Concept and mechanism
Developer work in an existing pipeline includes preparing the package, configuration, and release evidence. A successful compilation command does not guarantee the artifact contains the correct files. In CodeBuild, compare output paths with buildspec artifacts and base-directory. Keep secrets outside the file and use supported references with role-limited access. The same review should check that scripts do not print retrieved values. When testing Lambda, pin a published version; invoking $LATEST while it keeps changing makes results hard to reproduce. Also identify relevant environment configuration and dependencies.
Guided application
Unit tests with mocks help isolate logic but can accept a contract the real service does not use. Add representative event examples and integration tests in a suitable environment, including missing fields, duplicates, and unexpected responses. For an AI-proposed change, review the diff and check the same behavior and security criteria. A convincing explanation does not execute failure cases. Before promotion, tie test results to the approved artifact to avoid silently rebuilding another package. A technical PM should be able to request this evidence and confirm APS receives the rehearsed version and configuration.
The build creates dist/app.js, but artifacts selects only root files. Correct selection and inspect the produced package before investigating runtime timeouts.
Common pitfalls
Confusing a green build with a valid application; mocks without a contract; secrets in comments; rebuilding artifacts after approval.
Related topics: Gradual deployment and recovery · Diagnosis, capacity, and cost
Each promotion should identify the code and evidence supporting the decision.
Reference: CodeBuild buildspec reference · DVA-C02; exam guide 2.1