Amazon Web Services

CI/CD — CodePipeline, CodeBuild & CodeDeploy

Build, test and release automatically, with a deployment strategy that can be rolled back.

A pipeline takes a commit and moves it to production through defined stages.

A conveyor with inspection points. Anything that fails a check is pulled off the line before it reaches the customer, and the line can be reversed if a fault is spotted after dispatch.

Key Concepts

1
    source -> build -> test -> deploy staging -> approve -> deploy prod
    CodeCommit CodeBuild        CodeDeploy       manual     CodeDeploy
    or GitHub
2
CodeBuild runs the build in a container from a buildspec.yml, producing an artifact. CodeDeploy releases it with a strategy. CodePipeline wires the stages together and stops on failure.
buildspec.yml
3
The deployment strategies are the part interviewers ask about.
    in-place / rolling  replace instances in batches. Cheapest.
                        Two versions run at once -- the API must
                        tolerate that.
    blue/green          build a full new environment, switch the
                        load balancer, keep the old one. Instant
                        rollback. Double the capacity briefly.
    canary              send 10% of traffic to the new version,
                        watch metrics, then shift the rest.
    linear              shift in equal increments on a timer.
4
Blue/green is the answer when rollback speed matters, because reverting is a target group switch rather than another deploy.
5
Automatic rollback is what makes it safe. Wire a CloudWatch alarm on 5xx rate or latency into the deployment group, and a bad release reverts itself without anyone being paged.
6
Database migrations break the neat picture, and good candidates say so. The new and old versions run simultaneously during any rolling or canary deploy, so migrations must be backward compatible: add a column, deploy, backfill, then remove the old one in a later release. Never rename in a single step.
7
Keep credentials out of the buildspec. CodeBuild assumes an IAM role, so it needs no stored keys, and secrets come from Secrets Manager at build time.
8
Artifacts should be built once and promoted through environments. Rebuilding per environment means the thing you tested is not the thing you shipped.
9
What the interviewer is probing.1. "Which deployment strategy gives the fastest rollback?" Probing: the trade. Stalls: "Rolling." Moves up: blue/green — reverting is a target group switch rather than another deployment, at the cost of briefly running double capacity.
10
2. "Your deploy runs two versions at once. What does that mean for the database?" Probing: the migration constraint. Stalls: "Nothing." Moves up: migrations must be backward compatible — add a column, deploy, backfill, drop the old one later. Never rename in one step.
11
3. "How does a bad release roll back without a human?" Probing: automatic rollback. Stalls: "Someone notices." Moves up: a CloudWatch alarm on error rate or latency wired into the deployment group reverts it automatically.
12
4. "Why build the artifact once?" Probing: promotion. Stalls: "It is faster." Moves up: rebuilding per environment means the thing you tested is not the thing you shipped.