A DevOps team is managing a critical production application deployed across multiple AWS accounts. They use AWS CloudFormation to manage their infrastructure. Recently, they observed configuration drift in an Amazon S3 bucket policy in a production account, where a manual change was made outside of CloudFormation, granting unintended public access. The team needs to detect such drifts automatically, prevent future manual changes, and revert any non-compliant configurations back to the desired state defined in their CloudFormation templates. Which combination of AWS services will MOST effectively address these requirements?
- ACloudFormation Change Sets to preview changes and AWS Organizations SCPs to restrict actions.
- BAWS Config for drift detection and CloudFormation Stack Policy to prevent manual changes.
- CAWS CloudTrail for auditing changes and custom Lambda functions for remediation.
- DAWS Systems Manager State Manager to enforce desired state and CloudWatch Alarms for notifications.
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Config for drift detection and CloudFormation Stack Policy to prevent manual changes.
AWS Config can continuously monitor resource configurations for drift from the desired state defined in CloudFormation templates and trigger alerts. CloudFormation Stack Policies allow you to protect specific resources or properties within a stack from being updated or deleted outside of CloudFormation, effectively preventing manual changes and enforcing the template's defined configuration. This combination directly addresses detection, prevention, and enforcement of desired state.
Why the other options are wrong
- A. Change Sets are for previewing *intended* CloudFormation changes. SCPs restrict actions at the account level but don't specifically prevent manual changes on a *resource within a stack* from deviating from its CloudFormation definition, nor do they detect drift.
- C. CloudTrail records API calls (good for auditing), but doesn't automatically detect drift or directly prevent manual changes. Custom Lambda for remediation adds complexity.
- D. SSM State Manager is primarily for configuration management on EC2 instances, not for detecting and preventing drift on arbitrary AWS resources managed by CloudFormation, nor does it prevent manual changes to stack resources.
Config & CloudFormation Stack Policies
AWS Config detects configuration drift, while CloudFormation Stack Policies prevent manual updates to specified stack resources, ensuring infrastructure remains aligned with IaC definitions.
- AWS Config monitors for configuration changes/drift.
- Stack Policies protect resources from manual modification.
- Enforces desired state defined by IaC.
Memory trick: Config warns you about the deviation, Stack Policy builds the fence.