AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceEasy
A company is implementing a new CI/CD pipeline using AWS CodePipeline. The security team mandates that all deployments must be approved by a security engineer before proceeding to production. How can a DevOps engineer implement this requirement MOST effectively within CodePipeline?
- AUse AWS Step Functions to orchestrate a workflow that includes a human approval task.
- BIntegrate AWS Security Hub into CodePipeline to automatically block deployments lacking security approval.
- CConfigure an AWS Lambda function to send an approval request to the security team and pause the pipeline.
- DAdd a manual approval action in CodePipeline before the production deployment stage.
Show answer & explanationAnswer & explanation
Correct answer: D. Add a manual approval action in CodePipeline before the production deployment stage.
CodePipeline provides a built-in manual approval action specifically designed for scenarios where human intervention, such as a security team's sign-off, is required before a pipeline stage can proceed.
Why the other options are wrong
- A. Step Functions can orchestrate complex workflows, but a simple manual approval is a native CodePipeline feature.
- B. AWS Security Hub aggregates findings and does not directly provide a mechanism for manual approval within a CodePipeline workflow.
- C. While possible, this is over-engineering for a feature that CodePipeline natively supports.
CodePipeline Manual Approval
A CodePipeline action type that pauses the pipeline execution at a specific stage, requiring a designated user or group to manually approve or reject the continuation of the pipeline.
- Integrates directly into CodePipeline stages.
- Sends notifications (e.g., via SNS) for approval requests.
- Provides an approval URL in the AWS Console.
Memory trick: To 'gate' the 'pipeline', use the 'manual' 'switch'.