AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationMedium
A development team is using AWS CodePipeline to automate their CI/CD process. They need to integrate a custom security scanning tool that runs as a Docker container into the build stage. This tool requires specific environment variables and access to the source code artifact. How can this be efficiently achieved within CodePipeline?
- ADeploy the Docker container to an EC2 instance, and use a CodePipeline custom action to invoke a script on that instance.
- BAdd a manual approval step in CodePipeline and execute the security scanning tool locally before approving the pipeline.
- CStore the Docker container image in Amazon ECR and use an AWS Lambda function to pull and run it during the build stage.
- DUse an AWS CodeBuild project as a build stage action, specifying the Docker image and environment variables in the buildspec.yml.
Show answer & explanationAnswer & explanation
Correct answer: D. Use an AWS CodeBuild project as a build stage action, specifying the Docker image and environment variables in the buildspec.yml.
AWS CodeBuild is designed to run arbitrary commands, including Docker containers, as part of a build or test stage in CodePipeline. By specifying the Docker image and environment variables in the buildspec.yml, the custom security scanning tool can be seamlessly integrated and executed within the build environment, accessing artifacts and utilizing CodeBuild's compute resources.
Why the other options are wrong
- A. Deploying to a separate EC2 instance for every scan is inefficient, adds management overhead, and complicates artifact transfer and environment variable management.
- B. A manual approval step breaks automation and is not a scalable or efficient way to integrate an automated security scanning tool into the CI/CD pipeline.
- C. While ECR stores the image, a Lambda function is not ideal for long-running or resource-intensive build tasks like security scanning, and would require more complex orchestration.
AWS CodeBuild
A fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy.
- Integrates with CodePipeline.
- Supports custom build environments, including Docker images.
- Scales automatically and pays for compute time used.
Memory trick: CodeBuild runs Docker with its buildspec's power.