← AWS CoreCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to AWS Core
Snapshot Sep 30, 2026 · 22:47 UTC · version 1.0.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "aws-deployment",
"description": "Configures CI/CD pipelines using AWS CodePipeline, CodeBuild, CodeDeploy, CodeConnections, and CodeArtifact. Covers CodePipeline V2 (triggers, variables, execution modes, cross-account), buildspec.yml (caching, VPC, Docker), CodeDeploy strategies (blue/green, canary, linear), CodeArtifact (private package registries, auth tokens, cross-account), and source connections (GitHub, GitLab, Bitbucket). Applies when CodePipeline, CodeBuild, CodeDeploy, CodeConnections, CodeArtifact, buildspec.yml, appspec.yml, or CI/CD pipeline orchestration is referenced. Does NOT cover: ECS Fargate services or task definitions (use aws-containers), CDK Pipelines or cdk deploy (use aws-cdk), sam deploy (use aws-serverless), Amplify deployments (use aws-amplify), or GitHub Actions/GitLab CI.",
"included_files": [
{
"relative_path": "references/codeartifact.md",
"size_in_bytes": 6515
},
{
"relative_path": "references/codebuild.md",
"size_in_bytes": 7460
},
{
"relative_path": "references/codeconnections.md",
"size_in_bytes": 6939
},
{
"relative_path": "references/codedeploy.md",
"size_in_bytes": 10627
},
{
"relative_path": "references/codepipeline.md",
"size_in_bytes": 10525
},
{
"relative_path": "references/troubleshooting.md",
"size_in_bytes": 8122
}
],
"skill_md_contents": "---\nname: aws-deployment\ndescription: \"Configures CI/CD pipelines using AWS CodePipeline, CodeBuild, CodeDeploy, CodeConnections, and CodeArtifact. Covers CodePipeline V2 (triggers, variables, execution modes, cross-account), buildspec.yml (caching, VPC, Docker), CodeDeploy strategies (blue/green, canary, linear), CodeArtifact (private package registries, auth tokens, cross-account), and source connections (GitHub, GitLab, Bitbucket). Applies when CodePipeline, CodeBuild, CodeDeploy, CodeConnections, CodeArtifact, buildspec.yml, appspec.yml, or CI/CD pipeline orchestration is referenced. Does NOT cover: ECS Fargate services or task definitions (use aws-containers), CDK Pipelines or cdk deploy (use aws-cdk), sam deploy (use aws-serverless), Amplify deployments (use aws-amplify), or GitHub Actions/GitLab CI.\"\nversion: 1\n---\n\n# AWS Deploy (CI/CD)\n\n**Works best with** the [AWS MCP server](https://docs.aws.amazon.com/aws-mcp/) for running CLI commands and validating configurations directly. All guidance also works with standard AWS CLI.\n\n## Critical Warnings\n\n**CodeConnections PENDING trap**: Connections created via CLI/CloudFormation remain `PENDING` indefinitely — MUST complete OAuth in the AWS Console. No API-only path exists.\n\n**Cross-account triple requirement**: Cross-account deploys need ALL THREE: (1) KMS key policy granting target account (use key ID, not alias), (2) S3 bucket policy for target account, (3) cross-account IAM role with trust policy. Missing any one = cryptic `Access Denied`.\n\n**CodeDeploy ApplicationStop uses PREVIOUS revision**: Broken stop scripts in a prior deployment block ALL future deploys. Make stop scripts idempotent (exit 0 if service absent). Unblock with `--ignore-application-stop-failures`.\n\n**CodeBuild VPC without NAT**: Builds in VPC subnets without NAT gateway hang at `DOWNLOAD_SOURCE` silently. Private subnets MUST have NAT gateway or VPC endpoints.\n\n**CodeConnections IAM**: Use `codeconnections:` prefix for API calls and IAM policy Actions. Resource ARNs must match exactly — new resources use `codeconnections` prefix, existing resources may use `codestar-connections` prefix. Specify both in Resource if you have mixed-age resources.\n\n**UseConnection is over-permissive**: `codeconnections:UseConnection` grants access to ALL repositories the connection can reach. MUST specify condition keys (`codeconnections:FullRepositoryId`, `codeconnections:ProviderAction`, `codeconnections:BranchName`) to limit CodeBuild to only the required repository.\n\n## How These Services Compose\n\nCodeConnections → CodeBuild → CodeDeploy, orchestrated by CodePipeline.\n\n| Layer | Service | Role |\n|-------|---------|------|\n| Source | CodeConnections | Authenticates to GitHub/GitLab/Bitbucket, delivers code |\n| Packages | CodeArtifact | Private package registry, dependency caching from public registries |\n| Build/Test | CodeBuild | Compiles, tests, packages artifacts |\n| Deploy | CodeDeploy | Deploys to EC2/ECS/Lambda with traffic shifting strategies |\n| Orchestrator | CodePipeline | Chains stages, manages transitions, approval gates |\n\nDefault: V2 pipeline type with QUEUED execution mode. Use PARALLEL only when executions are fully independent.\n\n## Quick Navigation\n\n| You want to... | Go to |\n|----------------|-------|\n| Create a pipeline (V2, triggers, variables, modes) | [codepipeline.md](references/codepipeline.md) |\n| Connect GitHub/GitLab/Bitbucket source | [codeconnections.md](references/codeconnections.md) |\n| Write buildspec.yml / configure builds | [codebuild.md](references/codebuild.md) |\n| Set up private package registry for builds | [codeartifact.md](references/codeartifact.md) |\n| Configure deployment strategy (blue/green, canary) | [codedeploy.md](references/codedeploy.md) |\n| Cross-account or cross-region deployment | [codepipeline.md](references/codepipeline.md) |\n| Fix failing pipeline, build, or deployment | [troubleshooting.md](references/troubleshooting.md) |\n\n## Common Workflows\n\n| Task | Action | Reference |\n|------|--------|-----------|\n| Pipeline from GitHub to ECS | Create connection → CodeBuild Docker stage → CodeDeploy ECS blue/green | [codepipeline](references/codepipeline.md), [codedeploy](references/codedeploy.md) |\n| Pipeline stuck at source | Check connection status; if PENDING, complete OAuth in AWS Console | [troubleshooting](references/troubleshooting.md) |\n| Build timing out | Check VPC/NAT, increase `timeoutInMinutes`, verify Docker privileged mode | [codebuild](references/codebuild.md) |\n| Deploy to another account | Configure KMS + S3 bucket policy + cross-account role, add `RoleArn` to action | [codepipeline](references/codepipeline.md) |\n| Roll back failed deployment | Auto-rollback on alarm/failure; manual: `stop-deployment --auto-rollback-enabled` | [codedeploy](references/codedeploy.md) |\n| Lambda canary deployment | CodeBuild packages → CodeDeploy Lambda with canary traffic shifting | [codedeploy](references/codedeploy.md) |\n\n## Troubleshooting\n\n| Error/Symptom | Cause | Fix |\n|---------------|-------|-----|\n| `YAML_FILE_ERROR` in CodeBuild | Missing or malformed `runtime-versions` in buildspec (recommended for standard images) | Add `runtime-versions` block in install phase |\n| `file already exists` on CodeDeploy | Redeployment without overwrite config | Set `file_exists_behavior: OVERWRITE` |\n| Pipeline trigger not firing | File path filter checks only first 100 files in diff | Reduce path filter scope or merge smaller |\n| PARALLEL mode wrong revision | Race between event and source action | Use QUEUED mode for sequential consistency |\n| Docker: `Cannot connect to daemon` | Missing privileged mode | Set `privilegedMode: true` AND start dockerd in buildspec |\n| `CODEBUILD_CLONE_REF` permission error | CodeBuild role missing UseConnection | Add `codeconnections:UseConnection` to CodeBuild service role |\n| Deployment never completes | MinimumHealthyHosts too high for instance count | Ensure healthy threshold < total instances |\n| ECS deployment stuck | Health check failing on new task set | Verify target group health check path/port |\n\n## Security\n\n- MUST store secrets in Secrets Manager or Parameter Store; reference via CodeBuild `type: SECRETS_MANAGER` — MUST NOT embed in buildspec as PLAINTEXT\n- MUST use customer-managed KMS keys for cross-account artifact encryption (default encryption does not support cross-account)\n- SHOULD scope CodeBuild/CodeDeploy service roles to specific resource ARNs; MUST NOT use `*` for `s3:GetObject` or `kms:Decrypt`\n- MUST use CodeConnections (not personal access tokens) for source connections; OAuth tokens cannot be rotated automatically\n- See [CodePipeline security best practices](https://docs.aws.amazon.com/codepipeline/latest/userguide/security-best-practices.html) for comprehensive guidance\n\n## Not Covered\n\n| Topic | Use instead |\n|-------|-------------|\n| CDK Pipelines (`aws-cdk-lib/pipelines`) | `aws-cdk` |\n| `sam deploy` / SAM CLI | `aws-serverless` |\n| ECS service deployment config (circuit breaker, rolling params) | `aws-containers` |\n| GitHub Actions / GitLab CI | Third-party tools, not covered |\n"
}SHA-256: 0807338c8915768ea5660da2f70130bd376cc2f3991f20c3fdf15e503fea5101