Store the Docker images in ECR and enable the local Docker layer cache in CodeBuild
A DevOps engineer uses AWS CodeBuild to frequently produce software packages. The CodeBuild project builds large Docker images that the DevOps engineer can use across multiple builds. The DevOps engineer wants to improve build performance and minimize costs. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Both halves are needed and they work together: ECR stores the images so they are reusable across builds rather than being rebuilt from nothing each time, and the local Docker layer cache lets the Docker daemon itself reuse cached layers within and across builds on the same host (A). Option C's instruction to always use the most recent image version actively defeats caching because a new version is pulled every time. Option D bakes images into custom AMIs, which requires building and maintaining an AMI per image version and is far heavier than a build-time cache. Option B uses an S3 bucket for the cache, which Docker cannot consume as a layer cache.
Large Docker images built repeatedly across multiple builds mean the same layers are being rebuilt, which wastes both build time and cost. Storing the built images in an Amazon ECR repository makes them available for reuse across builds, and enabling the local Docker layer cache in the CodeBuild project lets the Docker daemon reuse layers it has already built instead of downloading and rebuilding them from scratch, which is what directly improves build performance.
Modifying the CodeBuild project runtime to always use the most recent image version (C) — this is the opposite of caching, because pulling the newest image on every build guarantees nothing is reused and forfeits the performance benefit. Caching Docker images in an Amazon S3 bucket with a Lifecycle policy (B) — Docker's layer cache is stored on the local filesystem of the build host, not in an arbitrary S3 bucket, so an S3 location is not a Docker layer cache and provides no build-time benefit. Creating custom AMIs containing the cached images and launching EC2 instances from them (D) — this requires building and refreshing custom AMIs for each image change, which adds significant time and operational cost compared with a build-time cache.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to improve build performance and minimize cost when producing large Docker images used across multiple builds. Two mechanisms together address it. Storing the images in an Amazon Elastic Container Registry repository makes them centrally available so a later build can pull an existing image instead of rebuilding everything from source, and this repository is where the artifacts persist across builds (A). Enabling the local Docker layer cache for CodeBuild makes the Docker daemon reuse the layers it has already built rather than pulling and rebuilding them, which is what removes the redundant work from each build; as DKM noted, this is the Docker local layer cache feature and it is what speeds up the build process by reusing layers (A). Together the repository and the cache are what reduce both build time and cost. A is the correct answer.Why the Other Options Are Wrong
B caches the Docker images in an Amazon S3 bucket available across build hosts and expires the cache with an S3 Lifecycle policy. Docker's layer cache lives on the local filesystem of the build environment; storing image data in an arbitrary S3 bucket does not make Docker reuse those layers, so there is no build-time performance benefit. C stores the images in ECR but modifies the CodeBuild project's runtime configuration to always use the most recent image version. Pulling the most recent version on every build is the opposite of caching, since it guarantees nothing is reused and therefore loses the performance improvement the question asks for. D creates custom AMIs that contain the cached Docker images and launches EC2 instances from those AMIs in the build. This requires building and maintaining a custom AMI for each image change, which introduces AMI build time and lifecycle management and is substantially more expensive and operationally heavy than a build-time layer cache. A is correct.Community Comment Notes
Community voted A unanimously. DKM explained that the local Docker layer cache stores build cache layers on the local filesystem and can significantly speed up the build process by reusing layers that have already been built, which is the performance mechanism. teo2157 described both halves, pushing built images to ECR after a successful build and pulling them at the start of each build to use as a cache. Ky_24 noted that ECR provides centralized storage so images can be maintained and reused across builds, reducing the need to rebuild base images repeatedly. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →