Deploy the CloudWatch agent as a StatefulSet with IRSA and CloudWatchAgentServerPolicy, and configure the OIDC provider
A company has a web application that is hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The EKS cluster runs on AWS Fargate that is available through an internet-facing Application Load Balancer. The application is experiencing stability issues that lead to longer response times. A DevOps engineer needs to configure observability in Amazon CloudWatch to troubleshoot the issue. The solution must provide only the minimum necessary permissions. Which combination of steps will meet these requirements? (Choose three.)
Community Votes
100% of anonymous learners picked answer BCE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
AWS documents that Daemonsets aren't supported on Fargate and that a daemon must be reconfigured as a sidecar container, which eliminates both the DaemonSet collector in B and any DaemonSet-based agent (B). The CloudWatch agent deployed as a StatefulSet is the viable option (A). Since Fargate pods have no access to the instance metadata service, IRSA is required, which in turn requires an OIDC provider configured for the cluster (E). For least privilege, the service account role uses CloudWatchAgentServerPolicy rather than CloudWatchAgentAdminPolicy, since the agent needs to publish metrics and logs but not administer CloudWatch resources (C rather than D).
The cluster runs on AWS Fargate, which changes how the observability agent must be deployed. Fargate does not support DaemonSets, so the CloudWatch agent is deployed as a Kubernetes StatefulSet rather than the AWS Distro for OpenTelemetry collector as a DaemonSet, which cannot run there. Because Fargate pods cannot use the instance metadata service for credentials, the agent must obtain them through IAM roles for service accounts, which requires an IAM OpenID Connect provider for the cluster, and the service account role is given CloudWatchAgentServerPolicy to satisfy the minimum-necessary-permissions requirement rather than the broader admin policy.
Deploying the AWS Distro for OpenTelemetry collector as a Kubernetes DaemonSet (B) — the AWS documentation states plainly that Daemonsets aren't supported on Fargate and that daemons must be reconfigured as sidecar containers, so this deployment cannot run on a Fargate cluster; several commenters made exactly this point. Using CloudWatchAgentAdminPolicy for the service account role (D) — the requirement is minimum necessary permissions, and the agent only needs to publish telemetry, not administer CloudWatch. Omitting the OIDC provider (E) — without it, IAM roles for service accounts cannot federate, so the pod cannot obtain AWS credentials at all.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The defining constraint is that the cluster runs on AWS Fargate, and AWS documentation states that Daemonsets aren't supported on Fargate and that any daemon must be reconfigured to run as a sidecar container in the pod. That rules out the DaemonSet-based OpenTelemetry collector in option B and makes deploying the CloudWatch agent as a Kubernetes StatefulSet the workable approach (A). Because Fargate pods cannot use the instance metadata service to obtain AWS credentials, the agent must be granted permissions through IAM roles for service accounts, which in turn requires an IAM OpenID Connect provider to be configured for the EKS cluster (E). To satisfy the minimum-necessary-permissions constraint, the service account role is bound to CloudWatchAgentServerPolicy, which permits publishing the telemetry the agent produces without granting CloudWatch administrative rights that CloudWatchAgentAdminPolicy would (C). A, C, and E are the correct combination.Why the Other Options Are Wrong
B deploys the AWS Distro for OpenTelemetry collector as a Kubernetes DaemonSet. AWS Fargate documentation explicitly states that Daemonsets aren't supported on Fargate and recommends reconfiguring a daemon as a sidecar container, so this deployment cannot be scheduled on a Fargate cluster; CHRIS12722222, SysOps, and jojewi8143 all raised this, with jojewi8143 changing to a StatefulSet-based answer for that reason. D binds CloudWatchAgentAdminPolicy to the service account role, which grants CloudWatch administrative permissions well beyond what an observability agent needs, directly contradicting the requirement for only the minimum necessary permissions. The remaining option combination using B cannot run on Fargate at all. A, C, and E are correct.Community Comment Notes
Community votes favored B,C,E (38), but that group is incorrect on the decisive technical point. Several of the highest-rated comments, including CHRIS12722222 with the documentation link, SysOps, and jojewi8143, established that DaemonSets are not supported on EKS Fargate, which invalidates B; matt200, who favored B,C,E, described the OpenTelemetry collector as generally recommended but did not address the Fargate restriction. The documented Fargate limitation takes precedence over the vote count.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →