Question 1 · choose 1
An application is deployed to an Auto Scaling group with AWS CodeDeploy in-place deployments. Revisions are stored in an S3 bucket that uses SSE-KMS with a customer managed key. After the group moved to a new launch template with a new IAM instance profile, deployments to the new instances fail. The CodeDeploy agent's log on those instances shows access denied errors while it downloads the revision. Which change fixes the problem?
- AAdd s3:GetObject on the revision bucket to the IAM service role that CodeDeploy uses for the deployment group
- BAllow the new instance profile's role to read objects in the revision bucket and to decrypt with the customer managed KMS key
- CChange the deployment configuration from CodeDeployDefault.OneAtATime to CodeDeployDefault.AllAtOnce for the deployment group
- DReinstall the CodeDeploy agent through the user data of the new launch template and restart the agent service on each instance
Show the answer and why
AAdd s3:GetObject on the revision bucket to the IAM service role that CodeDeploy uses for the deployment group
Incorrect
The revision is downloaded by the agent on the instance, with the credentials of the instance profile, not by the CodeDeploy service role.
BAllow the new instance profile's role to read objects in the revision bucket and to decrypt with the customer managed KMS key
Correct
The instance profile gives the agent its permission to download the revision from Amazon S3, and an encrypted revision also needs access to the KMS key that encrypted it.
CChange the deployment configuration from CodeDeployDefault.OneAtATime to CodeDeployDefault.AllAtOnce for the deployment group
Incorrect
A deployment configuration sets how many instances are updated at a time. It does not change what the instances may read.
DReinstall the CodeDeploy agent through the user data of the new launch template and restart the agent service on each instance
Incorrect
The agent is already running, because it is writing the access denied errors. Its credentials come from the instance profile.
On EC2, the CodeDeploy agent uses the instance profile to talk to CodeDeploy and to fetch the revision. A new instance profile must carry the same S3 access and, for SSE-KMS objects, permission to use the KMS key.
AWS documentation
- Troubleshoot EC2/On-Premises deployment issues (opens in a new tab)
- Step 4: Create an IAM instance profile for your Amazon EC2 instances (opens in a new tab)
- Create a pipeline in CodePipeline that uses resources from another AWS account (opens in a new tab)
- Working with deployment configurations in CodeDeploy (opens in a new tab)