Deployment Artifacts and Configuration Management

Lambda deployment packages, ECR, AppConfig, and environment-specific configuration management.

Once you have built an app, you need to put it on a server. This process is called deployment. How do you package your code, manage configuration, and deploy it in AWS?

DVA-C02 exam questions in this area focus on how to package and manage code and settings.

 

Lambda Deployment Packages

There are two ways to upload a Lambda function to AWS.

First method: .zip file Compress the function code and required libraries into a ZIP file and upload it. Direct upload: up to 50MB Upload via S3: up to 250MB Suitable for simple functions or when there are few dependencies.

Second method: Container image Package as a Docker image, store it in ECR, then link it to Lambda. Supports up to 10GB. Advantageous when there are large dependencies, such as machine learning models. Teams familiar with container technology can reuse their existing Docker workflows.

 

Amazon ECR (Elastic Container Registry)

ECR is a service for storing and managing Docker container images. Think of it as AWS's Docker Hub. Just as you store code in GitHub, you store Docker images in ECR.

Key features: Image scanning: Automatically checks stored images for known security vulnerabilities. Lifecycle policies: Automatically cleans up old images to reduce storage costs. Cross-account sharing: With resource policies configured, images can be safely shared with other AWS accounts.

 

AWS AppConfig

What if you could change your app's settings without deploying new code? For example, turning a new feature on or off, or releasing it to a specific user group first. That is exactly what AWS AppConfig does.

Feature Flag: Enables turning specific features on or off without a code deployment. For example, useful when testing a new payment system with only a subset of users first. Gradual rollout: Instead of applying configuration changes to everyone at once, apply them to a small group first. If something goes wrong, you can roll back immediately. Validation: Validates configuration using a JSON schema or Lambda function before it is deployed. Prevents incorrect configurations from being deployed. Auto-rollback: If an error is detected after deployment, automatically reverts to the previous configuration.

 

Environment-Specific Configuration Management

Apps typically run in separate development (Dev), test/staging (Staging), and production (Production) environments. Each environment needs different settings (database addresses, API keys, etc.).

Ways to manage environment-specific configuration in AWS: Parameter Store path-based hierarchy: Separate by path, like /app/dev/db-url and /app/prod/db-url Lambda environment variables: Set different environment variables per function to have different behavior per environment SAM template Parameters or Mappings: Inject different values per environment when deploying serverless apps

 

Exam Key Points

"Large dependencies in Lambda (up to 10GB)" -- Container image (ECR)

"Lambda deployment package exceeds 50MB" -- Upload ZIP to S3

"Change configuration without code deployment" -- AWS AppConfig

"Turn features on/off without code" -- Feature Flag (AppConfig)

"Automatically detect Docker image security vulnerabilities" -- ECR image scanning

"Manage environment-specific configuration hierarchically" -- Parameter Store (path-based)

"Inject environment-specific values in SAM" -- Parameters/Mappings

AppConfig is the key service for separating code deployment from configuration deployment

Back to blog list