QuestionQ42

SDLC Automation

A DevOps engineer needs to deploy a serverless web application based on AWS Lambda. The deployment must satisfy these requirements:

  • Provide staging and production environments.
  • Prevent developers from accessing the production environment.
  • Do not hardcode passwords in the Lambda functions.
  • Store the source code in AWS CodeCommit.
  • Use AWS CodePipeline to automate deployment.

What is the MOST operationally efficient solution that meets these requirements?

Explanation

Separate AWS accounts establish isolation between staging and production and allow production access to be restricted through account-level IAM policies and cross-account deployment roles. Lambda environment variables keep environment-specific values, including passwords, outside the function source code; Lambda encrypts environment variables at rest with AWS KMS. AWS CodePipeline supports cross-account actions, including deployment resources in another account, and CodeDeploy supports the AWS Lambda compute platform.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!