Task 3.4: Deploy code by using AWS Continuous Integration and Continuous Delivery (CI/CD) services
Releasing through a pipeline: Lambda packaging, API Gateway stages and custom domains, CodePipeline, CodeBuild and CodeDeploy, updating templates, branches and tags, stage variables, and deployment strategies (all at once, rolling, blue/green, canary, linear) with their rollbacks.
Study it
Packaging: .zip archives, layers and container images
Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.
Question 1 · choose 1
AWS CodeDeploy performs in-place deployments of a web application to Amazon EC2 instances. After the new version has been installed and started, a script must call the application's /health endpoint on each instance and fail the deployment if the check does not pass. In which AppSpec lifecycle event hook should the developer run this script?
ABeforeInstall
BValidateService
CAfterInstall
DApplicationStop
Show the answer and why
ABeforeInstall
Incorrect
BeforeInstall runs preinstall tasks, such as decrypting files or backing up the current version, before the new revision is in place.
BValidateService
Correct
ValidateService is the last deployment lifecycle event and is used to verify that the deployment completed successfully.
CAfterInstall
Incorrect
AfterInstall is for tasks such as configuring the application or changing file permissions. It runs before ApplicationStart, so the new version is not running yet.
DApplicationStop
Incorrect
ApplicationStop runs even before the revision is downloaded, to stop the running application gracefully.
The scriptable hooks of an in-place EC2 deployment include, in order, ApplicationStop, BeforeInstall, AfterInstall, ApplicationStart and ValidateService; health checks belong in the last one.
An AWS Elastic Beanstalk environment runs six instances behind a load balancer. For the next application version, the environment must keep full capacity during the deployment, the instances that run the current version must not be modified, and if the new version fails its health checks, rolling back must only mean terminating the new instances. The environment URL must not change. Which deployment policy should the developer choose?
AAll at once
BRolling with additional batch
CBlue/green, with a CNAME swap to a cloned environment
DImmutable
Show the answer and why
AAll at once
Incorrect
All at once deploys to every instance at the same time, and all instances are out of service for a short time.
BRolling with additional batch
Incorrect
This keeps full capacity, but it updates the existing instances batch by batch, which can leave a partially completed rolling deployment when the new version fails.
CBlue/green, with a CNAME swap to a cloned environment
Incorrect
Blue/green deploys to a separate environment and then swaps the environment URLs, which the requirement rules out.
DImmutable
Correct
An immutable deployment launches a full set of new instances in a separate Auto Scaling group alongside the old ones. If it fails, rollback only terminates the new instances.
Immutable deployments never touch the running instances: new ones are added, checked, and either kept or terminated.
A V2 pipeline in AWS CodePipeline uses a GitHub repository as its source through a connection, and it starts on every push to the main branch. The team wants a separate production pipeline that starts only when a release tag such as v2.3.0 is pushed, and never for ordinary commits. What should the developer configure on the production pipeline?
AThe source action's BranchName set to a branch named release
BA manual approval action in front of the production deploy stage
CA push trigger with a Git tag filter that includes v*
DA pull request trigger filtered on the main branch
Show the answer and why
AThe source action's BranchName set to a branch named release
Incorrect
BranchName defines a single branch, so every ordinary commit pushed to that branch would still start the pipeline.
BA manual approval action in front of the production deploy stage
Incorrect
An approval action stops a running execution until someone approves or rejects it. The pipeline would still start for every commit.
CA push trigger with a Git tag filter that includes v*
Correct
Push triggers can be filtered on Git tags, so the pipeline starts only when a matching tag is pushed.
DA pull request trigger filtered on the main branch
Incorrect
Pull request triggers react to pull requests being opened, updated or closed, and they filter on branches and file paths, not tags.
V2 pipelines support trigger filters on branches, file paths and Git tags, which is how tags drive release pipelines.
An AWS SAM template defines an AWS Lambda function that already has AutoPublishAlias set to live. For each release, 10 percent of traffic should move to the new version first and the remaining 90 percent ten minutes later. If the function's error alarm goes off during the shift, traffic must return to the previous version automatically. Which TWO settings should the developer add to the function? (Choose TWO.)
AA DeploymentPreference with Type set to Linear10PercentEvery10Minutes
BA DeploymentPreference with Type set to Canary10Percent10Minutes
CDeploymentPreference Alarms that list the function's error alarm
DA ProvisionedConcurrencyConfig for the live alias
ERemoval of AutoPublishAlias so that traffic goes straight to $LATEST
Show the answer and why
AA DeploymentPreference with Type set to Linear10PercentEvery10Minutes
Incorrect
A linear configuration shifts 10 percent every 10 minutes until all traffic has moved, which takes far longer than one ten-minute step.
BA DeploymentPreference with Type set to Canary10Percent10Minutes
Correct
This canary configuration shifts 10 percent of traffic first and the remaining 90 percent ten minutes later.
CDeploymentPreference Alarms that list the function's error alarm
Correct
CodeDeploy watches the listed CloudWatch alarms during the deployment and rolls back automatically if one of them is triggered.
DA ProvisionedConcurrencyConfig for the live alias
Incorrect
Provisioned concurrency keeps execution environments initialized. It does not control how traffic moves between versions.
ERemoval of AutoPublishAlias so that traffic goes straight to $LATEST
Incorrect
AWS SAM gradual deployments shift traffic on the alias that AutoPublishAlias creates and points at each new version, so removing it works against the requirement.
In AWS SAM, AutoPublishAlias plus DeploymentPreference (type, alarms, optional hooks) hands traffic shifting and rollback to CodeDeploy.
A developer changes the TableName property of an AWS::DynamoDB::Table in an AWS CloudFormation template. A change set shows that the update will replace the table. The team wants to go ahead with the update, but the existing table and its data must be kept in the account instead of being deleted when CloudFormation replaces it. What should the developer add to the table resource before executing the change set?
ADeletionPolicy set to Retain
BTermination protection turned on for the stack
CA stack policy that denies Update:Replace on the table
DUpdateReplacePolicy set to Retain
Show the answer and why
ADeletionPolicy set to Retain
Incorrect
DeletionPolicy applies when a resource is deleted from the stack, for example when it is removed from the template. It does not apply to a resource that is replaced during an update.
BTermination protection turned on for the stack
Incorrect
Termination protection only blocks deleting the stack. It does not keep a resource that an update replaces.
CA stack policy that denies Update:Replace on the table
Incorrect
A stack policy prevents the replacement from happening at all, so the update the team wants could not go ahead.
DUpdateReplacePolicy set to Retain
Correct
UpdateReplacePolicy keeps (or, in some cases, backs up) the existing physical resource when an update replaces it, so the old table stays in the account.
DeletionPolicy covers deletion from the stack; UpdateReplacePolicy covers replacement during an update. Changing TableName requires replacement.
A front-end team builds a single-page web application in a Git repository. It wants every push to the main branch to build and publish the site to a global CDN automatically, with a separate environment for a staging branch, without building its own pipeline. Which service should the developer use?
AAWS Amplify Hosting connected to the repository and its branches
BAmazon S3 static website hosting with manual uploads
CAWS Elastic Beanstalk with a single-instance environment
DAn Amazon EC2 instance running a web server, updated over SSH after each push
Show the answer and why
AAWS Amplify Hosting connected to the repository and its branches
Correct
Amplify Hosting provides a Git-based workflow with continuous deployment to a global CDN, and branches can map to environments.
BAmazon S3 static website hosting with manual uploads
Incorrect
Manual uploads are not continuous deployment, and a website endpoint alone is not a global CDN.
CAWS Elastic Beanstalk with a single-instance environment
Incorrect
Beanstalk runs application servers; it is not a Git-based CDN hosting workflow for static front ends.
DAn Amazon EC2 instance running a web server, updated over SSH after each push
Incorrect
This needs manual server management and gives no automatic deployment on push.
Amplify Hosting gives front-end teams Git-based continuous deployment with per-branch environments.
A team releases a web application on AWS Elastic Beanstalk. For the next version, it wants a canary release: a small share of client traffic should go to new instances running the new version for a period of time, with the rest on the current version, before the release completes. Which deployment policy fits?
ARolling
BAll at once
CTraffic splitting
DRolling with additional batch
Show the answer and why
ARolling
Incorrect
Rolling updates existing instances batch by batch; it does not send a set share of traffic to new instances for a test period.
BAll at once
Incorrect
All instances switch at the same time, with no canary period.
CTraffic splitting
Correct
Traffic splitting sends a percentage of client traffic to new instances for an evaluation period before completing the deployment.
DRolling with additional batch
Incorrect
This keeps full capacity during a rolling update but does not split traffic by percentage.
Elastic Beanstalk traffic splitting provides canary testing as part of a deployment.
Developers push to a repository several times an hour. In the team's AWS CodePipeline V2 pipeline, newer executions overtake older ones, so some commits are never deployed on their own, which breaks the team's audit process. Every commit must go through the pipeline, one execution at a time and in order. What should the developer configure?
AThe SUPERSEDED execution mode
BThe PARALLEL execution mode
CA manual approval action at the start of each stage
DThe QUEUED execution mode
Show the answer and why
AThe SUPERSEDED execution mode
Incorrect
In SUPERSEDED mode, the default, a more recent execution can overtake an older one, which is the current problem.
BThe PARALLEL execution mode
Incorrect
PARALLEL runs executions at the same time and independently, not one at a time in order.
CA manual approval action at the start of each stage
Incorrect
Approvals pause executions for people; they do not change how executions are ordered.
DThe QUEUED execution mode
Correct
In QUEUED mode, executions are processed one by one in the order they are queued; it requires a V2 pipeline.
CodePipeline execution modes control whether executions are superseded, queued or run in parallel.
A team defines its application with the AWS CDK and wants a delivery pipeline that is also defined in the CDK app. When developers add a new stage or stack to the app, the pipeline should reconfigure itself to deploy it, without anyone editing the pipeline by hand. What should the developer use?
AA CodePipeline pipeline created by hand in the console
BCDK Pipelines
CA cron job that runs cdk deploy on a build server every hour
DCloudFormation drift detection on the application stacks
Show the answer and why
AA CodePipeline pipeline created by hand in the console
Incorrect
A hand-built pipeline must be edited by hand when new stages or stacks are added.
BCDK Pipelines
Correct
CDK Pipelines are self-updating; when stages or stacks are added, the pipeline reconfigures itself to deploy them.
CA cron job that runs cdk deploy on a build server every hour
Incorrect
A scheduled job deploys on a timer rather than on changes, and it lacks pipeline stages.
DCloudFormation drift detection on the application stacks
Incorrect
Drift detection finds manual changes to deployed resources; it does not deploy anything.
CDK Pipelines keep the pipeline definition in code and update the pipeline as the app grows.
A pipeline in AWS CodePipeline in account A must deploy, through AWS CodeDeploy, to EC2 instances in account B. The pipeline's artifact bucket uses the pipeline's default encryption key. The deploy action in account B cannot read the artifacts. What should the developer change about the artifact encryption?
ATurn off encryption for the artifact bucket
BCopy the artifacts into a bucket in account B with a script after each build
CUse a customer managed KMS key that account B may use
DTurn on automatic rotation of the default key
Show the answer and why
ATurn off encryption for the artifact bucket
Incorrect
Removing encryption weakens security and is not the documented way to share artifacts across accounts.
BCopy the artifacts into a bucket in account B with a script after each build
Incorrect
A copy step adds work outside the pipeline; the documented approach shares the artifacts through a key both accounts can use.
CUse a customer managed KMS key that account B may use
Correct
Cross-account pipelines use a customer managed KMS key in place of the default key, with permissions for the other account to use it.
DTurn on automatic rotation of the default key
Incorrect
Rotation does not change who may use the key.
For cross-account deployments, encrypt pipeline artifacts with a customer managed key that the target account is allowed to use.