AWS CodeDeploy
Core concept: CodeDeploy automates application deployments to EC2, Lambda, and ECS with traffic shifting, rollback, and lifecycle hooks.
What Is CodeDeploy?
CodeDeploy is like a smart deployment manager. Instead of manually updating your servers one by one, CodeDeploy orchestrates the rollout β shifting traffic gradually, running health checks, and automatically rolling back if something goes wrong.
Deployment Targets
| Platform | Deployment Type | Agent | Traffic Control |
|---|---|---|---|
| EC2/On-Premises | In-place or Blue/Green | β CodeDeploy Agent | ASG, tags |
| Lambda | Traffic shifting (aliases) | β Not needed | Alias routing |
| ECS | Blue/Green (ALB) | β Not needed | Target group swap |
Deployment Strategies
EC2 Deployment Strategies
| Strategy | Description | Downtime |
|---|---|---|
| AllAtOnce | Deploy to all instances simultaneously | β οΈ Brief |
| HalfAtATime | Deploy to 50% of instances, then remaining | Minimal |
| OneAtATime | Deploy to one instance at a time | None |
| Blue/Green | Create new ASG, shift ALB traffic | None |
Lambda Deployment Configurations
| Configuration | Behavior |
|---|---|
| LambdaAllAtOnce | Shift 100% traffic immediately |
| LambdaCanary10Percent5Minutes | 10% β wait 5 min β 90% |
| LambdaCanary10Percent10Minutes | 10% β wait 10 min β 90% |
| LambdaCanary10Percent15Minutes | 10% β wait 15 min β 90% |
| LambdaCanary10Percent30Minutes | 10% β wait 30 min β 90% |
| LambdaLinear10PercentEvery1Minute | 10% β 20% β ... β 100% (every 1 min) |
| LambdaLinear10PercentEvery2Minutes | 10% β 20% β ... β 100% (every 2 min) |
| LambdaLinear10PercentEvery3Minutes | 10% β 20% β ... β 100% (every 3 min) |
| LambdaLinear10PercentEvery10Minutes | 10% β 20% β ... β 100% (every 10 min) |
- Canary = shift small %, wait, then shift ALL remaining
- Linear = shift same % at regular intervals until 100%
ECS Deployment Configurations
| Configuration | Behavior |
|---|---|
| ECSAllAtOnce | Shift 100% immediately |
| ECSCanary10Percent5Minutes | Same as Lambda canary |
| ECSLinear10PercentEvery1Minute | Same as Lambda linear |
Lifecycle Hooks
EC2/On-Premises Hook Order
ApplicationStop β Stop current app
β
DownloadBundle β Download new revision from S3/GitHub
β
BeforeInstall β Pre-install tasks (backup, decrypt)
β
Install β Copy files to destination
β
AfterInstall β Post-install (set permissions, config)
β
ApplicationStart β Start the application
β
ValidateService β Run health checks β MOST IMPORTANT
Lambda Hook Order
BeforeAllowTraffic β Run pre-traffic validation Lambda
β
AllowTraffic β Traffic shifted to new version
β
AfterAllowTraffic β Run post-traffic validation Lambda
Pre-Traffic Hook Example (Lambda)
public class PreTrafficHook implements RequestHandler<Map<String, Object>, Void> {
private final CodeDeployClient codeDeploy = CodeDeployClient.create();
public Void handleRequest(Map<String, Object> event, Context context) {
String deploymentId = (String) event.get("DeploymentId");
String lifecycleEventHookExecutionId = (String) event.get("LifecycleEventHookExecutionId");
String status = "Succeeded";
try {
// Test the new Lambda version
invokeNewVersion();
validateResponse();
} catch (Exception e) {
status = "Failed"; // This triggers automatic rollback
}
codeDeploy.putLifecycleEventHookExecutionStatus(
PutLifecycleEventHookExecutionStatusRequest.builder()
.deploymentId(deploymentId)
.lifecycleEventHookExecutionId(lifecycleEventHookExecutionId)
.status(status)
.build());
return null;
}
}
appspec.yml
Lambda
version: 0.0
Resources:
- MyLambdaFunction:
Type: AWS::Lambda::Function
Properties:
Name: "OrderProcessor"
Alias: "live"
CurrentVersion: "1"
TargetVersion: "2"
Hooks:
- BeforeAllowTraffic: "arn:aws:lambda:us-east-1:123:function:PreTrafficHook"
- AfterAllowTraffic: "arn:aws:lambda:us-east-1:123:function:PostTrafficHook"
EC2
version: 0.0
os: linux
files:
- source: /
destination: /var/www/html
permissions:
- object: /var/www/html
owner: apache
group: apache
mode: "755"
hooks:
ApplicationStop:
- location: scripts/stop-server.sh
timeout: 120
BeforeInstall:
- location: scripts/install-deps.sh
timeout: 300
AfterInstall:
- location: scripts/set-permissions.sh
ApplicationStart:
- location: scripts/start-server.sh
timeout: 120
ValidateService:
- location: scripts/health-check.sh
timeout: 60
ECS Blue/Green
version: 0.0
Resources:
- TargetService:
Type: AWS::ECS::Service
Properties:
TaskDefinition: "arn:aws:ecs:us-east-1:123:task-definition/my-task:2"
LoadBalancerInfo:
ContainerName: "api-container"
ContainerPort: 8080
Hooks:
- BeforeInstall: "LambdaValidateDatabases"
- AfterInstall: "LambdaRunIntegrationTests"
- AfterAllowTestTraffic: "LambdaVerifyGreenTargetGroup"
- BeforeAllowTraffic: "LambdaCheckHealth"
- AfterAllowTraffic: "LambdaVerifyProductionShifting"
Rollback Behavior
| Trigger | Rollback |
|---|---|
| Any lifecycle hook fails | β Automatic |
| CloudWatch alarm breached | β Automatic (if configured) |
| Manual trigger | β Via console/CLI |
CodeDeploy "rollback" = redeploy the previous revision. It doesn't reverse changes β it deploys the old version as a new deployment.
Deployment Groups
| Config | Description |
|---|---|
| Deployment group | Target instances (EC2 tags, ASG, ECS service) |
| Deployment config | Traffic shifting strategy |
| Service role | IAM role for CodeDeploy |
| Alarms | CloudWatch alarms that trigger rollback |
| Triggers | SNS notifications on deployment events |
| Auto-rollback | Enable/disable on failure or alarm |
DVA-C02 Exam Tips
- Canary = shift small %, wait, shift rest. Linear = gradual increment
- Hook failure = automatic rollback
- Rollback = redeploy previous version (new deployment)
- EC2 supports in-place AND blue/green. ECS = blue/green only
- Lambda uses aliases for traffic shifting
- BeforeAllowTraffic = pre-traffic validation (Lambda platform)
- ValidateService = health check (EC2 platform)
- appspec.yml = mandatory deployment specification file
- CodeDeploy Agent needed on EC2, NOT needed for Lambda/ECS
- ECS blue/green requires ALB with two target groups
Practice Questions
Q1. ValidateService hook fails. What happens?
A) Deployment marked failed, no rollback
B) Automatic rollback to previous version
C) Hook retries 3 times
D) Deployment continues with warning
β Answer & Explanation
B β Any hook failure triggers automatic rollback by redeploying the last successful version.
Q2. 10% traffic to new Lambda, wait 5 min, then 100%. Which config?
A) LambdaLinear10PercentEvery1Minute
B) LambdaAllAtOnce
C) LambdaCanary10Percent5Minutes
D) LambdaBlueGreen
β Answer & Explanation
C β Canary10Percent5Minutes: 10% immediate β monitor 5 min β shift remaining 90%.
Q3. ECS Fargate needs zero-downtime deployment. Which strategy?
A) In-place
B) Rolling update
C) Blue/Green with ALB target group swap
D) AllAtOnce
β Answer & Explanation
C β ECS Fargate with CodeDeploy supports only Blue/Green via ALB target group swapping.
