Automation and infrastructure as code
Automation keeps environments consistent, recoverable and secure. Task statement 2.2 asks for "automation strategies to ensure infrastructure integrity" and knowledge of "immutable infrastructure" — this chapter covers both.
AWS CloudFormation
Define AWS resources in templates (YAML/JSON); CloudFormation creates, updates and deletes them as a stack.
Resources:
AssetsBucket:
Type: AWS::S3::Bucket
Properties:
VersioningConfiguration:
Status: Enabled
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: aws:kms
| Feature | Use |
|---|---|
| Parameters, mappings, outputs | Reusable templates across environments |
| Change sets | Preview changes before applying |
| Rollback | Failed updates roll back automatically |
| Drift detection | Find resources changed manually outside CloudFormation |
| StackSets | Deploy stacks to many accounts and Regions at once (e.g. baseline security in every account) |
| Nested stacks | Compose large templates from smaller ones |
"Recreate the same environment quickly in another Region for DR" or "deploy a standard baseline to every account" → CloudFormation (StackSets).
(The AWS CDK and other tools generate CloudFormation from code; the exam guide treats the CDK as out of scope, but the concept is the same.)
AWS Systems Manager
A suite for operating fleets of instances (EC2 and on-premises):
| Capability | Use |
|---|---|
| Session Manager | Browser/CLI shell access without SSH, bastions or open ports; logged |
| Run Command | Run scripts across many instances |
| Patch Manager | Automate OS patching with baselines and maintenance windows |
| Automation | Runbooks for common tasks and remediation (e.g. create AMI, restart service) |
| Parameter Store | Configuration and secrets |
| Inventory / State Manager | Track software and enforce configuration |
| OpsCenter / Incident Manager | Operational issue tracking and response |
Self-service and platforms
- AWS Service Catalog — curated, approved products for teams to launch.
- AWS Proton — platform teams publish templates for containers and serverless services; developers deploy within standards.
- AWS Elastic Beanstalk — upload code; Beanstalk handles capacity, load balancing, scaling and health monitoring. Supports rolling, immutable and blue/green deployments.
Immutable infrastructure and safe deployments
Immutable infrastructure means you never patch servers in place — you build a new image and replace instances. Benefits: consistency, easy rollback, no configuration drift.
| Strategy | How | Risk |
|---|---|---|
| In place / rolling | Update instances in batches | Mixed versions during rollout |
| Immutable | Launch a fresh set of instances with the new version, then switch | Higher temporary capacity cost |
| Blue/green | Run new environment alongside old; switch traffic (Route 53 weighted, ALB target groups) | Easy instant rollback |
| Canary | Shift a small % of traffic first (Route 53 weighted, API Gateway canary, Lambda aliases) | Limits blast radius |
Golden AMIs can be built automatically with EC2 Image Builder.
Exam patterns
- "Ensure all accounts deploy the same security baseline automatically" → CloudFormation StackSets (or Control Tower).
- "Patch hundreds of instances monthly with minimal effort" → Systems Manager Patch Manager.
- "Detect manual changes to production infrastructure" → CloudFormation drift detection / AWS Config.
- "Release with instant rollback" → blue/green deployment.