AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A developer is configuring an AWS CodePipeline to deploy a web application to Amazon S3 and Amazon CloudFront. After the new version of the application is uploaded to S3, the CloudFront distribution needs to be invalidated to ensure users receive the latest content. Which action type should be used in CodePipeline to automate this CloudFront invalidation?

  1. AAmazon S3 deploy action
  2. BAWS CloudFormation deploy action
  3. CAWS Lambda invoke action
  4. DAWS CodeBuild action
Show answer & explanation

Correct answer: D. AWS CodeBuild action

AWS CodeBuild can be used to run custom commands, including AWS CLI commands. A CodeBuild action in CodePipeline can execute the `aws cloudfront create-invalidation` command to invalidate the CloudFront distribution after new content is deployed to S3.

Why the other options are wrong

  • A. An S3 deploy action only uploads files; it does not handle CloudFront invalidation.
  • B. CloudFormation deploys infrastructure, not application content or specific operational tasks like invalidating a distribution.
  • C. While a Lambda function could be invoked to do this, CodeBuild provides a more direct and often simpler way to run CLI commands within CodePipeline.

CodePipeline CloudFront Invalidation

To ensure users receive the latest content after deploying to S3 via CodePipeline, a CloudFront distribution's cache must be invalidated. This is typically automated using an AWS CodeBuild action within CodePipeline to execute the `aws cloudfront create-invalidation` CLI command.

  • Required for fresh content delivery.
  • Automated using CodeBuild action.
  • Executes `aws cloudfront create-invalidation`.
  • Ensures users see changes quickly.

Memory trick: CodeBuild is the CLI master, making CloudFront cache faster.

More Deployment questions