AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationHard

A company is using AWS CloudFormation to manage its infrastructure. They have several nested stacks representing different components of their application. A recent update to a common network component stack (a nested stack) caused issues in multiple dependent application stacks. The team needs a strategy to prevent such widespread failures from future updates to shared nested stacks. Which CloudFormation feature would be most effective?

  1. AUsing change sets to preview changes before executing them on the main stack.
  2. BCreating custom resources to validate nested stack outputs before proceeding.
  3. CImplementing stack policies to prevent unintended updates to critical resources.
  4. DEmploying drift detection to identify configuration changes after deployment.
Show answer & explanation

Correct answer: C. Implementing stack policies to prevent unintended updates to critical resources.

Stack policies are designed to protect critical resources from unintended updates or deletions during stack operations. By applying a stack policy to the shared network component nested stack, specific resources within it can be protected, or specific update actions can be prevented, thereby reducing the risk of widespread failures in dependent application stacks.

Why the other options are wrong

  • A. Change sets help visualize changes but require manual review and approval, and don't programmatically prevent deployment if issues are missed.
  • B. Custom resources can add validation logic, but they are more complex to implement for this specific use case and might not prevent the update itself, only react to it.
  • D. Drift detection identifies changes made outside CloudFormation but doesn't prevent CloudFormation from making problematic updates in the first place.

AWS CloudFormation Stack Policies

A JSON policy document that defines which stack resources can be updated or deleted during a stack update operation, preventing unintended changes to critical resources.

  • Protects specific resources from update/deletion.
  • Applied to a stack, not individual resources.
  • Used to enforce governance and prevent accidental changes.

Memory trick: Stack policies guard, preventing update hazards.

More Deployment, Provisioning, and Automation questions