Use IAM Roles Anywhere for the on-premises pipeline and CodeArtifact external connections for public repositories
A company is migrating from its on-premises data center to AWS. The company currently uses a custom on-premises Cl/CD pipeline solution to build and package software. The company wants its software packages and dependent public repositories to be available in AWS CodeArtifact to facilitate the creation of application-specific pipelines. Which combination of steps should the company take to update the CI/CD pipeline solution and to configure CodeArtifact with the LEAST operational overhead? (Choose two.)
Community Votes
100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
IAM Roles Anywhere gives workloads outside AWS temporary credentials by trusting a local certificate, letting the existing on-premises pipeline call CodeArtifact directly with no VM image, import/export, or presigned URL plumbing (B). For public dependencies, the documented best practice is one CodeArtifact repository per external source with the external connection configured as upstream, so assets flow from the public repo into the domain repository (D). Option E wrongly makes external connections downstream and merges unrelated sources into one repository.
To move an on-premises CI/CD pipeline and its public repository dependencies into CodeArtifact with the least overhead, create an IAM Roles Anywhere trust anchor plus an IAM role that allows CodeArtifact actions and trusts that anchor, then have the on-premises pipeline assume the role to publish packages. Separately, for each dependent public repository, create a CodeArtifact repository with an external connection and set the dependent repositories as upstream so builds resolve them automatically.
Building a VM image and converting it to an AMI with an instance profile just to publish packages (A)—this adds image creation, Import/Export, and instance management for a task that Roles Anywhere handles with a certificate and an assumed role. Using a presigned PutObject URL to S3 plus a Lambda to forward packages (C)—this invents a two-hop delivery path with a custom function instead of publishing directly to CodeArtifact. Making external connections downstream (E) reverses the intended direction; upstream is what pulls public assets into the repository.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
IAM Roles Anywhere establishes a trust anchor from an on-premises certificate authority and an IAM role trusting that anchor with CodeArtifact permissions. The existing on-premises pipeline then assumes that role to receive temporary credentials and publish packages straight into CodeArtifact, with no infrastructure to build or images to import, which is the least-overhead path. For the public repositories the pipeline depends on, each one gets its own CodeArtifact repository with an external connection, and the dependent repositories are configured as upstream, so assets are automatically pulled in and versioned during builds.Why the Other Options Are Wrong
A requires packaging software into a VM image, converting it with AWS Import/Export, launching an EC2 instance, and only then publishing via the CLI—far more moving parts and operational overhead. C routes packages through an S3 bucket with a presigned URL and a Lambda function, adding a bespoke two-stage delivery mechanism where a direct assumed role suffices. E creates one repository with external connections configured downstream, which inverts the flow—external connections must be upstream so public assets are pulled into the repository. B and D are correct.Community Comment Notes
Community voted B,D (95). Commenters agreed Roles Anywhere is the intended on-premises authentication path and that the documented best practice for external connections is one repository per source with upstream repositories; they characterized A as complex, C as a needless custom path, and E as reversed configuration.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →