AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeEasy

A DevOps team is using AWS CloudFormation to manage their infrastructure. They have a core network stack that defines VPCs, subnets, and route tables, which is deployed once per region. Multiple application stacks in the same region need to reference specific subnet IDs and security group IDs from this core network stack. The team wants to ensure that these references are dynamically linked and updated if the core network stack changes, without hardcoding values or manual input. Which CloudFormation feature should they use?

  1. AEmploy CloudFormation Mappings to define a lookup table for resource IDs.
  2. BUse CloudFormation Parameters in the application stacks to manually input the IDs.
  3. CCreate a custom Lambda-backed resource to fetch the required IDs from the network stack at deployment time.
  4. DUtilize CloudFormation Outputs from the network stack and Fn::ImportValue in the application stacks.
Show answer & explanation

Correct answer: D. Utilize CloudFormation Outputs from the network stack and Fn::ImportValue in the application stacks.

CloudFormation Outputs allow you to export values from one stack (the network stack) that can then be imported by other stacks (the application stacks) using the `Fn::ImportValue` intrinsic function. This creates a dynamic link, ensuring that if the exported values in the network stack change, the importing application stacks can be updated automatically or referenced correctly, without manual intervention.

Why the other options are wrong

  • A. Mappings are for static key-value lookups within a single template, not for dynamic cross-stack references of deployed resources.
  • B. Parameters require manual input for each deployment and would not dynamically update if the network stack changed, leading to potential inconsistencies.
  • C. While a custom resource could achieve this, it adds unnecessary complexity and operational overhead, as CloudFormation provides a native, simpler solution for this exact use case.

CloudFormation Outputs & Fn::ImportValue

CloudFormation Outputs allow values from a stack to be exposed, and `Fn::ImportValue` allows other stacks in the same region to reference these exported values.

  • Enables cross-stack referencing.
  • Creates dynamic links between stacks.
  • Facilitates modular and reusable infrastructure.

Memory trick: Export from one, import to another, like passing a baton in a relay race.

More Configuration Management and Infrastructure as Code questions