CI/CD and Deployment Strategies on AWS
Learn to ship to AWS safely: OIDC from CI, images to ECR, ECS and Lambda deploys, blue-green and canary releases, and Terraform pipelines.
What You'll Learn
Understanding Why Manual Deploys Fail
A payments team in Pune ships orders-api every Friday at 6 PM.
Authenticating CI to AWS with OIDC
CI needs permission to push images and update services.
Building, Scanning, and Pushing Images to ECR
Before an image can run, it has to be built, checked, and stored in a registry.
Deploying to ECS with New Task Definitions
A new image does nothing until a task definition points at it.
Choosing a Deployment Strategy
The pipeline decides how code gets to AWS. The deployment strategy decides how traffic moves from the old version to the new one.
Running Blue-Green and Canary Releases with Automatic Rollback
A release strategy is only as safe as its rollback trigger.
Skills You'll Master
Curriculum Index9 topics
Understanding Why Manual Deploys Fail
A payments team in Pune ships orders-api every Friday at 6 PM.
Authenticating CI to AWS with OIDC
CI needs permission to push images and update services.
Building, Scanning, and Pushing Images to ECR
Before an image can run, it has to be built, checked, and stored in a registry.
Deploying to ECS with New Task Definitions
A new image does nothing until a task definition points at it.
Choosing a Deployment Strategy
The pipeline decides how code gets to AWS.
Running Blue-Green and Canary Releases with Automatic Rollback
A release strategy is only as safe as its rollback trigger.
Running Terraform Through Pull Requests
Infrastructure changes deserve the same review as code.
Hands-on Lab: Ship orders-api to Fargate and Watch It Roll Back
This lab builds the pipeline from this module on top of the ECS and Lambda lab.
Quick Reference and Common Mistakes
Quick reference Common mistakes Calling update-service --force-new-deployment and assuming your new image is live is...
Career Impact
Roles that use the skills in this module.
Cloud Engineer
DevOps Engineer
Solutions Architect
Platform Engineer
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
OIDC lets each workflow run request short-lived credentials from AWS, so there is no static key to leak or rotate. You can also limit the role to one repository and branch. Access keys stored as secrets stay valid until someone deletes them.
No. It restarts tasks from the task definition revision the service already uses. If that revision points to the old image tag, you get new tasks running the old code. To ship a new image, register a new task definition revision and point the service at it.
Use blue-green when a bad release is expensive and you need to switch back in seconds. Rolling updates are simpler and cheaper, and they are fine when a slow rollback is acceptable. Canary fits when you want real traffic to judge a release before everyone gets it.
A saved plan applies exactly what a person reviewed. Running apply from scratch makes a new plan that may include changes nobody saw. Terraform also refuses to apply a saved plan if the state changed since it was made, which protects you from stale plans.