Soru

Zorluk: KolayAWS Service Catalog Portfolio and Product Management

A SysOps administrator is configuring an AWS Service Catalog portfolio to allow developers to deploy a standardized three-tier application. The administrator wants to ensure that developers can launch the product even if they do not have direct IAM permissions to create the underlying Amazon EC2 and Amazon RDS resources. The resources must be provisioned using a specific IAM service role. Which configuration should the administrator apply to meet these requirements?

  1. Apply a launch constraint to the product that specifies the designated IAM service role.Cevap
  2. B
    Configure an IAM policy with AssumeRole permissions and attach it directly to the developers' IAM group.
  3. C
    Define a template constraint on the product that maps the IAM service role to the CloudFormation template parameters.
  4. D
    Create a StackSet constraint that deploys the product resources using the administrator's credentials.

Cevap

Apply a launch constraint to the product that specifies the designated IAM service role.
Applying a launch constraint to the product allows AWS Service Catalog to assume a specific IAM service role (the launch role) to provision the resources on behalf of the user. This allows users to launch the product even if they do not have direct IAM permissions to deploy the underlying AWS resources.

Adım Adım Çözüm

1
Identify the need to provision resources through AWS Service Catalog without granting the launching users direct permissions to create those resources.
Determine that a Service Catalog constraint must be configured to delegate permissions.
By default, AWS Service Catalog uses the end user's IAM permissions to provision resources, which fails if the user lacks those permissions.
2
Select the appropriate constraint type designed for overriding user permissions during launch.
Choose a launch constraint and associate it with an IAM service role.
A launch constraint specifies the IAM role that AWS Service Catalog assumes to provision the product's resources, enabling secure delegation.

Anahtar Kavram

AWS Service Catalog Launch Constraints
Tahmini Süre:1m 0s
Bu soruyu puanla