Question 1 · choose 1
A stack update failed, and AWS CloudFormation started to roll it back. The rollback then failed too, and the stack is now in UPDATE_ROLLBACK_FAILED. The events show that an engineer had deleted a Lambda permission outside of CloudFormation, so CloudFormation cannot restore it. The team must get the stack back to a state where it can be updated, without deleting the stack or its other resources. What should the DevOps engineer do?
- ARun an update on the stack with a corrected template that recreates the deleted Lambda permission resource
- BContinue rolling back the update, skipping the logical ID of the Lambda permission that cannot be restored
- CDelete the stack with the option to retain all resources, and create a new stack that imports them
- DRun drift detection on the stack and accept the detected differences so that the stack becomes updatable
Show the answer and why
ARun an update on the stack with a corrected template that recreates the deleted Lambda permission resource
Incorrect
A stack in UPDATE_ROLLBACK_FAILED cannot be updated. It must first be rolled back to a working state.
BContinue rolling back the update, skipping the logical ID of the Lambda permission that cannot be restored
Correct
Continuing the rollback returns the stack to UPDATE_ROLLBACK_COMPLETE, and resources that cannot roll back can be skipped by logical ID.
CDelete the stack with the option to retain all resources, and create a new stack that imports them
Incorrect
This throws away the stack the team wants to keep and turns a rollback fix into a migration.
DRun drift detection on the stack and accept the detected differences so that the stack becomes updatable
Incorrect
Drift detection reports differences between the template and the resources; it does not change the stack's state.
UPDATE_ROLLBACK_FAILED is fixed by continuing the rollback: either repair the cause by hand, or skip the resources that cannot roll back. After the stack reaches UPDATE_ROLLBACK_COMPLETE, it can be updated again, and the skipped resources should be brought back in line.
AWS documentation