A SaaS company builds a large Java container image with AWS CodeBuild on every commit and pushes it to a private Amazon ECR repository in the same account. The image build takes 14 minutes, mostly spent downloading Maven dependencies and rebuilding unchanged Docker layers. The company also wants builds to run inside its VPC so that an internal Nexus mirror is reachable, and it wants the CodeBuild project to push images without any static registry password in the buildspec. The build environment currently uses a standard image with privileged mode disabled, and the last run failed with 'Cannot connect to the Docker daemon'.
Which combination of changes should the DevOps engineer make to fix the failure and reduce build time? (Choose THREE.)
Choose 3.
- A.
Authenticate to ECR in the pre_build phase with aws ecr get-login-password piped to docker login, using the CodeBuild service role's permissions.
- B.
Enable privileged mode on the CodeBuild project so the Docker daemon can run inside the build container.
- C.
Store the ECR registry password as a PLAINTEXT environment variable so the docker push command can authenticate non-interactively.
- D.
Move the build to AWS Lambda compute in CodeBuild so the Docker daemon starts faster.
- E.
Increase the compute type to the largest available and disable all caching, because cache restoration adds latency to every build.
- F.
Enable Amazon S3 caching for the Maven local repository directory and Docker layer caching (LOCALDOCKERLAYER_CACHE) on the project.
Show answer
Answer: A, B, F
Privileged mode fixes the Docker daemon error, S3 plus local Docker layer caching removes the repeated downloads, and get-login-password uses the service role instead of a static password.
- A. get-login-password issues a short-lived token from the service role, so no static credential lives in the buildspec.
- B. Docker-in-Docker builds require privileged mode; the daemon error is the direct symptom of it being disabled.
- C. ECR does not use static passwords, and a PLAINTEXT variable would be a stored secret in the project.
- D. Lambda compute for CodeBuild does not support Docker image builds or privileged mode.
- E. Larger compute does not avoid re-downloading dependencies; disabling caching makes the problem worse.
- F. S3 caching persists Maven dependencies and local Docker layer caching reuses unchanged layers across builds.
