An extra 30% off every course until Sunday, October 11.Choose your certification →

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.1.3.1. Artifact Use Cases & Secure Management

2.1.3.1. Artifact Use Cases & Secure Management

Without secure artifact management, a compromised dependency or tampered container image can propagate through your entire deployment pipeline undetected. Every build output must be versioned, integrity-verified, and access-controlled.

Artifact types in AWS DevOps:
  • Application packages: JAR files, ZIP archives, Docker images stored in ECR or S3
  • Infrastructure artifacts: CloudFormation templates, CDK cloud assemblies, Terraform plan files
  • Machine images: AMIs built by EC2 Image Builder, hardened and pre-configured
  • Configuration artifacts: appspec.yml, buildspec.yml, environment-specific config files

Integrity verification: ECR supports signing images with AWS Signer and the Notation client (or Sigstore cosign), with the signature verified before deployment (e.g., a pipeline action) — a cryptographic provenance guarantee, unlike IAM or network controls, which only limit who can push. Immutable tags prevent overwriting. S3 Object Lock (WORM) protects artifacts for compliance: Compliance mode lets no one — not even the root user — delete an object or shorten its retention; Governance mode lets users with s3:BypassGovernanceRetention do so. CodeArtifact verifies package checksums against upstream repositories.

Vulnerability scanning: ECR basic scanning checks OS packages for CVEs on push or on demand — a point-in-time result. Enhanced scanning uses Amazon Inspector to cover OS and programming-language packages (npm, pip, Maven…) and re-scans continuously as new CVEs are published. Scanning checks what is in an image; repository policies only control who can pull or push it.

Access control patterns:
  • ECR: Resource-based policies control cross-account pull access. IAM policies control push/pull within the account.
  • S3: Bucket policies + IAM roles. Use aws:PrincipalOrgID condition to restrict to your organization.
  • CodeArtifact: Domain-level and repository-level policies. Cross-account access uses resource-based policies.

Artifact lifecycle: Automate cleanup to control costs. ECR lifecycle policies delete untagged images older than N days. S3 lifecycle policies transition old artifacts to Glacier or delete them. CodeArtifact automatically deduplicates packages fetched from upstream repositories.

Exam Trap: CodePipeline stores intermediate artifacts in an S3 bucket (auto-created or specified). These artifacts are encrypted with the pipeline's KMS key. If cross-account pipeline stages fail with access denied, check that the downstream account has permissions to decrypt using the pipeline's KMS key — not just S3 read access.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications