[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"lesson-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-en":3,"cheat-sheet---en":3,"topic-info----en":3,"prev-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-en":3,"next-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-en":3,"domain-info-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-en":4},null,{"meta":5,"body":8},{"title":6,"description":7},"Deployment, Provisioning, and Automation","Build and change infrastructure without manual clicking: golden AMIs and container images, CloudFormation and the AWS CDK, Terraform, multi-account provisioning with StackSets and AWS RAM, deployment strategies, and fleet automation with Systems Manager.",{"type":9,"value":10,"toc":58},"minimark",[11,15,18,23,48,52,55],[12,13,14],"p",{},"An engineer fixes a production problem by clicking through the console. Six weeks later the same stack has to exist in a second account, and half those clicks are missing because nobody wrote them down. This domain is the answer to that problem: describe the infrastructure in a file, let a service apply it, and get the same result every time in every account and Region.",[12,16,17],{},"It carries 22% of SOA-C03, and it changes what the earlier domains buy you. Monitoring tells you something is wrong, and reliability keeps the workload up. Provisioning decides whether the fix ships as a reviewed template change or as an undocumented console edit that nobody can reproduce.",[19,20,22],"h2",{"id":21},"what-this-domain-covers","What This Domain Covers",[24,25,26,30,33,36,39,42,45],"ul",{},[27,28,29],"li",{},"Golden AMIs with EC2 Image Builder, and container images with ECR repositories, image scanning, and lifecycle policies",[27,31,32],{},"CloudFormation template authoring: parameters, conditions, intrinsic functions, and outputs",[27,34,35],{},"Safe stack operations with change sets, drift detection, and stack policies, plus diagnosing a deployment that failed or rolled back",[27,37,38],{},"The AWS CDK, and where Terraform and Git fit into a CloudOps workflow",[27,40,41],{},"Multi-account and multi-Region provisioning with StackSets, resource sharing through AWS RAM, and governed catalogs with Service Catalog and Control Tower",[27,43,44],{},"Rolling, blue/green, canary, and in-place deployments, and how each maps onto Auto Scaling groups, ECS, and Lambda",[27,46,47],{},"Day-2 automation with Systems Manager: fleet management without SSH, Patch Manager and State Manager, Parameter Store, and event-driven operations",[19,49,51],{"id":50},"why-it-matters","Why It Matters",[12,53,54],{},"Exam questions here rarely ask what CloudFormation is. They hand you a stack stuck in UPDATE_ROLLBACK_FAILED, a StackSet that reached four accounts out of five, or an update that must ship without dropping a single request, and ask what to do next. Answering means knowing how each mechanism behaves when something goes wrong, not just the path where everything works.",[12,56,57],{},"The job pressure is the same. Infrastructure you can rebuild from a template survives an account migration, a Region outage, and the departure of the person who built it. Infrastructure that exists only as console state survives none of those.",{"title":59,"searchDepth":60,"depth":60,"links":61},"",3,[62,64],{"id":21,"depth":63,"text":22},2,{"id":50,"depth":63,"text":51}]