← AWS DevOps Engineer Professional: operations and delivery
18 / 24 · 80 MIN

Release validation and progressive exposure

Choose the right mechanism, validate the candidate target, and connect observed traffic to continuation decisions.

Start with the actual mechanism

Blue/green describes coexistence and switching between versions, but it does not identify the controller. ECS has native deployment and a CodeDeploy-controlled path; their rules and hooks are not interchangeable. In this lesson, ECS examples mentioning AppSpec and deployment groups explicitly use CODE_DEPLOY. Before adapting a runbook, record controller, strategy, load balancer, test target, production target, and contract version. For a new service, also consult the current native mechanism. A CodeDeploy/NLB-path restriction should not be taught as a universal ECS restriction. This initial identification prevents plausible commands from being applied to an object that does not control the deployment in progress.

Test the correct target at the correct stage

In a CODE_DEPLOY service with an ALB, two target groups represent original and replacement task sets. The optional test listener provides a path to green before production moves. Receiving HTTP 200 is insufficient: confirm the request reached the candidate revision and exercised the changed dependency. AppSpec must agree with task definition, container, and port. If validation uses the test listener, choose a hook after that routing changes, such as AfterAllowTestTraffic. This lesson’s case presents a validator testing blue; correcting only the state reported to the controller would leave release approval based on evidence from the wrong version. Retain target identity alongside functional results.

Complete the validation protocol

The validation Lambda must run checks and communicate the outcome through the CodeDeploy protocol. Normal handler completion does not replace PutLifecycleEventHookExecutionStatus with deployment and hook-execution identifiers. The call accepts Succeeded or Failed as the result; do not use another general-enum state as approval. Record callback failures without hiding functional failures. Also verify that the controller can retrieve alarms. When policy requires that signal, ignorePollAlarmFailure must reflect the decision to stop if retrieval fails. An observation outage should not silently become permission to expand traffic. A successful test, a delivered callback, and available monitoring are distinct pieces of evidence.

Distinguish exposure from observed sample

A weighted Lambda alias distributes invocations between two compatible published versions. It requires the same execution role and DLQ configuration and cannot target LATEST. Weight expresses probability and may differ considerably from the observed proportion at low volume. Segment outcomes by ExecutedVersion to avoid diluting a new regression in healthy old-version traffic. When provisioned capacity is used, track spillover and client experience: execution on standard concurrency is not the same as throttling. The exercise’s local gate requires an observed count and functional checks; its chosen value is fictional learning policy, not an AWS rule or statistical proof that failures are absent.

Coordinate capacity and recovery

Delivery can require capacity for two versions and their shared dependencies. In ECS CODE_DEPLOY, scaling during traffic shift has different stabilization rules from scaling already active at the start. Do not copy one phase’s window into another. After traffic changes, the blue task-set deletion delay is distinct from the canary interval; use observation to decide on outcomes and costs. EC2 hooks have different semantics: ApplicationStop comes from the previous successful revision, and Install belongs to the agent. A fix in the new package may not correct an old script executed before download. The runbook should identify which revision and phase to investigate.

Exercise: make a decision proportional to evidence

The local canary model distinguishes three outcomes: stop for a known functional failure, collect evidence when sample or telemetry is missing, and consider local criteria met when every check passes. It does not calculate statistical confidence, observe AWS, or automatically authorize a release. Execute cases with few requests, functional failure, missing telemetry, and sufficient sample. Explain why a confirmed failure may justify stopping before the minimum while zero errors in a small sample does not justify promotion. In change review, communicate version, window, observed population, outcomes, limitations, and next action. The decision should be reconstructable without relying on someone remembering a green dashboard.

# Original local policy exercise; not statistical proof or release authorization.
def canary_decision(observed, failures, telemetry, functional_ok, minimum=200):
 if not isinstance(observed, int) or not isinstance(failures, int):
 raise ValueError("counts must be integers")
 if observed < 0 or failures < 0 or failures > observed or minimum <= 0:
 raise ValueError("invalid counts")
 if failures or functional_ok is False:
 return "stop and investigate"
 if not telemetry or functional_ok is None or observed < minimum:
 return "collect required evidence"
 return "local criteria met; release decision still required"

assert canary_decision(3, 0, True, True).startswith("collect")
assert canary_decision(3, 1, True, True).startswith("stop")
assert canary_decision(220, 0, False, True).startswith("collect")
assert canary_decision(220, 0, True, False).startswith("stop")
assert canary_decision(220, 0, True, None).startswith("collect")
assert canary_decision(220, 0, True, True).startswith("local criteria")
try:
 canary_decision(3, 4, True, True)
except ValueError:
 pass
else:
 raise AssertionError("invalid counts accepted")
IN PRACTICE

The test returned 200 from blue while green was never exercised; the validator needs the correct target and an identified callback.

Common pitfalls

Mix native ECS and CodeDeploy; test blue to approve green; treat handler return as callback; replace probability with quota; confuse spillover and throttling.

Related topics: Reproducible builds and test evidence

Take this idea with you

Delivery gains evidence only when target, stage, and observed outcomes match the decision being made.

Create account

Reference: Native ECS blue/green deployments · DOP-C02

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.