← AWS Developer Associate: applications and operations
09 / 9 · 60 MIN

Private access, identities, and release gates

Diagnose networking, authorization, and qualifiers through tests representing the production identity and path.

Draw the complete request path

A rotation function can reach its database while failing to reach Secrets Manager. Draw both paths and mark hostname, resolution, address, port, networking rules, and API identity. Record where failure occurs: before connecting, during TLS, or after an HTTP response. That map guides handoffs between developers, networking, cloud, and APS. Do not start by broadening permissions without evidence of authorization denial. A manual check should use context comparable to the function, including networking and identity.

Diagnose a move into a VPC

In the IPv4 exercise, a Lambda that contacted a public API moves into a subnet routed to an internet gateway. That does not itself give it public access. Verify the approved egress path and dependencies before increasing timeouts. NAT can form part of a solution for public destinations; a supported AWS API can have a suitable private path. The choice depends on the destination and policy rather than a subnet’s public or private label. Define both a connectivity check and an application-outcome check after the change.

Use the endpoint without confusing controls

A Secrets Manager interface endpoint reaches the service through a private path. Private DNS can make the Regional hostname resolve through that path. This does not grant GetSecretValue to the role or make endpoint policy irrelevant. If HTTPS returns AccessDenied, collect identity, action, and resource and compare applicable policies. Change only the approved grant while retaining other boundaries. Recovery verification should confirm reading the expected secret without printing its value in logs or attaching it to a ticket.

Distinguish caller and execution role

When a role in account A invokes a function in account B, caller and resource need the applicable cross-account grants. The function execution role supports operations performed during execution; it does not replace client authorization to invoke. For a denied request, first identify the principal and ARN involved. Describe the change with action, resource, and approval owner. Administrative testing in account B can show that code runs but does not demonstrate that the client in A has the intended access.

Treat the qualifier as part of the contract

Alias prod can point to version 18 while remaining a different invoked resource from:18. A grant limited to the alias should not be interpreted as automatic permission for the numeric ARN. In the fictional case, a release changes the client to:18 and causes AccessDenied even though code is unchanged. Restore the approved alias path or obtain explicit approval for another contract. Include the complete ARN in the test plan and also check an out-of-scope resource that should remain denied.

Build a gate that observes the integration

A direct version test establishes less than the gate needs. The gate should confirm the reference used by the client, selected version, identity, business outcome, and expected observability signal. Retain evidence without credentials or sensitive payloads. Add an expected denial to detect excessive grants. If a negative check unexpectedly succeeds, stop promotion and investigate the effective grant. The plan need not use real data; a synthetic case with a predictable outcome allows comparison before and after.

Recover dependencies and confirm the service

Moving an alias to the previous version does not revert a shared route table or an external policy changed in the release. List these dependencies in the plan and assign an owner for each recovery. After fixing networking, confirm authorization; after fixing authorization, confirm the operation outcome. For rotation, also verify consistency between the secret and database before resuming clients. Management reporting should separate restored service, work awaiting reconciliation, and actions preventing incident recurrence.

IN PRACTICE

A fictional release changes the client to:18 although only:prod is authorized. Testing with the real role reveals the difference that administrative testing missed.

Common pitfalls

Treating timeout as AccessDenied; assuming private DNS grants actions; confusing execution role and caller; checking only as administrator; attributing all infrastructure rollback to an alias.

Related topics: IAM and least privilege · Production handover

Take this idea with you

A useful release check represents who calls, which resource they call, the path taken, and the outcome they should obtain.

Create account

Reference: Secrets Manager VPC endpoint · DVA-C02; exam guide 2.1

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.