2.3.3. AWS CodeDeploy for Application Deployment
First Principle: AWS CodeDeploy automates the deployment of application code to various compute services, ensuring consistent, reliable, and versioned releases with minimal downtime.
CodeDeploy automates pushing code to EC2, Lambda, or ECS, configured through appspec.yml which defines lifecycle hooks at each deployment stage.
Two strategies dominate the exam. In-place (EC2 only) stops the app on existing instances, deploys new code, and restarts — simple but causes downtime. Blue/green provisions new instances with the new version, shifts traffic after health checks pass, then terminates old instances — zero downtime with instant rollback.
For Lambda, CodeDeploy manages traffic shifting through aliases: canary (10% → wait → 100%), linear (10% every N minutes), or all-at-once. The AppSpec hooks BeforeAllowTraffic and AfterAllowTraffic run validation Lambda functions before and after the shift. The traffic percentages and interval come from the deployment configuration (for example, CodeDeployDefault.LambdaCanary10Percent5Minutes), not from the AppSpec file.
The critical exam concept: automatic rollback. If CloudWatch alarms fire during traffic shifting, CodeDeploy reverts automatically — but only if you've configured rollback triggers in the deployment group.
For EC2/on-premises, appspec.yml must sit at the root of the revision bundle, and hook script locations are relative to that root. Hook scripts can read environment variables that the CodeDeploy agent sets (DEPLOYMENT_GROUP_NAME, DEPLOYMENT_ID, APPLICATION_NAME, LIFECYCLE_EVENT), so one AppSpec can behave differently per environment, such as choosing a config file when DEPLOYMENT_GROUP_NAME is Staging.
When an EC2/on-premises deployment fails at a lifecycle event such as ApplicationStart, look first at the CodeDeploy logs on the instance, not CloudTrail or the deployment group settings: the agent log (/var/log/aws/codedeploy-agent/codedeploy-agent.log on Linux) records the agent's errors, and each deployment's hook-script output is in /opt/codedeploy-agent/deployment-root/<deployment-group-ID>/<deployment-ID>/logs/scripts.log.
Scenario: You've built your application and now need to deploy it to a fleet of EC2 instances or to a Lambda function. You want to automate this process and minimize downtime during updates.
⚠️ Exam Trap: CodeDeploy for Lambda uses traffic shifting (canary, linear, all-at-once). CodeDeploy for EC2/on-premises uses in-place or blue/green. They use DIFFERENT appspec.yml structures — Lambda uses hooks like BeforeAllowTraffic, EC2 uses hooks like ApplicationStop.