Use IAM Roles Anywhere for the on-premises pipeline and CodeArtifact external connections for public repositories

Answer Correct answer: B, D — use IAM Roles Anywhere for the on-premises pipeline to publish to CodeArtifact and configure external connections as upstream repositories.

A company is migrating from its on-premises data center to AWS. The company currently uses a custom on-premises Cl/CD pipeline solution to build and package software. The company wants its software packages and dependent public repositories to be available in AWS CodeArtifact to facilitate the creation of application-specific pipelines. Which combination of steps should the company take to update the CI/CD pipeline solution and to configure CodeArtifact with the LEAST operational overhead? (Choose two.)

  1. Update the C1ICD pipeline to create a VM image that contains newly packaged software. Use AWS Import/Export to make the VM image available as an Amazon EC2 AMI. Launch the AMI with an attached IAM instance profile that allows CodeArtifact actions. Use AWS CLI commands to publish the packages to a CodeArtifact repository.
  2. Create an AWS Identity and Access Management Roles Anywhere trust anchor. Create an IAM role that allows CodeArtifact actions and that has a trust relationship on the trust anchor. Update the on-premises CI/CD pipeline to assume the new IAM role and to publish the packages to CodeArtifact. Correct Answer
  3. Create a new Amazon S3 bucket. Generate a presigned URL that allows the PutObject request. Update the on-premises CI/CD pipeline to use the presigned URL to publish the packages from the on-premises location to the S3 bucket. Create an AWS Lambda function that runs when packages are created in the bucket through a put command. Configure the Lambda function to publish the packages to CodeArtifact.
  4. For each public repository, create a CodeArutact repository that is configured with an external connection. Configure the dependent repositories as upstream public repositories. Correct Answer
  5. Create a Codeartitact repository that is configured with a set of external connections to the public repositories. Configure the external connections to be downstream of the repository.

Community Votes

BD
100%

100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

IAM Roles Anywhere gives workloads outside AWS temporary credentials by trusting a local certificate, letting the existing on-premises pipeline call CodeArtifact directly with no VM image, import/export, or presigned URL plumbing (B). For public dependencies, the documented best practice is one CodeArtifact repository per external source with the external connection configured as upstream, so assets flow from the public repo into the domain repository (D). Option E wrongly makes external connections downstream and merges unrelated sources into one repository.

To move an on-premises CI/CD pipeline and its public repository dependencies into CodeArtifact with the least overhead, create an IAM Roles Anywhere trust anchor plus an IAM role that allows CodeArtifact actions and trusts that anchor, then have the on-premises pipeline assume the role to publish packages. Separately, for each dependent public repository, create a CodeArtifact repository with an external connection and set the dependent repositories as upstream so builds resolve them automatically.

Building a VM image and converting it to an AMI with an instance profile just to publish packages (A)—this adds image creation, Import/Export, and instance management for a task that Roles Anywhere handles with a certificate and an assumed role. Using a presigned PutObject URL to S3 plus a Lambda to forward packages (C)—this invents a two-hop delivery path with a custom function instead of publishing directly to CodeArtifact. Making external connections downstream (E) reverses the intended direction; upstream is what pulls public assets into the repository.

Community Discussion (7 comments)

thanhnv142 👍 6 Selected: BD
B and D are correct: <wants its software packages and dependent public repositories to be available in AWS CodeArtifact >: we need to push onprem artifact to CodeArtifact with IAM Anywhere Role and create an upstream for public repositories A: irrelevant B: correct C: irrelevant D: correct E: there is no downstream in CodeArtifact
youonebe 👍 1 Selected: BD
AWS IAM Roles Anywhere is a feature that allows workloads running outside of AWS, such as on-premises servers, containers, and applications, to access AWS resources using temporary security credentials obtained by assuming an IAM role.
dkp 👍 2 Selected: BD
ANS B&D
DanShone 👍 4 Selected: BD
B & D B - https://docs.aws.amazon.com/rolesanywhere/latest/userguide/getting-started.html D - Best practice for external connections is to have one repository per domain with an external connection to a given public repository.
Ramdi1 👍 3 Selected: BD
B & D The other options have drawbacks: A: Complex setup: Requires VM image creation, import, and AMI launching, adding unnecessary complexity. Security concerns: Using EC2 instances might introduce security risks compared to IAM roles. Inefficient publishing: Relies on manual CLI commands for publishing, less automated than other options.
vortegon 👍 2 Selected: BD
https://www.pulumi.com/ai/answers/bddaepm6EeuDs9du1MVtC8/aws-codeartifact-and-iam-roles-setup
Arnaud92 👍 1 Selected: AD
D. In CodeArtifact, the intended way to use external connections is to have one repository per domain with an external connection to a given public repository. A. Using aws codeartifact with rolesanywhere is the LEAST operational overhead => https://www.pulumi.com/ai/answers/bddaepm6EeuDs9du1MVtC8/aws-codeartifact-and-iam-roles-setup

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

IAM Roles Anywhere establishes a trust anchor from an on-premises certificate authority and an IAM role trusting that anchor with CodeArtifact permissions. The existing on-premises pipeline then assumes that role to receive temporary credentials and publish packages straight into CodeArtifact, with no infrastructure to build or images to import, which is the least-overhead path. For the public repositories the pipeline depends on, each one gets its own CodeArtifact repository with an external connection, and the dependent repositories are configured as upstream, so assets are automatically pulled in and versioned during builds.

Why the Other Options Are Wrong

A requires packaging software into a VM image, converting it with AWS Import/Export, launching an EC2 instance, and only then publishing via the CLI—far more moving parts and operational overhead. C routes packages through an S3 bucket with a presigned URL and a Lambda function, adding a bespoke two-stage delivery mechanism where a direct assumed role suffices. E creates one repository with external connections configured downstream, which inverts the flow—external connections must be upstream so public assets are pulled into the repository. B and D are correct.

Community Comment Notes

Community voted B,D (95). Commenters agreed Roles Anywhere is the intended on-premises authentication path and that the documented best practice for external connections is one repository per source with upstream repositories; they characterized A as complex, C as a needless custom path, and E as reversed configuration.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide