AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationMedium

A company is using AWS CloudFormation to manage its infrastructure. They have a requirement to ensure that specific sensitive resources, like Amazon RDS databases, are not accidentally deleted or replaced during stack updates. How can a SysOps Administrator prevent unintended deletion or replacement of these critical resources?

  1. AImplement an AWS CloudFormation Stack Policy that denies `Update:Delete` and `Update:Replace` actions for the RDS resource.
  2. BEnable termination protection on the RDS instance directly after it is provisioned by CloudFormation.
  3. CUse AWS Identity and Access Management (IAM) policies to restrict users from performing `rds:DeleteDBInstance` actions.
  4. DSet the DeletionPolicy attribute to `Retain` on the CloudFormation template for the RDS database resource.
Show answer & explanation

Correct answer: A. Implement an AWS CloudFormation Stack Policy that denies `Update:Delete` and `Update:Replace` actions for the RDS resource.

AWS CloudFormation Stack Policies are designed specifically to prevent unintended updates to stack resources. By applying a stack policy that denies 'Update:Delete' and 'Update:Replace' actions for the RDS resource, you ensure that CloudFormation itself cannot perform these operations.

Why the other options are wrong

  • B. Enabling termination protection on the RDS instance directly is a post-provisioning step and does not prevent CloudFormation from attempting to delete or replace the resource during a stack update if the template specifies it.
  • C. IAM policies control user permissions, not CloudFormation's behavior during stack updates. A user with permissions to update a stack could still trigger deletion if not prevented by a stack policy.
  • D. While `DeletionPolicy: Retain` prevents deletion, it doesn't prevent replacement, and it's not the primary mechanism for preventing updates to a resource already managed by a stack policy.

CloudFormation Stack Policies

CloudFormation Stack Policies are JSON documents that define which update actions (e.g., Delete, Replace) are allowed on specific resources within a CloudFormation stack, preventing unintended modifications.

  • Applied to an entire stack, not individual resources.
  • Overrides IAM permissions for stack updates.
  • Useful for protecting critical resources from accidental changes.

Memory trick: CloudFormation Stack Policies act like a guardian shield over your precious resources.

More Deployment, Provisioning, and Automation questions