AWS Certified DevOps Engineer – Professional flashcards
153 free flashcards. Tap a card to flip it.
Database Schema Migration in CI/CD
Flip cardAutomating the process of applying incremental and reversible database schema changes as part of a continuous integration and continuous delivery pipeline, ensuring consistency and version control.
- Schema changes are version-controlled alongside application code.
- Tools like Liquibase or Flyway manage the migration process.
- Migrations are typically executed during the build or deployment stage.
- Ensures database state matches application code requirements.
Memory trick: Liquibase scripts build the database, version by version.
AWS X-Ray for Performance Monitoring
Flip cardAWS X-Ray is a service that helps developers analyze and debug distributed applications by providing end-to-end visibility into request flows.
- Traces requests across multiple services.
- Identifies performance bottlenecks and latency.
- Visualizes service maps and individual trace details.
- Supports various AWS services and custom applications.
Memory trick: X-Ray sees through the layers to find the problem.
AWS CodeArtifact
Flip cardA fully managed artifact repository service that allows organizations to securely store, publish, and share software packages used in their development process.
- Supports popular package managers (Maven, npm, PyPI, NuGet).
- Integrates with CodeBuild and CodePipeline.
- Centralizes package management for an organization.
- Can fetch packages from public repositories.
Memory trick: Artifacts are coded for easy storage and sharing.
EKS Log Management with Fluent Bit and CloudWatch
Flip cardThis pattern involves using Fluent Bit as a DaemonSet in EKS to collect container logs and forward them to Amazon CloudWatch Logs for centralized storage, analysis, and alerting.
- Fluent Bit is a lightweight and efficient log processor.
- CloudWatch Logs provides centralized log storage, querying, and alarming.
- Scalable and managed solution for EKS logging.
Memory trick: Fluent Bit gathers logs, CloudWatch stores the stream, Alarms cry out, Dashboards make it gleam.
DAST (Dynamic Application Security Testing)
Flip cardA security testing method that analyzes a running application to identify vulnerabilities by simulating attacks from the outside, without access to the source code.
- Tests the application in its deployed state.
- Effective for runtime vulnerabilities (e.g., XSS, SQL injection).
- Often integrated into CI/CD after deployment to a test environment.
- Black-box testing approach.
Memory trick: DAST attacks the running app to find dynamic flaws.
CodePipeline Automatic Rollback
Flip cardAWS CodePipeline can be configured to automatically roll back to the last successfully deployed application version if a subsequent deployment fails, ensuring application stability and quick recovery.
- Built-in feature for deployment stability.
- Redeploys the last successful revision.
- Minimizes manual intervention during failures.
Memory trick: Pipeline fails, don't you dread, automatic rollback, success instead.
Blue/Green Deployment (Lambda)
Flip cardA deployment strategy where a new version of a Lambda function (green) is deployed alongside the existing version (blue), and traffic is gradually or instantly shifted to the new version, enabling zero-downtime and easy rollback.
- Minimizes downtime during deployments.
- Allows for quick and safe rollbacks.
- Traffic routing handled by CodeDeploy or Lambda aliases.
Memory trick: Serverless deployments are like traffic lights: Blue is current, Green is new, shift safely.
GitOps
Flip cardAn operational framework that takes DevOps best practices used for application development (e.g., version control, collaboration, CI/CD) and applies them to infrastructure automation.
- Uses Git as the single source of truth for declarative infrastructure and application configuration.
- Automated reconciliation agents continuously synchronize cluster state with Git.
- Provides auditability, reproducibility, and faster, safer deployments.
Memory trick: GitOps is like a watchful octopus, always pulling your cluster into perfect sync with Git.
AWS Secrets Manager Integration
Flip cardA service that helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Stores secrets securely with encryption.
- Supports automatic rotation of secrets for various services.
- Secrets can be retrieved programmatically at runtime.
- Integrates with AWS services like Lambda and RDS.
Memory trick: Secrets Manager: The vault that spins keys for you.
Infrastructure as Code (IaC)
Flip cardManaging and provisioning computer data centers through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools.
- Automates infrastructure setup and management.
- Ensures consistency and reduces human error.
- Uses version control for infrastructure changes (e.g., Git).
Memory trick: IaC builds your pipelines like a chef follows a recipe, always consistent.
SSM Parameter Store
Flip cardA capability of AWS Systems Manager that provides secure, hierarchical storage for configuration data management and secret management.
- Stores data as plain text, secrets, or encrypted strings.
- Supports hierarchical naming for organization (e.g., /prod/app/db-url).
- Integrates with IAM for granular access control.
Memory trick: Parameter Store is like a secure vault for all your app's secret settings.
Event-Driven Architecture (S3 to Lambda)
Flip cardAn architecture pattern where components react to events, rather than polling for changes. In AWS, this often involves services like S3 event notifications, Lambda, and other services to create automated workflows.
- Decouples components, improving scalability and resilience.
- Reacts in real-time to changes, eliminating polling.
- Commonly uses S3 event notifications, SNS, SQS, EventBridge, and Lambda.
- Reduces operational overhead and costs by only running code when events occur.
Memory trick: Event-Driven: The moment it happens, Lambda reacts.
Parallel Test Execution
Flip cardRunning multiple test suites or individual tests concurrently rather than sequentially to reduce the total time required for test completion.
- Speeds up CI/CD pipeline execution.
- Crucial for rapid feedback in frequent commit environments.
- Can be achieved by distributing tests across multiple resources.
Memory trick: Parallel tests are like multiple lanes on a highway, getting everyone to the finish line faster.
Automated Dependency Updates
Flip cardThe process of automatically detecting and applying updates to software dependencies within a project, often triggering associated CI/CD pipelines.
- Ensures applications use the latest security patches and features.
- Reduces manual overhead and errors.
- Requires robust versioning and repository management.
Memory trick: CodeArtifact is the central library, and CodePipeline is the librarian, always updating your books.
CodeBuild Custom Actions in CodePipeline
Flip cardLeveraging AWS CodeBuild as an action type within CodePipeline stages to execute custom scripts, run proprietary tools, or perform complex tasks in a flexible, containerized environment.
- Allows custom Docker images for specific toolchains.
- Supports arbitrary shell commands via buildspec.yml.
- Integrates seamlessly into CodePipeline stages.
Memory trick: CodePipeline's custom needs? CodeBuild's your flexible toolbox.
AWS CI/CD Core Services
Flip cardThe primary AWS services (CodeCommit, CodeBuild, CodeDeploy, CodePipeline) used together to implement automated Continuous Integration and Continuous Delivery workflows.
- CodeCommit: Source control.
- CodeBuild: Build and test code.
- CodeDeploy: Automate software deployments.
- CodePipeline: Orchestrate the entire workflow.
Memory trick: Commit, Build, Deploy, orchestrated by Pipeline.
CodeDeploy Blue/Green Deployment with Canary
Flip cardA deployment strategy that maintains two identical environments (Blue and Green) and gradually shifts traffic to the new Green environment, often using a canary release pattern to test the new version with a small subset of users.
- Minimizes downtime during deployments.
- Provides a quick and easy rollback mechanism.
- Canary strategy reduces risk by slowly exposing new code to users.
- Ideal for applications running on EC2, ECS, or Lambda.
Memory trick: Blue Green Canary: Two colors, one small bird, zero downtime.
Static Application Security Testing (SAST)
Flip cardA white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Performed early in the SDLC (e.g., during development or build).
- Identifies vulnerabilities at the code level (e.g., SQL injection, XSS).
- Provides fast feedback to developers.
- Integrates well with CI/CD pipelines.
Memory trick: SAST: Scan the code, catch bugs before they run.
Event-Driven Architecture
Flip cardA software architecture paradigm that promotes the production, detection, consumption of, and reaction to events. It enables loosely coupled, scalable, and resilient systems.
- Components communicate via events, not direct calls.
- Decouples producers from consumers.
- Often uses message queues or event buses (e.g., SNS, SQS, EventBridge).
Memory trick: Events are like dominoes: one action triggers the next, all automatically.
AWS CodeBuild
Flip cardA fully managed continuous integration service that compiles source code, runs tests, and produces software packages.
- Eliminates the need to provision, manage, and scale build servers.
- Integrates seamlessly with AWS CodePipeline and CodeCommit.
- Supports various programming languages and build environments.
Memory trick: CodeBuild is the workhorse that builds, tests, and packages your code for release.
SSM State Manager
Flip cardAn AWS Systems Manager capability that allows you to define and maintain a desired state for your EC2 instances and on-premises servers. It ensures consistency across your infrastructure.
- Uses associations to apply desired configurations.
- Can execute Run Command, Automation, or custom scripts.
- Supports scheduling and compliance reporting.
- Helps prevent configuration drift.
Memory trick: To keep EC2s 'Stately', use 'Manager' to 'Associate' commands for 'Compliance'.
Kubernetes ReplicaSet
Flip cardA ReplicaSet is a Kubernetes controller that maintains a stable set of replica Pods running at any given time, ensuring the desired number of healthy Pods for a deployment.
- Ensures a specified number of Pod replicas.
- Replaces unhealthy or terminated Pods automatically.
- Often managed indirectly by Deployments.
Memory trick: ReplicaSet keeps your Pods healthy and ready, always.
SSM Patch Manager
Flip cardAWS Systems Manager Patch Manager automates the process of patching managed instances with security updates and other patches, allowing for defined patch baselines and controlled deployment.
- Automates OS and application patching.
- Supports Windows and Linux instances.
- Integrates with Maintenance Windows for scheduling.
- Allows defining patch baselines for compliance.
Memory trick: Patch Manager takes care of your instances' health, while State Manager keeps their core identity.
CodeDeploy Blue/Green for ASG
Flip cardAWS CodeDeploy provides native support for blue/green deployments with Amazon EC2 Auto Scaling groups, enabling zero-downtime updates and easy rollbacks by managing traffic shifting and instance replacement.
- Uses two sets of identical environments (blue/green).
- Traffic is shifted from old (blue) to new (green) environment.
- Minimizes downtime and provides quick rollback.
- Integrated with Auto Scaling Groups and Elastic Load Balancing.
Memory trick: CodeDeploy's DeploymentGroup is the traffic cop, directing users to the new green light.
Automated Remediation with AWS Config and Lambda
Flip cardThis pattern involves using AWS Config to continuously monitor resource compliance and triggering an AWS Lambda function to automatically correct non-compliant resources.
- AWS Config detects non-compliance.
- Lambda function performs the remediation.
- Ensures continuous adherence to security and operational standards.
Memory trick: Config checks the rules, Lambda fixes the tools.
SAST in CI/CD
Flip cardStatic Application Security Testing (SAST) integrated into a Continuous Integration/Continuous Delivery (CI/CD) pipeline involves analyzing application source code, bytecode, or binary code for security vulnerabilities without executing the code.
- Identifies vulnerabilities early in the development lifecycle.
- Performed on non-running code.
- Can be automated within build or test stages of a pipeline.
Memory trick: Build Secure, Deploy Secure: SAST finds flaws before they fly.
S3 Event-Driven Processing with Lambda
Flip cardThis pattern leverages Amazon S3 Event Notifications to trigger AWS Lambda functions in response to S3 object-level events, enabling serverless and scalable processing workflows.
- S3 events (e.g., object creation) trigger Lambda.
- Lambda performs custom processing (e.g., transcoding, indexing).
- Provides a highly scalable and cost-effective serverless architecture.
Memory trick: Upload to S3, Lambda gets the call to transform for you and me.
SSM Automation for Forensics
Flip cardAWS Systems Manager Automation can be used to automatically collect forensic data (e.g., memory, disk) from EC2 instances after a security incident, without manual access.
- Executes predefined runbooks on instances.
- Non-intrusive, no direct login required.
- Can collect various types of forensic artifacts.
Memory trick: SSM automates the evidence collection.
S3 Object Lock
Flip cardAn Amazon S3 feature that prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, ensuring data immutability.
- Supports Write Once, Read Many (WORM) model.
- Two modes: Governance and Compliance.
- Requires S3 Versioning to be enabled on the bucket.
Memory trick: Object Lock locks your data like a vault.
AWS Config with SSM Automation
Flip cardA powerful combination for continuous compliance and automated remediation: AWS Config detects non-compliant resources, and SSM Automation executes corrective actions.
- AWS Config continuously evaluates resource configurations.
- SSM Automation documents define remediation steps.
- Enables self-healing infrastructure and compliance enforcement.
Memory trick: Config checks the rules, SSM fixes the tools.
Predictive Scaling
Flip cardAn Auto Scaling policy that uses machine learning to forecast future traffic and scale capacity proactively, anticipating demand changes.
- Leverages historical data for forecasting.
- Launches instances before traffic spikes occur.
- Reduces latency and improves application availability during anticipated surges.
Memory trick: Predictive Powers Prevent Performance Plunges.
Multi-Region Active-Active (Multi-Site)
Flip cardA disaster recovery strategy where identical, fully operational resources are deployed in multiple AWS Regions and serve traffic concurrently. This provides the highest availability and lowest RTO/RPO.
- All regions actively serve traffic.
- Requires data synchronization across regions.
- Lowest RTO and RPO among DR strategies.
- Highest cost due to duplicate resources.
Memory trick: Always Be Ready, Just In Case, On Demand.
Amazon SQS FIFO Queue
Flip cardA type of Amazon SQS queue that guarantees message ordering and exactly-once processing.
- Messages are delivered in the exact order they are sent.
- Messages are processed exactly once.
- Supports message deduplication.
- Higher throughput limits than standard queues (with batching).
Memory trick: Order First, Only Once.