A global e-commerce company uses AWS CloudFormation StackSets to deploy foundational infrastructure (e.g., VPC, IAM roles) across hundreds of AWS accounts and multiple AWS regions. The security team has identified a critical vulnerability in a default setting of an S3 bucket policy defined in one of these foundational StackSet templates. They need to update this specific S3 bucket policy across all deployed StackSet instances immediately without affecting other resources in the stack and with minimal disruption. What is the MOST efficient way to achieve this?
- AUse a custom AWS Lambda function triggered by a schedule to iterate through all accounts and update the S3 bucket policies directly.
- BUpdate the StackSet template with the new S3 bucket policy and perform a standard `UpdateStackSet` operation.
- CCreate a new StackSet with the corrected S3 bucket policy and delete the old StackSet after successful deployment.
- DManually log into each affected AWS account and region to update the S3 bucket policy via the AWS Management Console.
Show answer & explanationAnswer & explanation
Correct answer: B. Update the StackSet template with the new S3 bucket policy and perform a standard `UpdateStackSet` operation.
The most efficient way to update a specific resource within an existing StackSet across all deployed instances is to modify the original StackSet template with the corrected S3 bucket policy and then perform a standard `UpdateStackSet` operation. StackSets will intelligently identify the change, apply it to all existing stack instances in target accounts and regions, and handle the update process, including potential rollbacks if issues occur.
Why the other options are wrong
- A. A custom Lambda function adds unnecessary complexity and requires maintaining custom code for a task that StackSets can handle natively and more robustly.
- C. Creating a new StackSet and deleting the old one is a disruptive and less efficient approach, potentially leading to downtime or resource identifier changes, which is not suitable for a critical, non-disruptive update.
- D. Manual updates are not scalable, prone to human error, and do not provide an auditable IaC trail, making them unsuitable for hundreds of accounts.
CloudFormation StackSets Update
CloudFormation StackSets allow you to update the underlying template, which then propagates changes to all deployed stack instances across specified AWS accounts and regions.
- Propagates changes to many accounts/regions.
- Manages updates to existing stack instances.
- Ensures consistency across distributed infrastructure.
Memory trick: StackSets update is like sending out a new memo; everyone gets the latest information from a single source.