AWS Certified DevOps Engineer – Professional flashcards
153 free flashcards. Tap a card to flip it.
AWS CloudFormation
Flip cardAn AWS service that helps you model and set up your AWS resources so that you can spend less time managing those resources and more time focusing on your applications that run in AWS.
- Uses declarative templates (YAML or JSON).
- Supports version control and consistent deployments.
- Manages entire stacks of resources as a single unit.
Memory trick: CloudFormation builds your cloud, code by code, true and bold.
Amazon EC2 Spot Instances
Flip cardUnused EC2 capacity available at a discounted price, ideal for fault-tolerant, flexible applications that can handle interruptions.
- Up to 90% cost savings compared to On-Demand.
- Instances can be interrupted by AWS with a 2-minute notice.
- Best for batch jobs, big data, CI/CD, and other stateless workloads.
Memory trick: Spot instances: Save substantially, sacrifice stability.
CloudFormation StackSets Update
Flip cardCloudFormation StackSets allow you to update the underlying template, which then propagates changes to all deployed stack instances across specified AWS accounts and regions.
- Propagates changes to many accounts/regions.
- Manages updates to existing stack instances.
- Ensures consistency across distributed infrastructure.
Memory trick: StackSets update is like sending out a new memo; everyone gets the latest information from a single source.
AWS Transit Gateway
Flip cardA network transit hub that centralizes network connectivity for VPCs and on-premises networks, simplifying routing and management.
- Connects thousands of VPCs and on-premises networks.
- Simplifies network architecture and reduces operational overhead.
- Acts as a central gateway for inter-VPC and hybrid cloud connectivity.
Memory trick: Transit Gateway: Tame your traffic, centralize your connections.
CodeDeploy Deployment Group
Flip cardAn AWS CodeDeploy Deployment Group specifies the set of individual Amazon EC2 instances, AWS Lambda functions, or Amazon ECS services to which an application revision is deployed. It also defines the deployment configuration and strategies, such as blue/green or in-place deployments.
- Defines target instances/services for deployment.
- Specifies deployment type (in-place, blue/green).
- Includes rollback settings and load balancer integration.
- Integral to automated, safe application delivery.
Memory trick: DeploymentGroup is the traffic controller for your CodeDeploy rollout.
Blue/Green Deployment
Flip cardBlue/Green deployment is an application release strategy that reduces downtime and risk by running two identical production environments, 'Blue' (current version) and 'Green' (new version).
- Zero downtime during deployment.
- Instant rollback capability if issues arise.
- New version is thoroughly tested in 'Green' before traffic shift.
- Requires double the infrastructure for a short period.
Memory trick: Blue/Green for safe, swift, and sure updates.
Amazon CodeGuru Security
Flip cardAn AWS machine learning-powered service that automatically finds security vulnerabilities in your application code and provides recommendations to fix them. It can detect issues like hardcoded secrets, sensitive data exposure, injection flaws, and more.
- Static Application Security Testing (SAST).
- Detects security vulnerabilities and hardcoded secrets in code.
- Integrates with popular code repositories (e.g., GitHub, CodeCommit).
Memory trick: CodeGuru Security is the 'secret detective' of your code repositories.
Secrets Manager with CloudFormation
Flip cardAWS Secrets Manager securely stores, manages, and automatically rotates database credentials and other secrets. CloudFormation can integrate with Secrets Manager using dynamic references to retrieve these secrets during stack creation or updates, ensuring secrets are never hardcoded in templates and are managed securely.
- Stores secrets securely (encrypted at rest and in transit).
- Offers automatic rotation for various database types.
- CloudFormation uses dynamic references to retrieve secrets at deploy time.
- Applications retrieve secrets dynamically at runtime from Secrets Manager.
Memory trick: Secrets Manager is your vault for CloudFormation's dynamic secrets.
Scheduled Scaling
Flip cardA feature of AWS Auto Scaling that allows you to adjust the capacity of your Auto Scaling group based on a predictable schedule.
- Ideal for predictable traffic patterns (e.g., daily, weekly, seasonal spikes).
- Ensures resources are provisioned proactively before demand increases.
- Can be used to scale both out and in.
Memory trick: Schedule your scaling, save your servers from suffering.
Route 53 Failover Routing
Flip cardAmazon Route 53 failover routing policy allows you to route traffic to a healthy backup resource when your primary resource becomes unhealthy, ensuring high availability and disaster recovery.
- Routes traffic to a secondary resource if the primary fails.
- Relies on Route 53 health checks to determine resource health.
- Essential for achieving high availability and disaster recovery (DR).
- Can be configured for active-passive or active-active setups.
Memory trick: When the primary road closes, Failover Routing automatically guides traffic to the detour.
Centralized Egress Inspection with TGW
Flip cardA Transit Gateway (TGW) facilitates centralized egress traffic inspection by routing all internet-bound traffic from spoke VPCs through an inspection VPC containing a firewall appliance, before reaching the Internet Gateway.
- TGW simplifies inter-VPC routing at scale.
- Enables hub-and-spoke network topology.
- Allows for mandatory traffic inspection before internet access.
Memory trick: All 'traffic' must 'pass' through the 'transit' 'inspection' 'gate'.
S3 Cross-Region Replication (CRR)
Flip cardAn S3 feature that automatically replicates objects from a source bucket in one AWS Region to a destination bucket in another AWS Region.
- Asynchronous replication.
- Requires versioning to be enabled on both source and destination buckets.
- Used for disaster recovery, compliance, and latency reduction.
Memory trick: Cross-Region Replication: Copy data, conquer crises.
Asynchronous Decoupling with SQS
Flip cardAn architectural pattern where components communicate indirectly through a message queue like Amazon SQS, preventing direct dependencies.
- Buffers requests, protecting downstream services from overload.
- Enhances fault tolerance by allowing services to process messages at their own pace.
- Prevents cascading failures and improves overall system resilience.
Memory trick: Decouple with queues, conquer cascading chaos.
ECS Fargate Target Tracking Scaling
Flip cardTarget Tracking scaling for Amazon ECS Fargate automatically adjusts the number of tasks in a service to keep a specific metric (e.g., CPU utilization, ALB request count) at a target value.
- Proactive and reactive scaling.
- Automatically adjusts capacity to maintain performance.
- Simplifies auto-scaling configuration.
- Ideal for fluctuating workloads.
Memory trick: Fargate scales to target, keeps costs in sight.
CloudFormation Guard
Flip cardA policy-as-code tool that allows developers to define rules to validate CloudFormation templates against organizational policies before deployment.
- Enforces security and compliance policies pre-deployment.
- Integrates into CI/CD pipelines for automated checks.
- Prevents non-compliant infrastructure provisioning.
Memory trick: Guard your templates before they build the wrong thing.
CodePipeline Manual Approval
Flip cardA CodePipeline action type that pauses the pipeline execution at a specific stage, requiring a designated user or group to manually approve or reject the continuation of the pipeline.
- Integrates directly into CodePipeline stages.
- Sends notifications (e.g., via SNS) for approval requests.
- Provides an approval URL in the AWS Console.
Memory trick: To 'gate' the 'pipeline', use the 'manual' 'switch'.
Target Tracking Scaling Policy
Flip cardA target tracking scaling policy for an Auto Scaling group adjusts the desired capacity of the group to maintain a specified target value for a chosen metric, such as average CPU utilization or ALB request count. It automatically calculates the scaling adjustments needed.
- Proactively adjusts capacity to maintain a target metric.
- Ideal for handling unpredictable and fluctuating workloads.
- More responsive and smoother than simple or step scaling.
- Supports various metrics, including custom metrics like ALB RequestCountPerTarget.
Memory trick: Target Tracking aims for steady performance, hitting the bullseye even when traffic zips.
Aurora Multi-Master
Flip cardAn Amazon Aurora feature that allows you to create multiple read/write instances of a single database cluster, providing continuous availability with synchronous replication.
- All instances are active primary instances, capable of read/write.
- Provides zero RPO and near-zero RTO for failures.
- Supports synchronous replication for extreme availability (currently within a region).
Memory trick: Multi-Master: Maximize availability, minimize downtime, zero data loss.
AWS Config
Flip cardA service that enables you to assess, audit, and evaluate the configurations of your AWS resources. Config continuously monitors and records your AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations.
- Continuous monitoring of AWS resource configurations.
- Evaluates compliance against rules.
- Supports automated remediation via Systems Manager or Lambda.
Memory trick: Config checks and corrects, ensuring compliance constantly.
SCP for S3 Encryption Enforcement
Flip cardA Service Control Policy (SCP) can be used within AWS Organizations to enforce S3 bucket encryption standards (e.g., requiring KMS CMKs) by denying actions that create or modify buckets without the specified encryption.
- SCPs apply to accounts or OUs, not specific resources.
- They are preventative controls, denying actions that violate policy.
- Cannot grant permissions; only restrict what IAM policies can grant.
Memory trick: To 'control' 'all' 'buckets', use the 'organizational' 'policy'.
Configuration Drift
Flip cardThe phenomenon where the actual state of an infrastructure resource deviates from its desired or defined state, often due to manual changes outside of an Infrastructure as Code (IaC) process.
- Leads to inconsistencies and unpredictable behavior.
- Makes troubleshooting difficult and compromises security.
- Can be detected using tools that compare actual vs. desired state.
Memory trick: Drift Detection finds the gap, Config keeps the state on the map.
CloudFormation Exports/Imports
Flip cardA mechanism in AWS CloudFormation to share output values from one stack to other stacks, enabling modular and loosely coupled infrastructure deployments.
- Outputs from a stack can be 'exported' with a unique name.
- Other stacks can 'import' these exported values using `Fn::ImportValue`.
- Facilitates independent management and updates of related stacks.
Memory trick: Export for sharing, import for using, independent stacks keep on cruising.
AWS Secrets Manager
Flip cardA service that helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Stores and manages secrets securely.
- Offers automatic rotation of credentials.
- Integrates with other AWS services like IAM and KMS.
Memory trick: Secrets Manager: Your key to secure, rotating credentials, never hardcoded.
Decoupling with SQS
Flip cardDecoupling application components using an Amazon SQS queue allows independent scaling, improves fault tolerance by buffering requests, and absorbs traffic spikes, preventing cascading failures.
- SQS acts as a buffer between producers and consumers.
- Producers can write messages quickly without waiting for consumers.
- Consumers can process messages at their own rate, scaling independently.
- Prevents system overload during traffic spikes and improves overall resilience.
Memory trick: SQS queue absorbs the wave, processes at its own pace.
Amazon CloudFront
Flip cardAmazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency and high transfer speeds.
- Caches content at edge locations worldwide.
- Reduces latency and offloads origin servers.
- Supports custom domains and SSL/TLS encryption.
- Integrates seamlessly with S3, EC2, and other AWS services.
Memory trick: CloudFront is the global delivery truck, bringing content closer to every customer.
IAM Roles with IaC
Flip cardUsing Infrastructure as Code (IaC) tools like CloudFormation to define and manage AWS Identity and Access Management (IAM) roles, ensuring automated, consistent, and least-privilege permissions for resources.
- Automates IAM role creation and updates.
- Enforces least privilege by defining specific permissions in code.
- Integrates role lifecycle with resource lifecycle.
Memory trick: Each microservice, its own IAM role, defined in code, keeping control.
CloudFormation with CodeDeploy Blue/Green
Flip cardAWS CloudFormation can be integrated with AWS CodeDeploy to automate blue/green deployment strategies for applications running on Amazon EC2 instances and Auto Scaling groups.
- Automates creation of new 'green' environment.
- Orchestrates traffic shifting from 'blue' to 'green'.
- Minimizes downtime and provides rollback capabilities.
Memory trick: CodeDeploy handles the traffic switch, CloudFormation builds the new road.
Stack Policies & SCPs for Prevention
Flip cardCloudFormation Stack Policies prevent unintended updates or deletions of specific stack resources. AWS Organizations Service Control Policies (SCPs) act as preventative guardrails at the account or organizational level, denying actions even if an IAM user/role has explicit permissions, providing a strong, multi-layered defense against unauthorized infrastructure modifications.
- Stack Policies: resource-level prevention within a stack.
- SCPs: account/organizational-level prevention, overriding IAM.
- Together, they offer robust, proactive protection for critical infrastructure.
- Preventative controls, not just detective.
Memory trick: Stack Policies guard the resources, SCPs guard the accounts.
Secrets in Code Prevention
Flip cardThe practice of ensuring that no sensitive information (e.g., API keys, passwords, private keys) is hardcoded or accidentally committed into source code repositories.
- Uses secret scanning tools (e.g., Git-Secrets, TruffleHog).
- Integrates into CI/CD pipelines and pre-commit hooks.
- Complements secure secret storage solutions like AWS Secrets Manager.
Memory trick: Scan pre-commit, secrets out of sight, Manager keeps them safe and tight.
AWS CloudFormation StackSets
Flip cardAn extension of CloudFormation that enables you to provision, update, or delete CloudFormation stacks across multiple AWS accounts and regions from a single operation.
- Centralized management of common infrastructure.
- Supports deployment to multiple accounts and regions.
- Ideal for enterprise-scale IaC consistency.
Memory trick: StackSets spreads your stacks, across accounts and regions, bringing order back.
AWS Global Accelerator
Flip cardA networking service that improves the availability and performance of your applications by directing user traffic to the nearest healthy endpoint in an AWS Region using static Anycast IP addresses.
- Uses the AWS global network backbone for reduced latency.
- Provides static Anycast IP addresses as fixed entry points.
- Automatically reroutes traffic to healthy endpoints across regions during failures.
Memory trick: Global Accelerator: Go faster, get failover, globally.
Redshift COPY Command Transactionality
Flip cardThe `COPY` command in Amazon Redshift loads data from S3 into tables as a single, atomic transaction, ensuring that either all data is loaded or none is.
- Inherently transactional: all-or-nothing operation.
- Most efficient way to load large datasets from S3.
- Maintains data consistency during batch loads.
Memory trick: COPY command: Commit completely, consistent forever.
ALB-to-EC2 Encryption
Flip cardTo encrypt traffic between an Application Load Balancer and its backend EC2 instances, the backend instances must have SSL/TLS certificates installed and the ALB's target group must be configured to use HTTPS.
- ALB can terminate SSL/TLS, but this doesn't encrypt to instances.
- Target group protocol determines ALB-to-instance communication.
- Instances need certs if the target group uses HTTPS.
Memory trick: ALB needs a 'cert' to talk 'securely' to 'servers'.
Aurora Global Database Unplanned Failover
Flip cardAn unplanned failover for an Aurora Global Database involves promoting a secondary cluster in a different region to become the new primary, typically in less than a minute, to recover from a primary region outage with near-zero data loss (near-zero RPO).
- Used for disaster recovery when the primary region is unavailable.
- Promotes a secondary cluster to primary role.
- Achieves very low RTO (often <1 minute) and RPO (near-zero).
- Requires updating application endpoints to point to the new primary.
Memory trick: When the primary region burns, Global DB's unplanned promotion quickly makes a new leader.
Multi-Tenant Isolation Strategies
Flip cardMethods used in SaaS architectures to ensure that different customers (tenants) cannot access or interfere with each other's data or resources.
- Crucial for security, privacy, and compliance.
- Ranges from shared infrastructure with logical separation to dedicated infrastructure.
- AWS accounts provide the strongest logical isolation boundary.
Memory trick: Each customer gets their own 'house' (account) for ultimate privacy.
CloudFormation Outputs & Fn::ImportValue
Flip cardCloudFormation Outputs allow values from a stack to be exposed, and `Fn::ImportValue` allows other stacks in the same region to reference these exported values.
- Enables cross-stack referencing.
- Creates dynamic links between stacks.
- Facilitates modular and reusable infrastructure.
Memory trick: Export from one, import to another, like passing a baton in a relay race.
CloudFormation SecureString Parameters
Flip cardA CloudFormation parameter type (`AWS::SSM::Parameter::Value<SecureString>`) that allows secure retrieval of encrypted values stored in AWS Systems Manager Parameter Store, preventing sensitive data exposure in templates or logs.
- References `SecureString` parameters from Systems Manager Parameter Store.
- CloudFormation automatically decrypts values at deployment.
- Ensures sensitive data is not hardcoded or exposed in plaintext.
Memory trick: SecureString from SSM, CloudFormation pulls it keen, no plaintext ever seen.
SQS FIFO Queues
Flip cardAmazon SQS FIFO (First-In, First-Out) queues guarantee that messages are processed exactly once, in the exact order that they are sent and received. They are designed for applications where the order of operations and exactly-once processing are critical.
- Guarantees message ordering (first-in, first-out).
- Ensures exactly-once message processing.
- Supports message deduplication to prevent duplicate deliveries.
- Uses message group IDs to maintain order within specific groups.
Memory trick: FIFO queues line up messages perfectly, delivering each one exactly once, like a meticulous postman.
Systems Manager State Manager
Flip cardAWS Systems Manager State Manager is a secure and scalable configuration management service that automates the process of keeping your Amazon EC2 instances and on-premises servers in a defined state. It ensures your instances are configured consistently, with necessary software, patches, or settings, and remediates drift.
- Maintains a desired configuration state for instances.
- Automatically applies configurations (e.g., agents, scripts).
- Continuously monitors and remediates configuration drift.
- Uses associations to link documents to target instances.
Memory trick: State Manager keeps your instances in the desired 'state' always.
Secrets Manager for RDS Rotation
Flip cardAWS Secrets Manager automates the storage, retrieval, and rotation of database credentials for services like Amazon RDS, enhancing security and reducing operational burden.
- Native integration with RDS for rotation.
- Can use Lambda functions for custom rotation logic.
- Provides API for application credential retrieval.
Memory trick: To 'spin' 'secrets' for 'RDS', 'Secrets Manager' is the 'key'.
Lambda Resource Policy for API Gateway
Flip cardA resource-based policy on an AWS Lambda function allows or denies other AWS services (like API Gateway) from invoking it, using conditions like `SourceArn` for granular control.
- Lambda functions use resource-based policies for invocation permissions.
- API Gateway invokes Lambda as a service principal.
- `SourceArn` condition restricts invocation to a specific API Gateway resource.
Memory trick: Lambda's 'door' has a 'policy' to 'check' the 'caller's' 'ID'.
AWS API Auditing
Flip cardThe process of recording, storing, and analyzing all API calls made to AWS services in an account to track activity, ensure accountability, and identify potential security incidents or compliance violations.
- Crucial for security and compliance.
- Provides a historical record of actions.
- Enables detection of unauthorized activity.
Memory trick: CloudTrail logs, S3 stores, SNS shouts - unauthorized access is caught!
S3 Event-Driven Content Scanning
Flip cardThis pattern uses S3 Event Notifications to automatically trigger serverless functions (e.g., AWS Lambda) upon object creation, enabling immediate processing like malware scanning, content moderation, or data transformation.
- Reacts to S3 object events in real-time.
- Leverages serverless compute (Lambda) for scalability.
- Minimizes operational overhead for event processing.
Memory trick: S3 event arrives, Lambda takes the call, scans the content, then tells one and all.
Container Image Vulnerability Scanning
Flip cardThe process of automatically scanning container images for known software vulnerabilities before deployment, often integrated into a CI/CD pipeline.
- Essential for secure software supply chain.
- Identifies CVEs (Common Vulnerabilities and Exposures).
- Can block deployments based on severity thresholds.
- Amazon Inspector is a key AWS service for this.
Memory trick: Inspect containers for vulnerabilities to prevent bad deployments.
Amazon CloudWatch
Flip cardAmazon CloudWatch is a monitoring and management service that provides data and actionable insights for AWS, hybrid, and on-premises applications and infrastructure resources.
- Collects metrics, logs, and events.
- Provides real-time monitoring and alarming.
- Offers dashboards for visualization and analysis.
Memory trick: CloudWatch watches all, from metrics to logs, it stands tall, for insights and alarms, it answers every call.
Automated Build Environment Patching
Flip cardA CI/CD strategy to continuously update and patch custom Docker images used as build environments, ensuring that pipelines always run on secure and up-to-date infrastructure.
- Critical for maintaining security posture.
- Often involves a separate dedicated pipeline.
- Automates rebuilding and pushing updated images to ECR.
- Updates dependent CI/CD projects to use the new image versions.
Memory trick: Pipeline patches the custom image, then updates the build.
Automated Forensic Data Collection with SSM Automation
Flip cardThis pattern uses AWS Systems Manager Automation documents to orchestrate the automated collection of forensic artifacts (snapshots, memory dumps, logs) from EC2 instances and securely store them, followed by instance isolation.
- Orchestrates complex incident response workflows.
- Automates data collection from EC2 instances.
- Ensures secure storage and instance isolation.
Memory trick: SSM Automation takes the lead, collects the data, plants the seed, then isolates the instance, a crucial deed.
AWS Organizations Service Control Policies (SCPs)
Flip cardSCPs are policy-based controls that specify the maximum permissions for an organization's accounts. They act as guardrails to ensure accounts stay within your organization's access control guidelines.
- Preventative controls, deny actions at the API level.
- Apply across multiple AWS accounts in an Organization.
- Cannot grant permissions, only restrict them.
Memory trick: SCPs are the ultimate gate, no public S3, it seals the fate, across all accounts, it sets the state.
Event-Driven Container Remediation
Flip cardUsing AWS EventBridge to detect specific container events (like restarts or crashes) and trigger automated actions via AWS Lambda to remediate the issue and notify relevant teams.
- EventBridge monitors ECS Task State Change events.
- Lambda functions execute custom remediation logic.
- SNS provides immediate notification to operations teams.
- Ensures application health and availability in containerized environments.
Memory trick: EventBridge sees a crash, Lambda fixes the task, SNS sends the alert.
S3 Event-Driven Video Transcoding
Flip cardAutomating video transcoding by using S3 Event Notifications to trigger a workflow orchestrated by AWS Step Functions, which then uses AWS Batch for scalable and cost-effective compute.
- S3 Event Notifications provide immediate triggers for new objects.
- Step Functions orchestrate complex, multi-step workflows with state management.
- AWS Batch scales compute resources efficiently for intensive tasks.
- Ensures high availability, scalability, and cost-effectiveness for media processing.
Memory trick: S3 uploads, Step Functions orchestrates, Batch transcodes.
Automated Remediation with AWS Config
Flip cardAutomated remediation uses AWS Config rules to detect non-compliant resources and automatically trigger actions (often via AWS Lambda) to restore them to a compliant state.
- Detects configuration drift.
- Triggers actions based on compliance status.
- Reduces manual intervention for security and operational issues.
Memory trick: CloudTrail captures the change, EventBridge rings the bell, Lambda fixes the rule, Config keeps it well.
Microservice CI/CD
Flip cardA CI/CD strategy where each microservice has its own independent pipeline, allowing for isolated builds, tests, and deployments.
- Each microservice has its own codebase and repository.
- Dedicated CI/CD pipeline for each microservice.
- Independent deployment cycles.
- Reduces blast radius of changes.
Memory trick: Independent Pipelines for Independent Services Ensure Seamless Operations.
Cross-Account Config Remediation
Flip cardThis involves using AWS Config rules deployed via AWS Organizations to continuously monitor resource compliance across multiple accounts and automatically trigger remediation actions for non-compliant resources.
- Centralized compliance management.
- Automated detection and remediation of drift.
- Scalable across many AWS accounts.
Memory trick: Organizations centralizes the rule, Config finds the non-compliant tool, then automates the fix, no longer a fool.
Amazon RDS Performance Insights
Flip cardAmazon RDS Performance Insights is a database performance monitoring feature that helps you quickly assess the load on your database and determine where to focus your analysis if there is a performance issue.
- Visualizes database load and wait events.
- Identifies top SQL queries by load.
- Minimal performance impact on the database.
Memory trick: Performance Insights, a clear view, for slow queries, it helps you through.
Multi-Region Database Migration Orchestration
Flip cardAutomating complex, sequential database schema migrations across multiple active-active regions, minimizing downtime by performing updates one region at a time.
- Requires careful orchestration of steps.
- Verification steps are crucial between regional migrations.
- Minimizes blast radius of potential issues.
- AWS Step Functions is a powerful orchestration tool for such scenarios.
Memory trick: Step by step, region by region, verify everything to keep it stable.
CodeDeploy Blue/Green Deployment
Flip cardA deployment strategy where a new version of an application is deployed to a separate, identical environment (green) while the old version (blue) continues to serve traffic. Traffic is shifted to the green environment only after it passes health checks.
- Minimizes downtime and risk.
- Easy rollback by shifting traffic back to the blue environment.
- Requires double the infrastructure during deployment.
- Ideal for critical applications requiring high availability.
Memory trick: Blue is old, Green is new, traffic shifts when Green is true.
Automated Incident Response with SSM Automation
Flip cardUsing AWS Systems Manager Automation documents, orchestrated by services like EventBridge, to automatically respond to security incidents by containing threats, collecting forensic data, and recording actions.
- EventBridge detects security findings (e.g., GuardDuty).
- SSM Automation documents execute predefined runbooks for response actions.
- Actions can include isolation, data collection, and notification.
- Provides an auditable trail of actions for compliance.
Memory trick: GuardDuty alerts, EventBridge triggers, SSM automates, Security Hub audits.
End-to-End (E2E) Testing
Flip cardA type of software testing that validates the entire software system and its components for integration and data integrity. It simulates real user scenarios to ensure the application works as expected from start to finish.
- Tests the full user journey.
- Includes UI, backend, and database interactions.
- Often uses tools like Selenium, Cypress, Playwright.
- Performed against a deployed environment (e.g., staging).
Memory trick: E2E tests the whole journey from start to finish.
Immutable Infrastructure
Flip cardImmutable infrastructure is an approach where servers are never modified after they are deployed. If changes are needed, a new server image is built with the changes, and existing servers are replaced by new ones.
- Increases consistency and reliability.
- Simplifies rollbacks and deployments.
- Enhances security by preventing configuration drift on running instances.
Memory trick: Build once, deploy many, never change a single one; if it drifts, replace it, and the problem's gone.
CodeBuild Caching
Flip cardA CodeBuild feature that stores frequently used files, such as dependencies or intermediate build artifacts, in a cache (S3 or local) to speed up subsequent builds by avoiding repeated downloads or computations.
- Reduces build times, especially for dependency-heavy projects.
- Can use Amazon S3 or a local cache within the build environment.
- Configured in the buildspec.yml or CodeBuild project settings.
- Improves CI/CD pipeline efficiency and cost.
Memory trick: Cache those dependencies to build fast in CodeBuild.