Skip to main content

Governance gates and separation of duties

Exam alignment: DOP-C02 Domain 1 task statements for pipelines, testing, artifacts, or deployment.

Learning objective

Automate deterministic controls and reserve approval for accountable judgment.

Difficulty / SchwierigkeitsgradIntermediate
Study time / Lernzeit120 minutes
Prerequisites / VoraussetzungenPrevious lessons in this volume

Professional scenario

Seven manual approvals repeat scanner output and delay releases for days.

Core concepts

  • Deterministic checks belong in automated gates.
  • Manual approval is for accountable risk acceptance.
  • Evidence must be tied to the exact artifact.
  • Break-glass paths need limits, expiry, audit, and review.

Architecture flow

  1. Identify the release input and immutable identity.
  2. Select the managed AWS control plane and least-privilege role.
  3. Execute build, test, artifact, or deployment work.
  4. Collect service events, logs, reports, and runtime metrics.
  5. Stop, retry, or roll back according to explicit rules.

Decision matrix

RequirementPreferred choiceReason
Objective ruleAutomated policy gateConsistent and fast
Business risk decisionManual approvalHuman accountability
Emergency exceptionAudited break-glassControlled deviation

Failure modes and troubleshooting

  • Approver reviews evidence for another artifact.
  • Approval never expires.
  • Same identity authors and approves.

Security and operations

  • Use short-lived service roles and least privilege.
  • Encrypt artifacts and protect logs from secret exposure.
  • Record changes and approvals for audit.

Hands-on lab

Goal / Ziel: Reduce a manual checklist to automated evidence plus one approval.

Tasks

  1. Create the smallest safe test architecture.
  2. Implement or simulate the main workflow.
  3. Introduce one controlled failure.
  4. Diagnose it from service evidence.
  5. Document cleanup and one improvement.

Validation

  • The workflow uses an immutable version.
  • A required failure blocks promotion.
  • The diagnosis identifies the first failed transition.

Cost control / Kostenkontrolle: Keep resources short lived; read cleanup before starting.

Cleanup

  1. Delete pipeline/build/deployment resources.
  2. Delete temporary artifacts, images, logs, and roles.

Exam traps

  • Manual approval simply because compliance is mentioned.
  • Break-glass as normal process.

Key takeaways

  • Deterministic checks belong in automated gates.
  • Break-glass paths need limits, expiry, audit, and review.
  • Decisions must be justified by requirements and failure behavior.

Review questions

  1. What is the immutable release identity?
  2. Which evidence proves failure or success?
  3. What is the safest recovery action?
Answers
  1. A version, digest, or uniquely versioned artifact.
  2. Service events, logs, reports, health checks, and runtime metrics.
  3. Restore the known-good version using the configured rollback path.