Attach an instance profile with a CodeArtifact IAM role and run aws codeartifact login on the instance

Answer Correct answer: D — attach an instance profile with a CodeArtifact IAM role and run aws codeartifact login on the instance.

A company uses an AWS CodeArtifact repository to store Python packages that the company developed internally. A DevOps engineer needs to use AWS CodeDeploy to deploy an application to an Amazon EC2 instance. The application uses a Python package that is stored in the CodeArtifact repository. A BeforeInstall lifecycle event hook will install the package. The DevOps engineer needs to grant the EC2 instance access to the CodeArtifact repository. Which solution will meet this requirement?

  1. Create a service-linked role for CodeArtifact. Associate the role with the EC2 instance. Use the aws codeartifact get-authorization-token CLI command on the instance.
  2. Configure a resource-based policy for the CodeArtifact repository that allows the ReadFromRepository action for the EC2 instance principal.
  3. Configure ACLs on the CodeArtifact repository to allow the EC2 instance to access the Python package.
  4. Create an instance profile that contains an IAM role that has access to CodeArtifact. Associate the instance profile with the EC2 instance. Use the aws codeartifact login CLI command on the instance. Correct Answer

Community Votes

D
82%
B
18%

82% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CodeArtifact access requires both an IAM identity and an authentication token: the identity grants permission and the token is what the package manager presents (D). An EC2 instance can only receive an IAM identity through an instance profile, so the role must be delivered that way rather than attached in some other manner (D). The repository's own ACLs do not exist as a CodeArtifact access mechanism, which eliminates option C entirely, and a service-linked role is an identity that a service assumes on your behalf rather than one an instance uses.

The EC2 instance must be able to pull a Python package from a CodeArtifact repository during the CodeDeploy BeforeInstall hook. The instance needs an IAM identity with permission to read from the repository, and an EC2 instance receives credentials through an instance profile containing an IAM role, so an instance profile with a role that has CodeArtifact access is created and associated with the instance. The aws codeartifact login command on the instance then obtains the authorization token that pip and other package tools require, configuring the credential helper so the install succeeds.

Creating a service-linked role for CodeArtifact and associating it with the EC2 instance (A) — a service-linked role is assumed by the CodeArtifact service itself to act on your behalf, not an identity that an EC2 instance assumes, so it cannot authenticate the instance's package installs. Configuring ACLs on the CodeArtifact repository to allow the instance (C) — CodeArtifact does not support ACLs on repositories; access is controlled through IAM policies attached to users or roles plus resource-based policies. teo2157 and Srikantha both described the two required pieces, the IAM role with CodeArtifact permissions attached via the instance profile, and the aws codeartifact login command that sets up the credential configuration.

Community Discussion (4 comments)

Srikantha 👍 1 Selected: D
IAM role with CodeArtifact permissions: You need an IAM role attached to the EC2 instance (via instance profile) that grants permission to read from CodeArtifact. aws codeartifact login sets up your Python environment (e.g., pip) to authenticate to the CodeArtifact repository using temporary credentials tied to the instance’s IAM role. This is the recommended approach to grant secure and scalable access to CodeArtifact from EC2 instances.
teo2157 👍 4 Selected: D
Vote for D based on https://docs.aws.amazon.com/codeartifact/latest/ug/security-iam.html
tinyshare 👍 2 Selected: B
It is the resource allows who can use it, in this case, CodeArtifact. https://docs.aws.amazon.com/codeartifact/latest/ug/repo-policies.html
uncledana 👍 4 Selected: D
D. Create an instance profile that contains an IAM role that has access to CodeArtifact. Associate the instance profile with the EC2 instance. Use the aws codeartifact login CLI command on the instance. Explanation: To allow the EC2 instance to access the CodeArtifact repository, the EC2 instance must have the necessary IAM permissions to interact with AWS CodeArtifact. Here’s why option D is the best solution:

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Pulling a package from an AWS CodeArtifact repository requires two things: an IAM identity authorized to read from the repository, and an authentication token that the package manager presents when it connects. An Amazon EC2 instance receives an IAM identity only through an instance profile, so the solution creates an instance profile containing an IAM role that has access to CodeArtifact and associates that instance profile with the EC2 instance (D). Because the role is attached before the CodeDeploy BeforeInstall hook runs, the hook's package installation executes with those credentials. Running the aws codeartifact login CLI command on the instance retrieves the authorization token and configures the credential helper so that pip and other package managers authenticate to CodeArtifact, which is what makes the install succeed (D). teo2157 cited the CodeArtifact security and IAM documentation as the basis for this answer, and Srikantha described both halves, the instance profile granting permission to read from CodeArtifact and the login command setting up the package manager credential configuration. D is the correct answer.

Why the Other Options Are Wrong

A creates a service-linked role for CodeArtifact, associates the role with the EC2 instance, and uses the get-authorization-token command on the instance. A service-linked role is an IAM role that a particular AWS service assumes on your behalf to perform actions in the context of that service; it is not an identity that an EC2 instance assumes, so associating it with the instance does not give the instance CodeArtifact credentials, and the instance's package install would remain unauthorized. C configures ACLs on the CodeArtifact repository to allow the EC2 instance to access the Python package. CodeArtifact repositories do not have ACLs as an access control mechanism; access is granted through IAM policies on identities and through resource-based policies on the repository and domain, so there is nothing for this option to configure. B configures a resource-based policy on the CodeArtifact repository allowing the ReadFromRepository action for the EC2 instance principal. tinyshare argued for this on the grounds that a resource policy controls who can use the repository, which is true in principle; however, the EC2 instance principal is not an IAM principal that can be named until it has an IAM role, and a resource-based policy alone does not give the instance credentials or a CodeArtifact authentication token. The instance therefore still cannot authenticate a package install. D is correct.

Community Comment Notes

Community voted D (82), with B a minority (18). teo2157 cited the CodeArtifact security and IAM documentation for D, and Srikantha explained that the IAM role is attached via the instance profile to grant permission to read from CodeArtifact while aws codeartifact login sets up the package manager credential configuration. uncledana confirmed D in full. tinyshare was the sole dissenter, preferring B on the reasoning that a resource-based policy is what allows access to the repository and cited the CodeArtifact repository policies documentation; that reasoning does not account for the fact that the instance still needs an IAM identity and a token to authenticate, which only D supplies. No alternative received majority support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide