Memory hook: Build once, identify the artifact, test it, then move traffic deliberately.
Must remember
- Keep source, dependencies, build instructions and infrastructure definitions versioned. CodeBuild executes a buildspec; CodePipeline coordinates stages and artifacts; CodeDeploy manages supported deployment strategies. Store immutable, identifiable artifacts in suitable S3/ECR/package repositories.
- A Lambda deployment package must match its runtime and CPU architecture. Layers share supported dependencies; container images use a compatible runtime interface. An image tag can move: an immutable digest identifies what was actually deployed. Never bake runtime secrets into an artifact.
- SAM expresses serverless infrastructure using a CloudFormation transform.
sam buildprepares artifacts; local invocation supports development feedback but cannot reproduce every cloud permission, network or managed-service behaviour. CloudFormation change sets describe proposed changes; they do not prove application correctness. - Test in layers: unit tests for logic, integration tests for actual service contracts, contract/schema tests for producer/consumer compatibility and end-to-end smoke tests for useful service. Mocking a success response does not validate IAM or eventual consistency.
- Versions publish immutable Lambda configurations/code; aliases point to versions and support eligible traffic splitting. Canary exposes a small proportion first; linear shifts traffic in increments; all-at-once moves it together. Use alarms and lifecycle validation hooks to stop/roll back unsafe releases.
- ECS blue/green deployment uses separate task sets/traffic destinations for supported controllers. EC2 deployments need healthy spare capacity and suitable hooks. Database changes require backward-compatible sequencing because rolling code back may not reverse a destructive schema change.
- Separate development/staging/production roles and configuration. Approvals gate risk; automated tests detect behaviour. A successful pipeline means its configured steps passed, not that every failure mode has been tested.
- AppConfig separates configuration and feature-flag release from application binaries. Validators check proposed configuration, deployment strategies control rollout, and configured alarms support rollback. A configuration change can break the application without any code deployment, so test compatibility and choose safe defaults.
- Current emerging-topic check (10 October 2026): the official DVA-C02 guide lists broader AI-assisted code generation/review, test generation, CI/CD assistance, troubleshooting and optimisation as possible unscored pretest topics; Amazon Q Developer assistance also appears within the published development-domain skills. Treat generated code, tests and repair suggestions as proposals requiring review and representative validation. Keep secrets and personal data out of inappropriate model inputs/logs; scope agent tools and preserve explicit deployment authority. The emerging-topic list is not an additional weighted exam domain.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Release gradually and stop on error-rate increase | Canary/linear delivery with alarms and rollback. |
| Verify IAM against an actual database | Integration test in an isolated environment. |
| Ensure production runs the reviewed container | Pin and record the image digest. |
Traps
- Rebuilding separately in production may produce a different artifact.
- A change set previews infrastructure actions, not test outcomes.
- Rollback requires a compatible data and dependency state.
Active recall
1. What does CodePipeline do that CodeBuild does not?
Orchestrates the delivery stages; CodeBuild runs the build/test commands within a stage.
2. Why use a Lambda alias?
It gives a stable invocation target that can point or shift traffic between published versions.
3. Does a local SAM test prove production permissions work?
No. Test IAM, networking and managed-service integration separately.
4. What catches a deployment that returns 200 but writes no data?
A meaningful end-to-end validation that checks the expected state change.
5. What makes an artifact reproducible?
Versioned source/dependencies/build configuration and a recorded immutable artifact identity.