AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium

A financial institution requires strict governance and auditability for all changes to their AWS infrastructure. They are implementing Infrastructure as Code (IaC) using AWS CloudFormation. How can they ensure that all CloudFormation stack updates are reviewed and approved by a change management board before execution?

  1. AImplement AWS Organizations Service Control Policies (SCPs) to block direct CloudFormation updates.
  2. BIntegrate manual approval steps into an AWS CodePipeline that deploys CloudFormation templates.
  3. CConfigure AWS Config rules to flag unapproved CloudFormation changes.
  4. DUse AWS Service Catalog to restrict CloudFormation template deployments.
Show answer & explanation

Correct answer: B. Integrate manual approval steps into an AWS CodePipeline that deploys CloudFormation templates.

Integrating manual approval steps directly into an AWS CodePipeline is the most effective way to enforce a review and approval workflow for CloudFormation stack updates, ensuring human oversight before deployment.

Why the other options are wrong

  • A. SCPs can prevent certain actions, but they are too broad for enforcing a 'review and approve' workflow for specific CloudFormation changes within a pipeline; they would typically block all CloudFormation updates or specific resource types.
  • C. AWS Config rules can detect changes but cannot prevent them or enforce an approval workflow before they happen.
  • D. AWS Service Catalog helps standardize and provision approved resources but doesn't inherently provide a pre-deployment approval workflow for CloudFormation stack updates from a CI/CD perspective.

CodePipeline Manual Approval

A feature in AWS CodePipeline that allows the pipeline execution to be paused at a specific stage, requiring a human user to manually approve or reject the transition to the next stage.

  • Ensures human review and approval for critical deployments.
  • Can be integrated at any stage of the pipeline.
  • Provides an audit trail of approvals/rejections.

Memory trick: For IaC, if it's not CodePipeline-approved, it's not deployed.

More SDLC Automation questions