AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationMedium
A company is using AWS CloudFormation to manage its infrastructure. They have a requirement to ensure that specific sensitive resources, like Amazon RDS databases, are not accidentally deleted or replaced during stack updates. How can a SysOps Administrator prevent unintended deletion or replacement of these critical resources?
- AImplement an AWS CloudFormation Stack Policy that denies `Update:Delete` and `Update:Replace` actions for the RDS resource.
- BEnable termination protection on the RDS instance directly after it is provisioned by CloudFormation.
- CUse AWS Identity and Access Management (IAM) policies to restrict users from performing `rds:DeleteDBInstance` actions.
- DSet the DeletionPolicy attribute to `Retain` on the CloudFormation template for the RDS database resource.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement an AWS CloudFormation Stack Policy that denies `Update:Delete` and `Update:Replace` actions for the RDS resource.
AWS CloudFormation Stack Policies are designed specifically to prevent unintended updates to stack resources. By applying a stack policy that denies 'Update:Delete' and 'Update:Replace' actions for the RDS resource, you ensure that CloudFormation itself cannot perform these operations.
Why the other options are wrong
- B. Enabling termination protection on the RDS instance directly is a post-provisioning step and does not prevent CloudFormation from attempting to delete or replace the resource during a stack update if the template specifies it.
- C. IAM policies control user permissions, not CloudFormation's behavior during stack updates. A user with permissions to update a stack could still trigger deletion if not prevented by a stack policy.
- D. While `DeletionPolicy: Retain` prevents deletion, it doesn't prevent replacement, and it's not the primary mechanism for preventing updates to a resource already managed by a stack policy.
CloudFormation Stack Policies
CloudFormation Stack Policies are JSON documents that define which update actions (e.g., Delete, Replace) are allowed on specific resources within a CloudFormation stack, preventing unintended modifications.
- Applied to an entire stack, not individual resources.
- Overrides IAM permissions for stack updates.
- Useful for protecting critical resources from accidental changes.
Memory trick: CloudFormation Stack Policies act like a guardian shield over your precious resources.