AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A company uses AWS CodePipeline to deploy its microservices to Amazon ECS. Each microservice has its own pipeline. They want to ensure that the latest approved Docker image from an Amazon ECR repository is used in the ECS task definition during deployment, without hardcoding image tags in the source code or build process. How can this be achieved reliably?

  1. AManually update the ECS task definition with the correct image tag before each deployment.
  2. BStore the image tag in AWS Systems Manager Parameter Store and retrieve it in the CodeDeploy AppSpec.
  3. CConfigure the CodePipeline source stage to pull the ECS task definition from a Git repository with a placeholder tag.
  4. DUse the output artifact from a CodeBuild stage (which builds and pushes the image) as input to a subsequent ECS deployment action, dynamically replacing the image tag in the task definition.
Show answer & explanation

Correct answer: D. Use the output artifact from a CodeBuild stage (which builds and pushes the image) as input to a subsequent ECS deployment action, dynamically replacing the image tag in the task definition.

CodeBuild can output a JSON file containing the ECR image URI and tag after building and pushing a Docker image. This output artifact can then be used as input to an ECS deployment action. The ECS deployment action in CodePipeline has a feature to dynamically replace the image tag within an ECS task definition file using values from the input artifact, ensuring the latest image is always used.

Why the other options are wrong

  • A. Manual updates are error-prone and defeat the purpose of automation.
  • B. While Parameter Store can store tags, retrieving and integrating it into the ECS task definition update process within CodePipeline is less direct and automated than using CodePipeline's native artifact replacement feature.
  • C. Using a placeholder in a Git repository still requires a mechanism to replace that placeholder, which option C directly addresses within CodePipeline's deployment action.

CodePipeline ECS Image Update

CodePipeline can dynamically update an Amazon ECS task definition's Docker image tag by consuming an 'imagedefinitions.json' artifact generated by a preceding CodeBuild stage.

  • CodeBuild generates 'imagedefinitions.json'.
  • This JSON contains ECR image URI and tag.
  • ECS deployment action uses this artifact to update task definition.
  • Ensures latest built image is deployed without hardcoding.

Memory trick: Build artifact's image, updates ECS's page.

More Deployment questions