AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A development team uses AWS CodeBuild for continuous integration. They need to ensure that specific sensitive environment variables, such as API keys, are available during the build process but are not exposed in plain text in the build logs or source code. How should these variables be securely managed and injected into the CodeBuild environment?

  1. ADefine them directly in the buildspec.yml file as plaintext environment variables.
  2. BStore them in AWS Systems Manager Parameter Store and reference them in the buildspec.yml.
  3. CHardcode them as constants in the application's source code.
  4. DPass them as command-line arguments to the CodeBuild project.
Show answer & explanation

Correct answer: B. Store them in AWS Systems Manager Parameter Store and reference them in the buildspec.yml.

AWS Systems Manager Parameter Store allows storing sensitive data securely. CodeBuild can then retrieve these parameters at build time by referencing them in the buildspec.yml file, ensuring they are not exposed in logs or source code.

Why the other options are wrong

  • A. Plaintext in buildspec.yml is not secure and will be visible in build logs.
  • C. Hardcoding in source code is a major security vulnerability and makes updates difficult.
  • D. Command-line arguments can be exposed in execution details or history, making them unsuitable for sensitive data.

CodeBuild Parameter Store Integration

AWS CodeBuild can securely access and inject sensitive environment variables stored in AWS Systems Manager Parameter Store or AWS Secrets Manager into the build environment. This prevents exposure of secrets in build logs or source code.

  • Securely stores secrets (API keys, tokens).
  • CodeBuild retrieves at build time.
  • Prevents plaintext exposure in logs/source.
  • Uses `parameter-store` type in buildspec.yml.

Memory trick: Parameter Store is CodeBuild's secret keeper, keeping keys safe and deep.

More Deployment questions