QuestionQ50

Configuration Management and IaC

A development team wants to deploy an application by using AWS CloudFormation stacks. However, the developer IAM role lacks the permissions required to provision the resources defined in the AWS CloudFormation template. A DevOps engineer must implement a solution that enables the developers to deploy the stacks. The solution must adhere to the principle of least privilege.

Which solution satisfies these requirements?

Explanation

A CloudFormation service role lets CloudFormation provision stack resources with that role’s credentials instead of the developer role’s credentials. Granting the developer role iam:PassRole for the specific approved service role enables its use during stack deployment while avoiding direct resource-provisioning permissions and overly broad CloudFormation access.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!