AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseMedium
A company uses AWS CodePipeline for its CI/CD workflows. They have implemented automated testing, but occasionally, a faulty deployment still makes it to production, causing critical application failures. The DevOps team needs to implement a mechanism that automatically reverts the application to the last known good state if specific CloudWatch Alarms are triggered shortly after a production deployment. Which CodePipeline feature should they configure to achieve this?
- AIntegrate AWS CodeDeploy with a blue/green deployment strategy.
- BAdd a manual approval stage after the production deployment.
- CConfigure a custom action to invoke a Lambda function for rollback.
- DEnable CodePipeline automatic rollback on alarm and configure target alarms.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable CodePipeline automatic rollback on alarm and configure target alarms.
CodePipeline's automatic rollback on alarm feature is specifically designed for this scenario. It allows you to specify CloudWatch Alarms that, if triggered after a deployment, will automatically initiate a rollback to the previous successful pipeline execution, reverting the application to a stable state.
Why the other options are wrong
- A. Blue/green deployments reduce downtime and risk, but CodeDeploy itself doesn't inherently provide the logic for *automatic* rollback based on *CloudWatch Alarms* after the deployment is complete, without additional CodePipeline configuration.
- B. Manual approval prevents deployments but doesn't automate rollback after a failure in production.
- C. While possible, a custom Lambda function requires more operational overhead to implement and maintain compared to the native CodePipeline feature for automatic rollback.
CodePipeline Automatic Rollback
A CodePipeline feature that automatically reverts a deployment to the last successful state if specified CloudWatch Alarms are triggered after the deployment.
- Tied to CloudWatch Alarms for post-deployment monitoring.
- Reverts to the last successful pipeline execution.
- Reduces downtime from faulty deployments.
Memory trick: Pipeline sees an alarm, rolls back with charm.