Question 1 · choose 1
A company has 40 development accounts in AWS Organizations. Builds in AWS CodeBuild must install npm packages only through a company-controlled repository so that the security team can block packages centrally later. A public package fetched once must be reused by every team instead of being fetched from npmjs.com again. Which design meets these requirements with the least operational overhead?
- ACreate an Amazon ECR pull through cache rule for the npm public registry in a shared account and grant the organization access through the private registry's permissions policy
- BCreate a CodeArtifact repository with an external connection to npmjs.com in each development account and point builds at it
- CCreate a shared CodeArtifact domain with one repository that connects externally to npmjs.com, team repositories that use it as an upstream, and a domain policy for the organization
- DMirror the npm packages the teams use into an S3 bucket every night with a scheduled CodeBuild job and point npm at the bucket
Show the answer and why
ACreate an Amazon ECR pull through cache rule for the npm public registry in a shared account and grant the organization access through the private registry's permissions policy
Incorrect
Pull through cache rules sync upstream container image registries into a private registry. npm is not a supported upstream.
BCreate a CodeArtifact repository with an external connection to npmjs.com in each development account and point builds at it
Incorrect
Each account would fetch and store the same public packages again. The intended pattern is one repository per domain with the external connection and other repositories using it as an upstream.
CCreate a shared CodeArtifact domain with one repository that connects externally to npmjs.com, team repositories that use it as an upstream, and a domain policy for the organization
Correct
Packages fetched once through the external connection are reused by all downstream repositories, and a domain policy can grant principals in other accounts access to the domain.
DMirror the npm packages the teams use into an S3 bucket every night with a scheduled CodeBuild job and point npm at the bucket
Incorrect
This is custom tooling to build and run, and packages first requested during the day are missing until the next run. CodeArtifact fetches a missing package on request.
CodeArtifact keeps packages from a public repository after the first fetch through an external connection. Putting that connection on one repository in a shared domain, with team repositories as downstreams and cross-account access through the domain policy, gives one control point for all accounts.
AWS documentation