Skip to main content

CI/CD and Deployment Strategies on AWS

Learn to ship to AWS safely: OIDC from CI, images to ECR, ECS and Lambda deploys, blue-green and canary releases, and Terraform pipelines.

Prerequisites
~3 hours
9 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Manual Deploys Fail

A payments team in Pune ships orders-api every Friday at 6 PM.

Authenticating CI to AWS with OIDC

CI needs permission to push images and update services.

Building, Scanning, and Pushing Images to ECR

Before an image can run, it has to be built, checked, and stored in a registry.

Deploying to ECS with New Task Definitions

A new image does nothing until a task definition points at it.

Choosing a Deployment Strategy

The pipeline decides how code gets to AWS. The deployment strategy decides how traffic moves from the old version to the new one.

Running Blue-Green and Canary Releases with Automatic Rollback

A release strategy is only as safe as its rollback trigger.

Skills You'll Master

CI-CDDEPLOYMENT-STRATEGIESBLUE-GREENCANARYCODEDEPLOY

Curriculum Index9 topics

Career Impact

Roles that use the skills in this module.

  • Cloud Engineer

  • DevOps Engineer

  • Solutions Architect

  • Platform Engineer

See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

OIDC lets each workflow run request short-lived credentials from AWS, so there is no static key to leak or rotate. You can also limit the role to one repository and branch. Access keys stored as secrets stay valid until someone deletes them.

No. It restarts tasks from the task definition revision the service already uses. If that revision points to the old image tag, you get new tasks running the old code. To ship a new image, register a new task definition revision and point the service at it.

Use blue-green when a bad release is expensive and you need to switch back in seconds. Rolling updates are simpler and cheaper, and they are fine when a slow rollback is acceptable. Canary fits when you want real traffic to judge a release before everyone gets it.

A saved plan applies exactly what a person reviewed. Running apply from scratch makes a new plan that may include changes nobody saw. Terraform also refuses to apply a saved plan if the state changed since it was made, which protects you from stale plans.