← AWS DevOps Engineer Professional: operations and delivery
01 / 8 · 35 MIN

Pipeline, artifacts, and identity

Build promotion evidence and cross-account access.

Concept and mechanism

A pipeline should answer three questions: what was built, what was tested, and what will run. The commit hash identifies code but not every build input. Variable dependencies, tools, and configuration can produce a different binary on rebuild. Promote identified, tested artifacts while separating environment configuration and secrets. Keep reports linked to the actual version. A test command masking failure with a successful exit status breaks the gate even when its report documents errors. Report collection should preserve the failure determining whether promotion can continue.

Guided application

In CodeBuild, retrieving a secret through an appropriate integration avoids placing it in visible configuration, but does not make every log safe. A transformed value may escape exact-value masking. Do not print secrets or variants. Across accounts, distinguish role assumption from artifact access: the source needs sts:AssumeRole authorization and the destination needs suitable trust; S3, KMS, and other boundaries still apply. A pipeline in account A does not simply support passing an artifact produced in B to C when both actions are outside A. Confirm the supported flow before increasing permissions. Finally, an expired manual approval is failure, not implicit acceptance. The current API allows timeout configuration; record the effective value.

IN PRACTICE

The checksum changed after QA. The change owner needs evidence about the new binary or promotion of the already validated artifact.

Common pitfalls

Commit as binary; encoded secret as safe; notification as approval; excessive permissions to bypass a service limitation.

Related topics: Progressive delivery and rollback · IaC, drift, and reconciliation

Take this idea with you

Connect identity, evidence, and authorization to the object actually promoted.

Create account

Reference: DOP-C02 domain 1 · DOP-C02