes S3 *definitely sure* all data is locked up.
S3 Object Lock Compliance Mode
Flip cardS3 Object Lock in Compliance mode provides the strongest level of immutability for objects, preventing them from being overwritten or deleted by any user, including the root user, during a specified retention period.
- Once set, retention period cannot be shortened or removed.
- Protects against accidental and malicious deletion/modification.
- Suitable for strict regulatory compliance (e.g., HIPAA, FINRA).
- Applies to new objects uploaded to a bucket with Object Lock enabled.
Memory trick: Compliance Mode: No Deletion, Not Even by Root, for Records.
EBS Encryption with Customer-Managed Keys
Flip cardEncrypting Amazon EBS volumes using a Customer-Managed Key (CMK) in AWS Key Management Service (KMS) allows the customer to control and manage the encryption keys for data at rest.
- Encrypts data on EBS volumes at rest.
- Customer controls the KMS CMK lifecycle.
- Integrates seamlessly with EC2 and EBS.
- Ensures compliance with key management requirements.
Memory trick: EBS encryption with CMK: 'E'ncrypt 'B'y 'S'pecifying 'C'ustomer 'M'anaged 'K'ey.
S3 Access Control Best Practices
Flip cardCombine S3 bucket policies for fine-grained permissions and S3 Block Public Access settings to prevent unintended public exposure of sensitive data.
- Bucket policies control access at the bucket level.
- Bucket policies support IP conditions.
- S3 Block Public Access prevents all public access.
- Block Public Access is a strong preventative control.
Memory trick: Bucket Policy is the bouncer, Block Public Access is the bolted door.
CodePipeline CodeCommit Integration
Flip cardAWS CodePipeline automatically detects changes in an AWS CodeCommit repository when configured as a source stage, triggering pipeline executions without extra manual steps.
- Uses CloudWatch Events rules internally.
- Supports specific branches or all branches.
- Simplifies CI/CD setup for CodeCommit users.
Memory trick: CodePipeline *sees* CodeCommit changes and just *goes*.
AWS Serverless Application Model (SAM)
Flip cardAWS SAM is a framework that extends AWS CloudFormation to provide a simplified way of defining serverless applications, bundling multiple components (Lambda, API Gateway, DynamoDB, etc.) into a single deployable unit.
- Uses a simplified YAML/JSON template syntax.
- Builds upon CloudFormation, transpiles to CloudFormation.
- Includes SAM CLI for local development and testing.
Memory trick: SAM makes Serverless Apps a Simple, single unit.
EC2 User Data for Domain Join
Flip cardEC2 User Data allows scripts to be executed on an EC2 instance during its initial launch, making it ideal for immediate tasks like automatically joining a Windows instance to an Active Directory domain.
- Runs only once at first boot.
- Can be used for bootstrapping and configuration.
- Integrates well with AWS Directory Service for domain joins.
Memory trick: User Data welcomes new EC2 instances to the Directory Service family right away.
CloudFormation Stack Policies
Flip cardCloudFormation Stack Policies are JSON documents that define which update actions (e.g., Delete, Replace) are allowed on specific resources within a CloudFormation stack, preventing unintended modifications.
- Applied to an entire stack, not individual resources.
- Overrides IAM permissions for stack updates.
- Useful for protecting critical resources from accidental changes.
Memory trick: CloudFormation Stack Policies act like a guardian shield over your precious resources.
AWS Identity Federation with AD
Flip cardIntegrates on-premises Active Directory with AWS to allow users to sign in to AWS using their existing corporate credentials and assume IAM roles for access.
- Uses AWS Directory Service for Microsoft Active Directory.
- Enables single sign-on (SSO) experience.
- Grants permissions via IAM roles.
Memory trick: Federate for familiar faces, roles for restricted rights.
AWS Glue Triggers
Flip cardMechanisms within AWS Glue that initiate the execution of Glue jobs or crawlers based on schedules, on-demand, or events.
- Supports time-based schedules (cron).
- Supports event-based triggers (e.g., S3 object creation).
- Can trigger multiple jobs sequentially or in parallel.
Memory trick: Commit, Pipeline, then Glue Triggers align.
Systems Manager State Manager
Flip cardAWS Systems Manager State Manager is a secure and scalable configuration management service that automates the process of defining and maintaining a consistent desired state for your EC2 instances and on-premises servers.
- Uses Associations to apply configurations.
- Supports various document types (e.g., `AWS-RunShellScript`, `AWS-ApplyAnsiblePlaybooks`).
- Provides compliance reporting for configuration drift.
Memory trick: State Manager keeps your fleet in the *state* you desire, like a helpful robot.
AWS CloudFormation Guard
Flip cardAn open-source policy-as-code tool that allows developers to define and enforce rules for CloudFormation templates to ensure compliance and security before deployment.
- Validates templates against custom policies.
- Integrates into CI/CD pipelines.
- Supports security, compliance, and best practice checks.
Memory trick: Guard protects templates, policies stand tall.
AWS CodePipeline
Flip cardA fully managed continuous delivery service that automates release pipelines for fast and reliable application and infrastructure updates.
- Orchestrates entire release process (build, test, deploy).
- Integrates with other AWS services and third-party tools.
- Automates application and infrastructure updates.
Memory trick: Pipeline powers progress, pushing code through stages.
KMS CMKs with FIPS 140-2
Flip cardAWS Key Management Service (KMS) allows customers to use customer-managed keys (CMKs) for encryption. KMS is designed to be FIPS 140-2 validated, meaning its underlying hardware security modules (HSMs) meet specific security standards, often Level 2, with FIPS endpoints available for Level 3 compliance.
- CMKs provide customer control over encryption keys.
- KMS uses FIPS 140-2 validated HSMs.
- FIPS 140-2 Level 3 offers strong cryptographic protection.
- Redshift integrates with KMS for data at rest encryption.
Memory trick: Redshift CMK FIPS: Secure Data Warehouse.
RDS IAM Database Authentication + SSL/TLS
Flip cardIAM database authentication allows you to authenticate to your Amazon RDS database instance using AWS IAM. This provides a more secure and centralized way to manage database access. Combining it with SSL/TLS ensures both strong client authentication and encrypted communication in transit.
- Uses IAM users/roles for database authentication.
- Eliminates need for traditional database credentials.
- SSL/TLS encrypts data in transit.
- Provides fine-grained access control.
Memory trick: IAM + SSL: Secure RDS Connections.
EC2 User Data
Flip cardA script or set of commands provided to an EC2 instance at launch time, which runs during the initial boot cycle to perform setup tasks.
- Runs only once, during the first boot.
- Can install software, configure services, download files.
- Supports shell scripts and cloud-init directives.
Memory trick: User Data, the instance's first directive.
KMS Customer-Managed Keys (CMK)
Flip cardCustomer-Managed Keys (CMKs) in AWS Key Management Service (KMS) are encryption keys created and managed by the user, providing full control over their policies, rotation, and lifecycle.
- Users define key policies and permissions.
- Users control key rotation (manual or automatic).
- Users control key lifecycle, including enabling/disabling/deleting.
- Used for encrypting data across many AWS services.
Memory trick: Control My Keys: Customer-Managed Keys give ME the power!
S3 Data Event Auditing
Flip cardS3 data event auditing involves logging all object-level API activities within an Amazon S3 bucket to meet compliance, security, and operational requirements.
- Enabled via AWS CloudTrail data events.
- Captures GetObject, PutObject, DeleteObject, etc.
- Records caller identity, timestamp, IP address, and resource.
- Logs are stored in an S3 bucket for long-term retention.
Memory trick: CloudTrail Data Events: Who, What, When, Where for S3 Objects.
RDS SSL/TLS Encryption
Flip cardAmazon RDS supports SSL/TLS to encrypt connections between your application and your database instances, securing data in transit.
- Encrypts data between client and RDS instance.
- Uses standard SSL/TLS protocols.
- Configured at the RDS instance level.
Memory trick: Transit means travel, so encrypt the connection's tunnel.
Amazon GuardDuty S3 Protection
Flip cardAmazon GuardDuty's S3 Protection feature continuously monitors S3 data events and access logs for suspicious activity and generates security findings for potential threats.
- Detects unusual S3 access patterns.
- Monitors data events (CloudTrail) and access logs.
- Generates security findings and alerts.
- Fully managed threat detection service.
Memory trick: GuardDuty is the 'Guard' that 'Detects' the 'Duty' of watching S3.
AWS Config Remediation
Flip cardAWS Config continuously monitors resource configurations for compliance and can automatically trigger remediation actions using AWS Systems Manager Automation documents.
- Config detects non-compliant resources.
- Rules can be predefined or custom.
- Systems Manager Automation executes remediation.
- Enables automated compliance enforcement.
Memory trick: Config checks, Systems Manager fixes, automatically.
AWS Step Functions
Flip cardAWS Step Functions is a serverless workflow service that lets you combine AWS Lambda functions and other AWS services to build business-critical applications. You design workflows as state machines, which automatically manage the state, retries, and error handling for you.
- Visual workflow builder (state machine).
- Supports sequential, parallel, choice, and wait states.
- Built-in error handling, retries, and compensation logic.
Memory trick: Step Functions makes complex workflows take all the right *steps* and *turns*.
AWS CloudFormation StackSets
Flip cardAn extension of CloudFormation that enables you to provision, update, or delete stacks across multiple AWS accounts and regions with a single operation.
- Deploys stacks across multiple accounts/regions.
- Manages consistent resource deployment across an organization.
- Ideal for baseline configurations and shared services.
Memory trick: StackSets stack up resources, across the accounts, consistently.
AWS Config with Systems Manager Automation
Flip cardA combination of services where AWS Config detects non-compliant resource configurations and triggers Systems Manager Automation to automatically remediate them.
- Config Rules continuously evaluate resource compliance.
- Automation documents define remediation steps.
- Provides automated detection and self-healing for non-compliant resources.
Memory trick: Config checks, Automation corrects, compliance connects.
AWS Control Tower
Flip cardAWS Control Tower provides an easy way to set up and govern a secure, multi-account AWS environment, automating the creation of accounts with a baseline of security and operational best practices.
- Uses Account Factory for new account provisioning.
- Implements preventive and detective guardrails.
- Integrates with AWS Organizations for account management.
Memory trick: Control Tower *controls* your AWS accounts, setting up a *safe town* for them.
CodePipeline Approval Action
Flip cardA stage action in AWS CodePipeline that pauses the pipeline and waits for manual approval or rejection before proceeding to the next stage.
- Requires human intervention for decision-making.
- Can be configured with a timeout.
- Ideal for gatekeeping production deployments.
Memory trick: Approval action, the human checkpoint.