Skip to main content

AWS CI/CD Pipeline

Exam Weight: Domain 3 (Deployment) β€” 24% of exam. Know each tool's role and deployment strategies cold.


The AWS CI/CD Stack

Developer pushes code
↓
[CodeCommit] ← Source control (Git)
↓
[CodeBuild] ← Build, test, package (like Jenkins/GitHub Actions)
↓
[CodeDeploy] ← Deploy to EC2/ECS/Lambda
↓
[CodePipeline] ← Orchestrates the whole flow

CodeCommit

  • Fully managed Git repository (like GitHub/GitLab, but AWS)
  • Authentication: HTTPS (Git credentials or CodeCommit credentials) or SSH
  • Integrated with IAM for access control
  • Triggers: SNS, Lambda on push/PR events
AWS announced CodeCommit is no longer accepting new customers (July 2024). For the exam, it's still tested β€” but in practice, most teams use GitHub/GitLab with CodePipeline.

CodeBuild

What It Does

  • Compiles code, runs tests, produces artifacts
  • No servers to manage β€” fully managed
  • Uses build environments (Docker containers)
  • Charges per build minute

buildspec.yml

version: 0.2

env:
variables:
TABLE_NAME: "orders-table"
parameter-store:
DB_PASSWORD: "/prod/myapp/db-password" # From SSM
secrets-manager:
API_KEY: "prod/myapp/api-key" # From Secrets Manager

phases:
install:
runtime-versions:
java: corretto17
commands:
- echo "Installing dependencies..."

pre_build:
commands:
- echo "Running tests..."
- mvn test

build:
commands:
- echo "Building..."
- mvn package -DskipTests

post_build:
commands:
- echo "Build complete"
- aws s3 cp target/app.jar s3://my-artifacts/app.jar

artifacts:
files:
- target/app.jar
- appspec.yml
- scripts/**/*

cache:
paths:
- '/root/.m2/**/*' # Cache Maven dependencies

Key Features

FeatureDescription
VPC SupportRun builds inside your VPC to access private resources
Local Buildscodebuild_build.sh for local testing
Test ReportsJUnit/Cucumber XML β†’ CodeBuild Test Reports
Artifacts to S3Build output stored in S3
Environment VariablesPlaintext, SSM Parameter Store, Secrets Manager

CodeDeploy

CodeDeploy automates deployments to:

TargetDeployment Types Available
EC2 / On-PremisesIn-Place, Blue/Green
ECSBlue/Green (Canary, Linear, All-at-once)
LambdaCanary, Linear, All-at-once

appspec.yml (EC2/On-Premises)

version: 0.0
os: linux

files:
- source: /target/app.jar
destination: /opt/myapp/

hooks:
ApplicationStop:
- location: scripts/stop_server.sh
timeout: 30
BeforeInstall:
- location: scripts/install_dependencies.sh
timeout: 60
AfterInstall:
- location: scripts/configure_app.sh
ApplicationStart:
- location: scripts/start_server.sh
timeout: 60
ValidateService:
- location: scripts/health_check.sh
timeout: 30

Deployment Strategies

EC2 In-Place (Rolling)​

StrategyDescription
AllAtOnceDeploy to all instances simultaneously β€” downtime possible
HalfAtATimeDeploy to 50% at a time
OneAtATimeSafest β€” one instance at a time, slowest
CustomDefine your own percentage

Blue/Green (EC2, ECS, Lambda)​

Current (Blue): v1.0 β€” receiving 100% traffic
↓
New (Green): v2.0 β€” deployed, health checked
↓
Traffic shifted to Green
↓
Blue kept for rollback window (configurable)

Lambda & ECS Deployment Configurations​

Canary:
LambdaCanary10Percent5Minutes β†’ 10% for 5 min, then 100%
LambdaCanary10Percent30Minutes β†’ 10% for 30 min, then 100%

Linear:
LambdaLinear10PercentEvery1Minute β†’ +10% every 1 min
LambdaLinear10PercentEvery10Minutes β†’ +10% every 10 min

All-at-Once:
LambdaAllAtOnce β†’ instant 100% (fastest, no safety net)

appspec.yml (Lambda)

version: 0.0
Resources:
- MyLambdaFunction:
Type: AWS::Lambda::Function
Properties:
Name: "OrderProcessor"
Alias: "live"
CurrentVersion: "1"
TargetVersion: "2"

Hooks:
BeforeAllowTraffic: "PreTrafficCheckFunction"
AfterAllowTraffic: "PostTrafficCheckFunction"

CodePipeline

Orchestrates the full pipeline:

Source Build Test Deploy
─────────────────────────────────────────────────────
CodeCommit β†’ CodeBuild β†’ CodeBuild β†’ CodeDeploy
(or (tests) (or ECS,
GitHub, Beanstalk,
S3) CloudFormation)

Key Features

FeatureDescription
Manual ApprovalPause pipeline for human sign-off before prod deploy
Parallel ActionsRun multiple build/test stages simultaneously
Cross-RegionDeploy to multiple regions
ArtifactsS3 bucket stores outputs between stages
NotificationsSNS, EventBridge on pipeline state changes

Practice Questions

Q1. A team wants to deploy a new Lambda version gradually β€” send 10% of traffic to the new version for 5 minutes, then promote to 100% if healthy. Which CodeDeploy configuration should they use?

A) LambdaLinear10PercentEvery1Minute
B) LambdaCanary10Percent5Minutes
C) LambdaAllAtOnce
D) LambdaLinear10PercentEvery10Minutes

βœ… Answer & Explanation

B β€” Canary shifts a small % of traffic first, waits, then promotes 100% if healthy. LambdaCanary10Percent5Minutes = 10% for 5 minutes β†’ 100%. Linear shifts traffic incrementally in equal steps.


Q2. A CodeBuild project needs to fetch a database password from SSM Parameter Store during the build. How should this be configured?

A) Pass the password as a CodeBuild environment variable (plaintext)
B) Reference it in buildspec.yml under env.parameter-store
C) Use a Lambda function to retrieve the password before build
D) Store the password in the source code repository

βœ… Answer & Explanation

B β€” buildspec.yml supports env.parameter-store to securely retrieve SSM Parameter Store values at build time. The IAM role for CodeBuild needs ssm:GetParameters permission.


Q3. During a CodeDeploy deployment to EC2, the ValidateService hook fails. What does CodeDeploy do?

A) Continues deployment and logs the failure
B) Skips the hook and completes deployment
C) Rolls back the deployment to the previous version
D) Sends a notification but doesn't roll back

βœ… Answer & Explanation

C β€” If any hook (especially ValidateService) fails, CodeDeploy rolls back to the previous working version automatically.


Q4. A CodePipeline needs human approval before deploying to production. Which action type should be added between the staging and production stages?

A) CodeBuild β€” test stage
B) Manual Approval action
C) Lambda invoke
D) SNS notification

βœ… Answer & Explanation

B β€” CodePipeline's built-in Manual Approval action pauses the pipeline and sends an SNS notification to approvers. The pipeline proceeds only after approval.


Resources

πŸ“–
Track Page Progress0 / 635 Read
Knowledge Base Completion0%