AWS Certified DevOps Engineer – ProfessionalSDLC AutomationHard
A DevOps team is setting up a CI/CD pipeline for an application that uses multiple environment-specific configuration files (e.g., `appsettings.dev.json`, `appsettings.prod.json`). They want to ensure that the correct configuration is automatically injected into the application artifact during the build process, based on the target deployment environment, without hardcoding sensitive information. How can they achieve this securely and efficiently within an AWS CodeBuild project?
- AUse AWS Systems Manager Parameter Store to store configuration values and retrieve them in the buildspec.
- BPass environment variables to CodeBuild for each configuration value.
- CStore all configuration files in the source repository and use a buildspec command to copy the relevant file.
- DEncrypt environment-specific files with KMS and decrypt them in the buildspec.
Show answer & explanationAnswer & explanation
Correct answer: A. Use AWS Systems Manager Parameter Store to store configuration values and retrieve them in the buildspec.
AWS Systems Manager Parameter Store provides secure, hierarchical storage for configuration data and secrets. CodeBuild can be granted permissions to retrieve these parameters based on the target environment, allowing for dynamic and secure injection of configuration values without exposing them in source control or build logs.
Why the other options are wrong
- B. Passing all configuration values as environment variables can become unwieldy and less secure for a large number of parameters, especially when some are sensitive. Parameter Store offers better organization and security.
- C. Storing all configuration files, especially production ones, directly in source control is insecure and not scalable for managing sensitive data.
- D. While possible, decrypting entire files with KMS adds complexity, requires managing those files securely, and is less granular for individual configuration values compared to Parameter Store.
SSM Parameter Store
A capability of AWS Systems Manager that provides secure, hierarchical storage for configuration data management and secret management.
- Stores data as plain text, secrets, or encrypted strings.
- Supports hierarchical naming for organization (e.g., /prod/app/db-url).
- Integrates with IAM for granular access control.
Memory trick: Parameter Store is like a secure vault for all your app's secret settings.