Empty the non-empty S3 bucket from the custom resource's Lambda on Delete using RequestType Delete
A company has developed a static website hosted on an Amazon S3 bucket. The website is deployed using AWS CloudFormation. The CloudFormation template defines an S3 bucket and a custom resource that copies content into the bucket from a source location. The company has decided that it needs to move the website to a new location, so the existing CloudFormation stack must be deleted and re-created. However, CloudFormation reports that the stack could not be deleted cleanly. What is the MOST likely cause and how can the DevOps engineer mitigate this problem for this and future versions of the website?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The bucket fails deletion because it still contains objects, which is the documented behavior for CloudFormation's S3 bucket resource (B). The cleanup has to happen before bucket deletion, and the custom resource that populates the bucket is the natural owner of that responsibility, so its Lambda function implements the empty-on-Delete behavior. Option A addresses a static website configuration, which does not block deletion. Option C's DeletionPolicy applies to the custom resource itself rather than the bucket's contents. Option D's DeletionPolicy attribute is not a valid value for the S3 bucket resource, and a bucket DeletionPolicy would not empty it in any case.
CloudFormation cannot delete a non-empty S3 bucket, and the bucket is populated because a custom resource copies website content into it from a source location. The fix that also holds for future versions is to make the custom resource's Lambda function handle the Delete request type by recursively emptying the bucket, so that by the time CloudFormation attempts to delete the bucket resource it is empty and deletion succeeds. This keeps the cleanup logic inside the custom resource that owns the content.
Removing the WebsiteConfiguration property from the S3 bucket resource (A) — a static website configuration does not prevent CloudFormation from deleting a bucket, so this change has no bearing on the failure. Adding a DeletionPolicy of RemoveOnDeletion to the custom resource (C) — that attribute controls what happens to the custom resource itself on stack deletion, not whether the S3 bucket is empty. Setting a DeletionPolicy on the S3 bucket resource (D) — Empty is not a valid DeletionPolicy value for a bucket, and DeletionPolicy never empties bucket contents; only an explicit cleanup action does.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
CloudFormation will not delete an S3 bucket that still contains objects, and AWS documentation for the S3 bucket resource states this explicitly. In this template the bucket holds the website content because a custom resource copies it in from a source location, so the content must be removed before the stack can be deleted. The durable fix is to give the custom resource's Lambda function a Delete branch, keyed on the RequestType being Delete, that recursively empties the bucket. Because the same custom resource is used by every future version of the website, the mitigation is built in once and applies to subsequent deployments rather than requiring a manual cleanup each time (B). B is the correct answer.Why the Other Options Are Wrong
A states deletion failed because the bucket has an active website configuration and proposes removing the WebsiteConfiguration property. A static website configuration has no bearing on whether CloudFormation can delete a bucket; the blocker is the presence of objects, so this change would not resolve the failure. C states the custom resource does not define a deletion policy and proposes adding a DeletionPolicy of RemoveOnDeletion to the custom resource. DeletionPolicy governs what happens to the resource it is attached to when the stack is deleted, in this case the custom resource itself; it does not empty the S3 bucket, so the bucket would still block deletion. D states the bucket is not empty and proposes adding a DeletionPolicy with the value Empty to the S3 bucket resource. Empty is not a valid DeletionPolicy value for an S3 bucket, and more fundamentally a DeletionPolicy never removes objects from a bucket, so even a valid value would not empty it. B is correct.Community Comment Notes
Community voted B unanimously. youonebe cited the AWS documentation for the S3 bucket resource and noted that you can only delete empty buckets, so deletion fails when the bucket still contains objects. GripZA explained that CloudFormation cannot delete a non-empty S3 bucket by default, so if objects remain when stack deletion is attempted the deletion fails. trungtd, tgv, and inturist confirmed B without further qualification, and no alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →