Lesson 380 · AWS Learning Path

AWS 380: Service Catalog products and governed self-service

· Published · 4 min read

Labelled process diagram for AWS 380: Versioned intent to Automated validation to Controlled AWS change to Observed result and retained evidence, with decision, proof and rejection evidence.

Why this lesson matters

AWS Service Catalog lets users discover and operate approved infrastructure products without receiving every underlying service permission. Governance comes from product quality, portfolio access, launch identity, constraints, versions, sharing, lifecycle ownership, and evidence, not from a catalog label alone.

Product operating model

ConstructFunctionOwner decision
ProductDeployable CloudFormation/Terraform-based capabilitySupport, SLO, cost and data class
Provisioning artifactVersioned template releaseActive/deprecated versions and upgrade path
PortfolioProducts plus audience/governance boundaryPrincipals, shares, local constraints
Launch constraintRole used to provisionLeast privilege and trust/pass-role path
Template constraintAllowed parameter valuesSecurity/cost bounds without false safety
Tag update constraintWhether end-user tag updates propagateABAC, allocation and immutable tags
Provisioned productUser-owned running instance/stackUpdate, support, termination and data retention

Portfolio access permits discovery/launch but the launch role performs CloudFormation operations. Trace the end-user identity, Service Catalog API, launch constraint role, CloudFormation service behavior, and resource roles. A broad launch role lets a constrained user indirectly create powerful resources; restrict template capabilities, resource types/conditions, role passing, boundaries, and product parameters.

Versioning a product does not automatically make existing provisioned products current. Define compatibility, required/optional update deadlines, migration, rollback, deprecation, and removal. Never remove the only artifact needed to repair or roll back existing products. Product metadata must state owner, purpose, architecture, parameters, expected outputs, price estimate, limits, support route, data/backup behavior, and teardown effect.

Separate catalog administrator, product engineering, security review, portfolio owner, launch-role owner, end user, and provisioned-product operator. Record who can publish a version, associate it with a portfolio, change constraints, share it, provision it, update it, and terminate it. CloudTrail and Service Catalog records should make these transitions attributable. Test the end-user experience with the actual federated role, not an administrator session.

Sharing, tags, and lifecycle

Portfolio shares can distribute governance across accounts or Organizations. Recipient administrators may associate principals and apply local constraints according to the sharing model. Inventory source portfolio, shares, accepted/imported portfolio, principals, launch roles, target accounts/Regions, and version availability. Treat organization-wide sharing as a high-blast-radius release.

TagOptions and tags aid discovery and allocation but do not replace IAM enforcement. Prevent users from selecting privileged ABAC tags. Combine organizational tag policy, launch-role conditions, required product parameters, and runtime checks. Budgets alert; they do not usually stop resources automatically.

Provisioned products have launch, update, and terminate records. Termination can delete the backing stack while retained resources continue billing. Deletion policies, databases, snapshots, buckets, domains, KMS keys, logs, and external records need explicit ownership. Define abandoned-product detection and two-pass cleanup.

Monitor provisioning failures, products by version/age, unsupported versions, ownerless instances, update backlog, cost anomalies, policy drift, expiring exceptions, and termination residue. Product success includes usable outputs and application health, not only a completed provisioning record. Support must correlate the Service Catalog record, CloudFormation stack events, resource metrics, and user identity without exposing confidential parameters.

Read-only inspection and workshop

aws servicecatalog search-products-as-admin --region ap-south-1
aws servicecatalog list-portfolios --region ap-south-1
aws servicecatalog describe-product-as-admin --id PRODUCT_ID --region ap-south-1
aws servicecatalog list-constraints-for-portfolio --portfolio-id PORTFOLIO_ID --region ap-south-1
aws servicecatalog search-provisioned-products --region ap-south-1
aws servicecatalog list-record-history --region ap-south-1

Design a three-version private S3 application-storage product for development and regulated portfolios. Include encryption, block public access, versioning, logging decision, lifecycle/backup, allowed regions/classes, owner/cost tags, launch role, parameter constraints, outputs, alarms, support, update migration, termination, and retained-data process. Add a second networking product only to analyze whether combining lifecycle ownership is appropriate.

Test 16 failures: user lacks portfolio, stale share, product version disabled, invalid parameter, launch-role trust, pass-role, SCP deny, CloudFormation capability, name collision, quota, privileged tag, update replacement, incompatible version, termination blocked, retained resource orphan, and distributed version mismatch. For each preserve record ID, stack event, CloudTrail actor, user message, repair, and governance improvement.

Cost and acceptance

Price every product resource, CloudFormation/third-party processing where applicable, logs, notifications, sharing operations, support, retained resources, and idle provisioned products. Service Catalog pricing and supported product types can change, so confirm current pricing before launch. This lesson creates nothing.

Submit product contract, portfolio/audience map, IAM chain, parameter and tag threat model, three-version lifecycle, share model, provision/upgrade/terminate runbooks, sixteen failures, cost controls, and inventory dashboard. Pass requires least-privilege indirect provisioning, version support, explicit data disposition, and a named owner for every provisioned product.

Official sources

Advertisement