AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A developer is configuring an AWS CodePipeline to deploy a static website to an Amazon S3 bucket. After the new website files are deployed to S3, users are still seeing the old content due to caching by Amazon CloudFront. The developer needs to automate the process of clearing the CloudFront cache as part of the pipeline. Which CodePipeline action type should be used for this purpose?

  1. AA custom action type configured to call the CloudFront API directly.
  2. BA Lambda invoke action that triggers a function to invalidate CloudFront cache.
  3. CA CodeBuild action configured to run AWS CLI commands for CloudFront invalidation.
  4. DAn S3 deployment action with a built-in cache invalidation option.
Show answer & explanation

Correct answer: C. A CodeBuild action configured to run AWS CLI commands for CloudFront invalidation.

A CodeBuild action in CodePipeline is the most common and recommended way to automate CloudFront cache invalidation. You can configure a buildspec.yml file within CodeBuild to execute AWS CLI commands (e.g., `aws cloudfront create-invalidation`) to invalidate the CloudFront distribution associated with the S3 bucket.

Why the other options are wrong

  • A. A custom action type is overkill for this common task. CodeBuild provides a direct and simpler integration for running CLI commands.
  • B. While a Lambda function could technically invalidate the cache, using CodeBuild is generally simpler for this specific task within CodePipeline, as it avoids managing a separate Lambda function and its permissions.
  • D. S3 deployment actions in CodePipeline do not have a built-in option for CloudFront cache invalidation. This needs to be a separate step.

CloudFront Invalidation in CodePipeline

Automating the process of clearing the CloudFront cache after a new static website deployment in CodePipeline, typically achieved by running AWS CLI commands within a CodeBuild action.

  • Ensures users see new content immediately.
  • Commonly implemented with CodeBuild.
  • Uses `aws cloudfront create-invalidation`.

Memory trick: CODE-PIPE-CF: Clear Old Data, Every Time.

More Deployment questions