AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A development team is implementing a microservice architecture on AWS. Each microservice needs to access a specific set of resources (e.g., an S3 bucket, a DynamoDB table). To adhere to the principle of least privilege, each microservice should only have access to its own required resources. The team uses AWS CloudFormation for deploying these microservices. How can they best manage and automate the creation of these fine-grained IAM roles for each microservice within their CloudFormation templates?

  1. AManually create IAM roles for each microservice in the AWS Management Console.
  2. BUse AWS Identity Center (successor to AWS SSO) to manage microservice permissions.
  3. CDefine an IAM Role resource directly within each microservice's CloudFormation template with specific policies.
  4. DCreate a single, broad IAM role for all microservices and attach it to their EC2 instances.
Show answer & explanation

Correct answer: C. Define an IAM Role resource directly within each microservice's CloudFormation template with specific policies.

Defining an IAM Role resource directly within each microservice's CloudFormation template allows for automating the creation of fine-grained, least-privilege roles. This adheres to IaC principles and ensures that each service gets exactly the permissions it needs, managed alongside its infrastructure.

Why the other options are wrong

  • A. Manually creating IAM roles is not an IaC approach and leads to inconsistencies and potential errors across deployments.
  • B. AWS Identity Center is for managing workforce access to AWS accounts and applications, not for defining runtime permissions for AWS services/resources themselves.
  • D. A single broad IAM role violates the principle of least privilege and increases the blast radius in case of compromise.

IAM Roles with IaC

Using Infrastructure as Code (IaC) tools like CloudFormation to define and manage AWS Identity and Access Management (IAM) roles, ensuring automated, consistent, and least-privilege permissions for resources.

  • Automates IAM role creation and updates.
  • Enforces least privilege by defining specific permissions in code.
  • Integrates role lifecycle with resource lifecycle.

Memory trick: Each microservice, its own IAM role, defined in code, keeping control.

More Configuration Management and Infrastructure as Code questions