A DevOps engineer is designing a CI/CD pipeline for a containerized application using AWS CodeBuild and Amazon ECS. Which TWO actions will help reduce the frequency of Docker image pulls from the public Docker Hub registry?
Enabling CodeBuild local caching with the cache type LOCAL_DOCKER_LAYER_CACHE stores image layers in the build host's local Docker daemon after the first successful build. On subsequent builds, CodeBuild can reuse those locally cached layers instead of pulling them from Docker Hub, which cuts both external network calls and build time. This is the most direct way to reduce Docker Hub pull frequency for a standard container-image CI pipeline.
Why this answer
Option B is correct because enabling CodeBuild local caching with the cache type 'LOCAL_DOCKER_LAYER_CACHE' persists Docker image layers between builds on the same host, so previously pulled base image layers are reused and Docker does not need to re-pull them from Docker Hub. Option C is correct because storing the base image in Amazon ECR and referencing it in the build pulls the image from ECR (a private, AWS-hosted registry) instead of the public Docker Hub registry, directly reducing Docker Hub pulls. Option A is incorrect because a Docker Hub access token in Secrets Manager only authenticates and raises rate limits; it does not reduce the number or frequency of image pulls.
Option D is incorrect because AWS CodeArtifact does not support Docker/OCI registries as a Docker Hub proxy (it supports package formats like npm, Maven, PyPI, NuGet), so it cannot serve as a pull-through cache for Docker images. Option E is incorrect because attaching CodeBuild to a VPC with a NAT gateway only changes network routing for outbound traffic; it does not cache or eliminate Docker Hub image pulls.
Exam trap
Candidates may think that D (CodeArtifact proxy) is correct, but AWS CodeArtifact does not support Docker registries or act as a proxy for Docker Hub. It is intended for software packages like npm, PyPI, Maven, and NuGet, not for container image caching.