AWS 380: Service Catalog products and governed self-service
Why this lesson matters
AWS Service Catalog lets users discover and operate approved infrastructure products without receiving every underlying service permission. Governance comes from product quality, portfolio access, launch identity, constraints, versions, sharing, lifecycle ownership, and evidence, not from a catalog label alone.
Product operating model
| Construct | Function | Owner decision |
|---|---|---|
| Product | Deployable CloudFormation/Terraform-based capability | Support, SLO, cost and data class |
| Provisioning artifact | Versioned template release | Active/deprecated versions and upgrade path |
| Portfolio | Products plus audience/governance boundary | Principals, shares, local constraints |
| Launch constraint | Role used to provision | Least privilege and trust/pass-role path |
| Template constraint | Allowed parameter values | Security/cost bounds without false safety |
| Tag update constraint | Whether end-user tag updates propagate | ABAC, allocation and immutable tags |
| Provisioned product | User-owned running instance/stack | Update, support, termination and data retention |
Portfolio access permits discovery/launch but the launch role performs CloudFormation operations. Trace the end-user identity, Service Catalog API, launch constraint role, CloudFormation service behavior, and resource roles. A broad launch role lets a constrained user indirectly create powerful resources; restrict template capabilities, resource types/conditions, role passing, boundaries, and product parameters.
Versioning a product does not automatically make existing provisioned products current. Define compatibility, required/optional update deadlines, migration, rollback, deprecation, and removal. Never remove the only artifact needed to repair or roll back existing products. Product metadata must state owner, purpose, architecture, parameters, expected outputs, price estimate, limits, support route, data/backup behavior, and teardown effect.
Separate catalog administrator, product engineering, security review, portfolio owner, launch-role owner, end user, and provisioned-product operator. Record who can publish a version, associate it with a portfolio, change constraints, share it, provision it, update it, and terminate it. CloudTrail and Service Catalog records should make these transitions attributable. Test the end-user experience with the actual federated role, not an administrator session.
Sharing, tags, and lifecycle
Portfolio shares can distribute governance across accounts or Organizations. Recipient administrators may associate principals and apply local constraints according to the sharing model. Inventory source portfolio, shares, accepted/imported portfolio, principals, launch roles, target accounts/Regions, and version availability. Treat organization-wide sharing as a high-blast-radius release.
TagOptions and tags aid discovery and allocation but do not replace IAM enforcement. Prevent users from selecting privileged ABAC tags. Combine organizational tag policy, launch-role conditions, required product parameters, and runtime checks. Budgets alert; they do not usually stop resources automatically.
Provisioned products have launch, update, and terminate records. Termination can delete the backing stack while retained resources continue billing. Deletion policies, databases, snapshots, buckets, domains, KMS keys, logs, and external records need explicit ownership. Define abandoned-product detection and two-pass cleanup.
Monitor provisioning failures, products by version/age, unsupported versions, ownerless instances, update backlog, cost anomalies, policy drift, expiring exceptions, and termination residue. Product success includes usable outputs and application health, not only a completed provisioning record. Support must correlate the Service Catalog record, CloudFormation stack events, resource metrics, and user identity without exposing confidential parameters.
Read-only inspection and workshop
aws servicecatalog search-products-as-admin --region ap-south-1
aws servicecatalog list-portfolios --region ap-south-1
aws servicecatalog describe-product-as-admin --id PRODUCT_ID --region ap-south-1
aws servicecatalog list-constraints-for-portfolio --portfolio-id PORTFOLIO_ID --region ap-south-1
aws servicecatalog search-provisioned-products --region ap-south-1
aws servicecatalog list-record-history --region ap-south-1
Design a three-version private S3 application-storage product for development and regulated portfolios. Include encryption, block public access, versioning, logging decision, lifecycle/backup, allowed regions/classes, owner/cost tags, launch role, parameter constraints, outputs, alarms, support, update migration, termination, and retained-data process. Add a second networking product only to analyze whether combining lifecycle ownership is appropriate.
Test 16 failures: user lacks portfolio, stale share, product version disabled, invalid parameter, launch-role trust, pass-role, SCP deny, CloudFormation capability, name collision, quota, privileged tag, update replacement, incompatible version, termination blocked, retained resource orphan, and distributed version mismatch. For each preserve record ID, stack event, CloudTrail actor, user message, repair, and governance improvement.
Cost and acceptance
Price every product resource, CloudFormation/third-party processing where applicable, logs, notifications, sharing operations, support, retained resources, and idle provisioned products. Service Catalog pricing and supported product types can change, so confirm current pricing before launch. This lesson creates nothing.
Submit product contract, portfolio/audience map, IAM chain, parameter and tag threat model, three-version lifecycle, share model, provision/upgrade/terminate runbooks, sixteen failures, cost controls, and inventory dashboard. Pass requires least-privilege indirect provisioning, version support, explicit data disposition, and a named owner for every provisioned product.