AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A developer is configuring an AWS CodeBuild project that needs to fetch sensitive configuration parameters, such as API keys and database credentials, during the build process. These parameters are stored securely in AWS Systems Manager Parameter Store. How should the developer configure CodeBuild to access these parameters securely?

  1. AStore the parameters in an S3 bucket and use the `aws s3 cp` command in `buildspec.yml` to retrieve them.
  2. BReference the Parameter Store parameters in the `buildspec.yml` file using the `parameter-store` syntax, ensuring the CodeBuild service role has `ssm:GetParameters` permissions.
  3. CPass the parameters as environment variables directly in the CodeBuild project settings.
  4. DHardcode the parameters directly into the `buildspec.yml` file.
Show answer & explanation

Correct answer: B. Reference the Parameter Store parameters in the `buildspec.yml` file using the `parameter-store` syntax, ensuring the CodeBuild service role has `ssm:GetParameters` permissions.

AWS CodeBuild natively integrates with AWS Systems Manager Parameter Store. By referencing parameters using the `parameter-store` syntax in the `buildspec.yml` file, CodeBuild can securely fetch these values at build time. It's crucial that the CodeBuild service role has `ssm:GetParameters` permissions to access the specified parameters.

Why the other options are wrong

  • A. Storing sensitive parameters in an S3 bucket is less secure than Parameter Store, and requires managing S3 bucket policies and potentially encryption keys, adding complexity.
  • C. While CodeBuild supports environment variables, passing sensitive data directly can expose it in logs or configurations. Parameter Store integration is more secure.
  • D. Hardcoding sensitive information is a severe security vulnerability and should never be done.

CodeBuild Parameter Store Integration

AWS CodeBuild's native capability to securely retrieve sensitive configuration parameters from AWS Systems Manager Parameter Store during the build process, preventing hardcoding or exposure.

  • Uses `parameter-store` syntax in `buildspec.yml`.
  • Requires `ssm:GetParameters` permission.
  • Securely injects parameters at build time.

Memory trick: SECURE-BUILD: Safely Execute Code Under Reliable Environment.

More Deployment questions