Prev Next

Cloud / AWS CodePipeline Interview questions

Last updated

1. What is AWS CodePipeline? 2. What are the main components of CodePipeline? 3. What is a stage in CodePipeline? 4. What is an action in CodePipeline? 5. What are the supported source providers in CodePipeline? 6. What are artifacts in CodePipeline? 7. What is a pipeline execution in CodePipeline? 8. What is a transition in CodePipeline? 9. What is a manual approval action in CodePipeline? 10. What deploy providers does CodePipeline support? 11. What is the difference between CodePipeline, CodeBuild and CodeDeploy? 12. How do you create a pipeline in CodePipeline? 13. What is the CodePipeline service role? 14. How is CodePipeline priced? 15. What is the difference between V1 and V2 pipeline types? 16. What is AWS CodeConnections used for in CodePipeline? 17. What are variables in CodePipeline? 18. How do you start a pipeline manually? 19. How does CodePipeline detect source changes? 20. Why does CodePipeline need an S3 artifact bucket? 21. How does CodePipeline integrate with CodeBuild? 22. How do you deploy a CloudFormation stack using CodePipeline? 23. How do you implement manual approval with SNS notifications? 24. How does CodePipeline handle a failed action? 25. How do you run actions in parallel within a stage? 26. What is the difference between SUPERSEDED, QUEUED and PARALLEL execution modes? 27. How do you pass values between actions in CodePipeline? 28. How does CodePipeline deploy to Amazon ECS? 29. How do you deploy Lambda functions using CodePipeline? 30. How do you monitor pipeline events in CodePipeline? 31. How do you secure secrets in a CodePipeline workflow? 32. How can you invoke a Lambda function from a pipeline? 33. How do you trigger a pipeline only for specific branches, tags or file paths? 34. What is the difference between CodePipeline and Jenkins? 35. When would you choose CodePipeline over GitHub Actions? 36. How do you define a CodePipeline as code? 37. How do you build a cross-account pipeline in CodePipeline? 38. How do you set up a cross-region pipeline in CodePipeline? 39. Why do cross-account pipelines require a customer-managed KMS key? 40. Explain the execution flow of a CodePipeline run? 41. How do you implement blue/green deployment with CodePipeline? 42. How do you troubleshoot a CodePipeline permissions error? 43. Why is my pipeline not triggering on new commits? 44. How do stage conditions and rollbacks work in V2 pipelines? 45. How can you optimize CodePipeline execution time? 46. How do you implement a custom action with a job worker? 47. What happens when two commits arrive while a pipeline is running? 48. How do CDK Pipelines self-mutate? 49. How do you audit and restrict who can approve or change a pipeline? 50. How would you design a multi-environment pipeline for dev, test and prod?

1. What is AWS CodePipeline?

AWS CodePipeline is a fully managed continuous delivery service that models, visualizes and automates the steps needed to take code from a repository to production. You define a workflow of stages, and CodePipeline runs it every time a change is detected.

It does not build or deploy anything by itself. It orchestrates other tools such as CodeBuild, CodeDeploy, CloudFormation, ECS, Lambda or third-party services like Jenkins.

A pipeline typically looks like this: Source, Build, Test, Approval, Deploy. Each run is called an execution and its progress is visible in the console.

Take quiz
AWS CodePipeline is mainly used to:
compile Java code on its own build servers
orchestrate the release workflow from source to deployment
store Docker images
manage IAM users across accounts
Which best describes the role of CodePipeline?
a monitoring dashboard for EC2
a Git hosting service
an orchestrator that calls other services for each step
a container runtime

2. What are the main components of CodePipeline?

A pipeline is built from a small set of concepts:

  • Pipeline - the whole workflow definition.
  • Stage - a logical group such as Source, Build or Deploy.
  • Action - a single task inside a stage, run by a provider.
  • Transition - the link between two stages that can be enabled or disabled.
  • Artifact - the files passed from one action to the next, stored in S3.
  • Execution - one run of the pipeline for a specific revision.

Every pipeline also needs a service role and an artifact store.

Take quiz
Which component is the link between two stages that can be disabled?
Artifact
Execution ID
Action provider
Transition
An execution in CodePipeline refers to:
an IAM policy attached to the pipeline
the S3 bucket holding artifacts
a single stage definition
one run of the pipeline for a given revision

3. What is a stage in CodePipeline?

A stage is a logical unit of a pipeline that groups one or more actions, for example Source, Build, Staging or Production. Stages run in the order they are defined.

A pipeline needs at least two stages, and the first stage must contain a source action. Actions inside a stage can run sequentially or in parallel depending on their runOrder.

If any action in a stage fails, the stage fails and the pipeline stops there unless you retry it.

Take quiz
What must the first stage of every pipeline contain?
a manual approval
a source action
a deploy action
a Lambda invoke action
What happens when an action in a stage fails?
the pipeline skips to the last stage
the stage fails and later stages do not start
the pipeline restarts from the source automatically
the failed action is silently ignored

4. What is an action in CodePipeline?

An action is the smallest unit of work in a pipeline. It belongs to a stage and is tied to a provider that does the real work, such as CodeBuild for compiling or CodeDeploy for deploying.

Each action has a category, a provider, optional input and output artifacts, and a configuration block. Its runOrder decides whether it runs before, after or alongside other actions in the same stage.

The six action categories are Source, Build, Test, Deploy, Approval and Invoke.

Take quiz
Which is NOT an action category in CodePipeline?
Approval
Monitor
Invoke
Test
What decides the order of actions inside one stage?
the IAM role name
the alphabetical action name
the artifact size
the runOrder value

5. What are the supported source providers in CodePipeline?

The source action pulls code or artifacts and starts the pipeline. Supported providers include:

  • AWS CodeCommit
  • Amazon S3 (versioned bucket)
  • Amazon ECR (new image push)
  • GitHub, GitHub Enterprise, GitLab, Bitbucket through AWS CodeConnections

Third-party repositories use a connection resource that must be authorized once in the console before the pipeline can read from it.

Take quiz
Which source provider requires a versioned bucket?
Bitbucket
Amazon ECR
CodeCommit
Amazon S3
How does CodePipeline connect to a Bitbucket repository?
by mounting an EBS volume
using an SQS queue
through a CodeConnections connection
with a CloudFront signed URL

6. What are artifacts in CodePipeline?

Artifacts are the files that move between actions. An action can consume input artifacts and produce output artifacts, and each one is stored as a zip in the pipeline's S3 artifact bucket.

For example, the source action outputs SourceArtifact, CodeBuild takes it as input and outputs BuildArtifact, and CodeDeploy then uses that build output.

Artifact names must match exactly between the output of one action and the input of the next, otherwise the pipeline will not validate.

Take quiz
Where does CodePipeline store artifacts between actions?
on the CodeBuild instance disk
in DynamoDB
in AWS Systems Manager
in an S3 artifact bucket
What must be true for two actions to share an artifact?
both run in different regions
both actions use the same IAM role
the artifact must be a Docker image
the output artifact name equals the next input artifact name

7. What is a pipeline execution in CodePipeline?

A pipeline execution is a single run of the pipeline that processes one set of source revisions from start to finish. It gets a unique execution ID and its own status: InProgress, Succeeded, Superseded, Stopped, Stopping or Failed.

A new execution starts on a source change, on a schedule or trigger, or manually with start-pipeline-execution.

Execution history shows which commit went through which stage, which makes it easy to trace a bad deployment back to its revision.

Take quiz
Which is a valid pipeline execution status?
Paused
Archived
Compiling
Superseded
What does an execution ID help you do?
change the source branch
trace a specific run and its revision through the stages
rotate the KMS key
rename the pipeline

8. What is a transition in CodePipeline?

A transition is the connection between two stages. When a stage succeeds, the transition into the next stage is what lets the revision move forward.

You can disable a transition to hold changes before a sensitive stage such as Production, and enable it again when you are ready. While disabled, the revision waits and the pipeline shows it as pending.

This is a lightweight alternative to a manual approval when you just need to pause deployments, for example during a freeze.

Take quiz
Why would you disable a transition into the Production stage?
to change the artifact encryption key
to delete old artifacts
to speed up the build stage
to hold revisions back, for instance during a release freeze
A revision waiting behind a disabled transition will:
be deleted from S3
be deployed anyway after 5 minutes
roll back the previous stage
wait until the transition is enabled again

9. What is a manual approval action in CodePipeline?

A manual approval action pauses the pipeline until someone with the right IAM permission approves or rejects it. It is commonly placed before a production deploy.

You can attach an SNS topic so reviewers get an email or chat notification, plus a URL for review and comments. Approval reviewers need codepipeline:PutApprovalResult.

If nobody responds within the timeout (7 days by default), the action is treated as rejected and the pipeline fails at that point.

Take quiz
What IAM permission lets a reviewer approve an action?
codepipeline:StartPipelineExecution
codepipeline:PutApprovalResult
codebuild:StartBuild
sns:Publish
If nobody responds to an approval before the timeout, the action is:
restarted from Source
skipped silently
automatically approved
treated as rejected

10. What deploy providers does CodePipeline support?

Deploy actions push the built output to a target. The common providers are:

  • AWS CodeDeploy - EC2, on-premises servers, Lambda and ECS blue/green
  • AWS CloudFormation - stack and change set operations
  • Amazon ECS and ECS (Blue/Green)
  • AWS Elastic Beanstalk
  • Amazon S3 - static websites
  • AWS Service Catalog and AWS AppConfig

Anything not covered can be handled with a Lambda invoke action or a custom action.

Take quiz
Which provider deploys a static site by copying files to a bucket?
AWS Service Catalog
Amazon S3 deploy action
Amazon ECR
AWS AppConfig
Where can you use the ECS (Blue/Green) deploy action?
with S3 static hosting
only on Elastic Beanstalk
only on on-premises servers
with a CodeDeploy-managed ECS service

11. What is the difference between CodePipeline, CodeBuild and CodeDeploy?

They are separate services that usually work together, each with a single job.

CodePipeline CodeBuild CodeDeploy
orchestrates the whole release workflow. compiles and tests code in managed containers. rolls out an application to compute targets.
Runs stages and actions. Driven by buildspec.yml. Driven by appspec.yml.

In practice CodePipeline calls CodeBuild in the Build stage and CodeDeploy in the Deploy stage, passing artifacts between them.

Take quiz
Which file configures a CodeBuild project's commands?
taskdef.json
appspec.yml
pipeline.yml
buildspec.yml
Which service actually rolls the application out to EC2 instances?
CodeBuild
Amazon ECR
CodeDeploy
CodePipeline

12. How do you create a pipeline in CodePipeline?

In the console, choose Create pipeline and follow the wizard:

  1. Enter the pipeline name, pipeline type (V1 or V2) and service role.
  2. Pick the source provider, repository and branch.
  3. Add a build provider such as CodeBuild, or skip it.
  4. Add a deploy provider or skip it.
  5. Review and create. The pipeline runs immediately.

For repeatable setups use the CLI with a JSON definition, or define it in CloudFormation, CDK or Terraform.

Take quiz
What runs automatically right after a pipeline is created?
a manual approval
a CloudTrail export
a rollback
the first execution
Which is a repeatable way to create pipelines besides the console?
editing the S3 bucket policy
renaming the CodeBuild project
emailing AWS Support
a CloudFormation, CDK or Terraform template

13. What is the CodePipeline service role?

The service role is the IAM role CodePipeline assumes to call other services for you. It needs access to the artifact bucket, and permission to start the actions you configured, such as codebuild:StartBuild or codedeploy:CreateDeployment.

It is separate from the roles used by CodeBuild or CodeDeploy, which do the actual work with their own permissions.

Most permission errors in a new pipeline come from this role missing an action or a resource ARN.

Take quiz
Which principal assumes the CodePipeline service role?
the developer who pushed code
the Git provider
the CodePipeline service
the S3 bucket
A new pipeline fails at Build with AccessDenied for codebuild:StartBuild. What is missing?
a second source action
a larger artifact bucket
a Route 53 record
the permission on the pipeline service role

14. How is CodePipeline priced?

CodePipeline has two pricing models depending on the pipeline type:

V1 V2
Flat monthly fee per active pipeline. Pay per action execution minute.
A pipeline is active if it had at least one execution that month. Only actions that actually run are billed.

You also pay separately for the services it calls, like CodeBuild minutes, S3 storage for artifacts and KMS requests. Check the current pricing page for exact rates and free tier limits.

Take quiz
How does V2 billing work?
per IAM user
per action execution minute
a flat yearly license
per commit pushed
Which costs are NOT included in the CodePipeline charge?
the pipeline definition itself
viewing the console
stage transitions
CodeBuild minutes and S3 artifact storage

15. What is the difference between V1 and V2 pipeline types?

V2 is the newer pipeline type and adds features V1 lacks, plus a different billing model.

Feature V1 V2
Pricing per active pipeline per action minute
Pipeline variables not supported supported
Git tag / file path triggers no yes
Execution modes SUPERSEDED only SUPERSEDED, QUEUED, PARALLEL
Stage conditions no yes

New pipelines should generally use V2 unless you have a strong reason to stay on V1.

Take quiz
Which execution modes are available only in V2?
MANUAL
SUPERSEDED
ROLLING
QUEUED and PARALLEL
Which feature is available in V2 but not V1?
artifact stores
pipeline-level variables
source actions
manual approvals

16. What is AWS CodeConnections used for in CodePipeline?

AWS CodeConnections (formerly CodeStar Connections) lets AWS services access third-party repositories like GitHub, GitLab and Bitbucket. You create a connection resource, then authorize it once through the provider's app installation.

Pipelines reference the connection ARN in the source action. A connection stays in the PENDING state until someone completes the handshake, and a pipeline using a pending connection cannot fetch code.

It replaces the older GitHub OAuth token (version 1) source action, which is no longer recommended.

Take quiz
What state is a connection in before the authorization handshake is complete?
ARCHIVED
ACTIVE
DELETED
PENDING
What does the source action reference to use GitHub?
a password in plain text
an SSH key in S3
a VPC endpoint
the connection ARN

17. What are variables in CodePipeline?

Variables are values a pipeline can read at runtime. There are two groups:

  • Action output variables - values produced by actions, like #{SourceVariables.CommitId}.
  • Pipeline-level variables (V2) - values set at start time, referenced as #{variables.env}.

Built-ins such as #{codepipeline.PipelineExecutionId} are always available. Variables can feed action configuration, for example passing a commit ID to CodeBuild as an environment variable.

Take quiz
Which syntax reads a V2 pipeline-level variable named env?
${env}
$(env)
#{variables.env}
%env%
What does #{codepipeline.PipelineExecutionId} return?
the last commit message
the S3 bucket name
the ID of the current execution
the IAM role ARN

18. How do you start a pipeline manually?

From the console, open the pipeline and choose Release change. From the CLI:

aws codepipeline start-pipeline-execution --name my-pipeline

This runs the latest revision from the source. With V2 you can also pass variables using --variables, or a specific source revision with --source-revisions.

To follow progress, use aws codepipeline get-pipeline-state --name my-pipeline.

Take quiz
Which CLI command starts an execution?
aws codebuild start-pipeline
aws codepipeline run-build
aws pipeline release
aws codepipeline start-pipeline-execution
Which command shows the current stage and action status?
list-webhooks
get-pipeline-state
create-custom-action-type
put-approval-result

19. How does CodePipeline detect source changes?

It depends on the provider. CodeCommit, S3 and ECR sources use Amazon EventBridge rules: an event fires when a branch is updated, an object is put or an image is pushed, and the rule starts the pipeline.

Third-party repositories use CodeConnections, which handle the webhook events for you. The older method, polling (PollForSourceChanges), checks periodically and is discouraged because it is slower.

For S3, CloudTrail data events must be enabled for the bucket so EventBridge can see object writes.

Take quiz
Which mechanism is recommended for CodeCommit change detection?
a cron job on EC2
an SNS email
polling every second
an EventBridge rule
Why must CloudTrail data events be on for an S3 source?
to grant the service role access
to encrypt the artifact
so the bucket can be versioned
so EventBridge can see object writes

20. Why does CodePipeline need an S3 artifact bucket?

Actions run on separate compute, so they cannot pass files directly. CodePipeline uploads each action's output to an S3 artifact bucket, and the next action downloads it as input.

The bucket also keeps revision data for retries. Objects are encrypted with the default S3 key, or with a customer-managed KMS key if you configure one, which is required for cross-account access.

A pipeline with actions in several regions needs one artifact bucket per region.

Take quiz
Why is an artifact bucket needed?
to host the pipeline console
to store IAM users
actions exchange files through it instead of directly
to run CodeBuild jobs
A pipeline that runs actions in two regions needs:
no artifact bucket at all
a single global bucket only
one artifact bucket in each region
a DynamoDB table per region

21. How does CodePipeline integrate with CodeBuild?

You add a Build (or Test) action with the provider AWS CodeBuild and point it at a build project. CodePipeline passes the input artifact, CodeBuild runs the commands in buildspec.yml and then returns the files listed under artifacts as the output artifact.

version: 0.2
phases:
  build:
    commands:
      - mvn -q package
artifacts:
  files:
    - target/app.jar

A failing command makes the build fail, which fails the action and stops the stage.

Take quiz
Where does CodeBuild define which files become the output artifact?
the artifacts section of buildspec.yml
the SNS topic
the source repository settings
the pipeline transition
What happens when a buildspec command exits with an error?
the pipeline skips the build stage
the artifact is emailed
the build and its action fail
the source is reverted

22. How do you deploy a CloudFormation stack using CodePipeline?

Add a Deploy action with the provider AWS CloudFormation and choose an action mode:

  • CREATE_UPDATE - create or update a stack directly.
  • CHANGE_SET_REPLACE then CHANGE_SET_EXECUTE - create a change set, review it, then apply.
  • REPLACE_ON_FAILURE - recreate the stack if it failed.
  • DELETE_ONLY - remove a stack.

The template comes from an input artifact. The action also needs a CloudFormation role that can create the resources in the template.

Take quiz
Which pair of modes supports a reviewable change set?
DELETE_ONLY and CREATE_UPDATE
CREATE_UPDATE and DELETE_ONLY
REPLACE_ON_FAILURE only
CHANGE_SET_REPLACE and CHANGE_SET_EXECUTE
Where does the CloudFormation template come from in the action?
a CloudWatch alarm
the IAM console
an input artifact
an SNS message

23. How do you implement manual approval with SNS notifications?

Add an Approval action, choose Manual approval and select an SNS topic. When the pipeline reaches it, CodePipeline publishes a message to the topic with a review link.

  1. Create an SNS topic and subscribe reviewers by email or chat.
  2. Allow the pipeline service role to sns:Publish.
  3. Give reviewers codepipeline:PutApprovalResult.
  4. Optionally add a review URL and comments.

Reviewers then open the console and choose Approve or Reject.

Take quiz
Which permission must the pipeline role have to send the notification?
s3:GetObject
codebuild:BatchGetBuilds
sns:Publish
sns:CreateTopic only
What do reviewers do after receiving the SNS message?
delete the connection
restart the SNS topic
approve or reject in the console or API
edit the artifact bucket

24. How does CodePipeline handle a failed action?

When an action fails, the stage is marked Failed and the pipeline stops progressing. The revision stays at that stage, and nothing later runs.

You can choose Retry stage to rerun either all actions or only the failed actions in that stage, without repeating earlier stages. In V2 you can also configure a stage on-failure condition to retry automatically or roll back.

If the fix is in code, a new commit starts a fresh execution instead.

Take quiz
What does 'retry failed actions' do?
reruns only the failed actions in that stage
disables all transitions
deletes the artifact bucket
restarts the whole pipeline from Source
What starts a fresh execution after you fix code?
an SNS topic change
a new commit on the tracked branch
a KMS key rotation
a stage rename

25. How do you run actions in parallel within a stage?

Give the actions the same runOrder value. Actions with the same number run at the same time; higher numbers wait until all lower numbers finish.

"actions": [
  { "name": "UnitTests",  "runOrder": 1 },
  { "name": "LintCheck",  "runOrder": 1 },
  { "name": "Package",    "runOrder": 2 }
]

Here the tests and lint run together, then Package starts once both succeed.

Take quiz
Two actions in one stage both have runOrder 1. They will:
run in separate pipelines
run in alphabetical order
be rejected by validation
run at the same time
In the example, when does Package start?
before UnitTests
after both runOrder 1 actions succeed
only after manual approval
at the same moment as LintCheck

26. What is the difference between SUPERSEDED, QUEUED and PARALLEL execution modes?

These V2 modes decide what happens when a new change arrives while a run is in progress.

SUPERSEDED QUEUED PARALLEL
A newer run replaces an older waiting one at a stage. Runs wait in a FIFO queue, in order. Runs execute independently at the same time.
Default behavior. Every commit is processed. Good for isolated, independent runs.

Use QUEUED when every commit must be deployed in order, and SUPERSEDED when only the latest commit matters.

Take quiz
Which mode processes every commit strictly in order?
ROLLBACK
QUEUED
PARALLEL
SUPERSEDED
What does SUPERSEDED do to an older waiting execution?
runs it in parallel
replaces it with the newer one
deletes the pipeline
keeps it forever

27. How do you pass values between actions in CodePipeline?

Use output variables with a namespace. Give the producing action a namespace, then reference its variables in a later action with #{namespace.variableName}.

# CodeBuild environment variable set from a source action
CommitId = #{SourceVariables.CommitId}

CodeBuild can export its own variables via exported-variables in buildspec.yml, which later actions can read. Variables are for small strings; use artifacts for files.

Take quiz
Which syntax reads an output variable from an action namespace?
{{namespace}}
#{namespace.variableName}
$namespace/variableName
@variableName
Large files between actions should be passed as:
pipeline names
output variables
SNS messages
artifacts

28. How does CodePipeline deploy to Amazon ECS?

The standard Amazon ECS deploy action performs a rolling update. It reads an imagedefinitions.json file from the build artifact, which maps a container name to a new image URI, then updates the service with a new task definition revision.

[{"name": "web", "imageUri": "123456789012.dkr.ecr.us-east-1.amazonaws.com/web:1.4.2"}]

For blue/green, use the ECS (Blue/Green) action with CodeDeploy, which needs appspec.yaml and a task definition instead.

Take quiz
Which file maps a container name to a new image for the ECS deploy action?
imagedefinitions.json
Dockerfile
buildspec.yml
appspec.yml
Which action is needed for ECS blue/green deployments?
Manual approval only
ECS (Blue/Green) with CodeDeploy
S3 deploy
Elastic Beanstalk deploy

29. How do you deploy Lambda functions using CodePipeline?

There are three common routes. The simplest is a CloudFormation deploy action using a SAM or CDK template, where CodeBuild first runs sam package to upload code to S3.

A second option is CodeDeploy with a Lambda deployment group, which shifts alias traffic gradually (canary or linear) and can roll back on a CloudWatch alarm.

Third, an Invoke action can call a custom Lambda that updates function code directly, though that gives you no built-in traffic shifting.

Take quiz
Which option supports gradual traffic shifting for Lambda?
Elastic Beanstalk
Manual approval
S3 deploy action
CodeDeploy with a Lambda alias
What does sam package do in the build step?
encrypts the KMS key
uploads code to S3 and rewrites the template
starts a CodeDeploy rollback
creates the pipeline

30. How do you monitor pipeline events in CodePipeline?

CodePipeline emits state-change events to Amazon EventBridge for pipelines, stages and actions, such as CodePipeline Pipeline Execution State Change.

You can create a rule that matches FAILED and sends it to SNS, Lambda or a chat channel. Notification rules through AWS Chatbot offer a simpler path for Slack or Teams.

CloudTrail records API calls such as UpdatePipeline for auditing, and the console shows execution history.

Take quiz
Which service receives pipeline state-change events?
AWS Snowball
Amazon EventBridge
AWS Config only
Amazon Athena
Which service records who called UpdatePipeline?
AWS CloudTrail
Amazon Macie
AWS X-Ray
Amazon Inspector

31. How do you secure secrets in a CodePipeline workflow?

Never hard-code secrets in the pipeline definition or the repository. Store them in AWS Secrets Manager or Systems Manager Parameter Store and read them at build time.

In CodeBuild you can map them as environment variables of type SECRETS_MANAGER or PARAMETER_STORE. The build role needs read permission on just those secrets.

Also enable KMS encryption on the artifact bucket and avoid printing secret values to build logs.

Take quiz
Which CodeBuild environment variable type reads from Secrets Manager?
CODECOMMIT_REF
PLAINTEXT
SECRETS_MANAGER
S3_OBJECT
Where should database passwords NOT be stored?
in Parameter Store as SecureString
behind a KMS key
in plain text inside the repository or pipeline JSON
in Secrets Manager

32. How can you invoke a Lambda function from a pipeline?

Add an Invoke action with the AWS Lambda provider and set the function name. CodePipeline passes a job event containing artifact locations and user parameters.

The function must report back by calling PutJobSuccessResult or PutJobFailureResult with the job ID, otherwise the action waits until it times out.

codepipeline.put_job_success_result(jobId=event["CodePipeline.job"]["id"])

Take quiz
What must the Lambda do at the end of an Invoke action?
write to CloudTrail
delete its own role
call PutJobSuccessResult or PutJobFailureResult
publish to Kinesis
What happens if the function never reports a result?
the action is skipped
the source is rolled back
the action waits until it times out
the pipeline auto-approves

33. How do you trigger a pipeline only for specific branches, tags or file paths?

Use V2 triggers. In the pipeline definition, add a trigger on the source action with filters for pushes or pull requests.

  • Branches - include or exclude patterns like release/*.
  • Tags - start only on tags like v*.
  • File paths - run only when files under services/api/** change.

This is useful in monorepos, where you do not want every commit to start every pipeline.

Take quiz
Which is most useful for monorepos?
a manual approval on Source
a second artifact bucket
disabling all transitions
file path filters on the trigger
To run only for version tags such as v1.2.0, you would filter on:
the CodeBuild project name
the IAM user
tags with a v* pattern
the S3 key prefix

34. What is the difference between CodePipeline and Jenkins?

CodePipeline is a managed AWS service focused on orchestration, while Jenkins is a self-hosted automation server you install and maintain.

CodePipeline Jenkins
Hosting fully managed you run controllers and agents
Extensibility actions and custom actions thousands of plugins
Pricing per pipeline or minute free software plus infrastructure
AWS integration native IAM, EventBridge via plugins

Jenkins can also be a build provider inside CodePipeline, so the two can coexist.

Take quiz
Who maintains the servers in a CodePipeline setup?
your DNS registrar
AWS, since it is fully managed
the Git provider
you, on EC2 controllers
Can Jenkins be used together with CodePipeline?
only in V1 pipelines
only for S3 sources
no, they conflict
yes, as a build or test provider

35. When would you choose CodePipeline over GitHub Actions?

Pick CodePipeline when your delivery is AWS-centric: deploying via CloudFormation, CodeDeploy or ECS, needing IAM roles instead of stored keys, and cross-account promotion with AWS-native audit trails.

Pick GitHub Actions when your code and workflow live in GitHub, you want a large marketplace of ready actions and prefer YAML next to the code.

Many teams mix them: GitHub Actions runs tests and CodePipeline handles controlled deployments.

Take quiz
Which need favors CodePipeline?
hosting Git repos
editing README files
native IAM-based cross-account AWS deployments
reusing marketplace YAML actions
Which describes a common hybrid?
CodePipeline replaces GitHub hosting
CodePipeline for tests only, Jenkins for Git
GitHub Actions for tests, CodePipeline for deployments
GitHub Actions replaces IAM

36. How do you define a CodePipeline as code?

You can describe a pipeline with CloudFormation (AWS::CodePipeline::Pipeline), AWS CDK, Terraform or a JSON file used with the CLI.

aws codepipeline get-pipeline --name my-pipeline > pipeline.json
aws codepipeline update-pipeline --cli-input-json file://pipeline.json

Keeping the definition in version control makes changes reviewable and lets you recreate the pipeline in another account or region. With CDK you can use the higher-level CDK Pipelines construct.

Take quiz
Which CloudFormation resource type defines a pipeline?
AWS::CodeBuild::Source
AWS::IAM::Pipeline
AWS::CodePipeline::Pipeline
AWS::S3::Pipeline
Why keep the pipeline definition in version control?
it makes builds faster
it removes the need for IAM
it stops all failures
changes become reviewable and repeatable

37. How do you build a cross-account pipeline in CodePipeline?

A common pattern is one tooling account that owns the pipeline and deploys into dev, test and prod accounts.

  1. Create a customer-managed KMS key in the tooling account and use it to encrypt the artifact bucket.
  2. Allow the target account to use that key and to read the bucket via resource policies.
  3. Create a deployment role in each target account that trusts the pipeline role.
  4. Set the roleArn on each cross-account action so CodePipeline assumes it.

CodeCommit or ECR sources can also live in a separate account, using a role with access to them.

Take quiz
Why is a customer-managed KMS key needed?
to speed up CodeBuild
the target account must decrypt the artifacts
to name the stages
to create SNS topics
How does a cross-account action get target account access?
it disables MFA
it emails credentials
CodePipeline assumes a role in that account
it copies the IAM user

38. How do you set up a cross-region pipeline in CodePipeline?

A pipeline lives in one region, but individual actions can run in other regions using the region field on the action.

The pipeline uses artifactStores (plural) with one S3 bucket per region instead of a single artifactStore. CodePipeline copies artifacts to the bucket in the target region before the action runs.

Each region's bucket needs the right permissions, and a KMS key for that region if you use encryption.

Take quiz
What must exist for each region an action runs in?
a Route 53 zone
a separate AWS account
a copy of the pipeline service
an artifact bucket in that region
Which field on an action selects the region?
endpoint
zone
az
region

39. Why do cross-account pipelines require a customer-managed KMS key?

By default, artifacts are encrypted with the AWS managed key aws/s3. Its key policy cannot be edited, so it cannot be shared with another account.

A customer-managed key has a key policy you control. You grant the target account's deployment role kms:Decrypt and related actions, so it can read the artifacts.

Without it, the deploy action in the other account fails with an AccessDenied error when trying to download the artifact.

Take quiz
Why can't the default aws/s3 key be used cross-account?
it only supports Windows
it is too expensive
its key policy cannot be modified
it deletes objects daily
Missing KMS permission typically causes:
a duplicate execution
a slower build
AccessDenied when reading the artifact
a missing SNS topic

40. Explain the execution flow of a CodePipeline run?

A run moves through a fixed sequence:

flowchart LR
  A["Change detected"] --> B["Source action"]
  B --> C["Artifact saved to S3"]
  C --> D["Build action"]
  D --> E["Test action"]
  E --> F{Approval?}
  F -->|Approved| G["Deploy action"]
  F -->|Rejected| H["Execution failed"]

The source action fetches the revision and stores it as an artifact. Each later action downloads its input, does its job through its provider, and uploads output. If an action fails or an approval is rejected, the execution stops at that stage.

Take quiz
Where is the source revision stored after the Source action?
in the SNS topic
as an artifact in S3
in the deploy target only
inside the IAM role
What happens when an approval is rejected?
the pipeline is deleted
the deploy runs anyway
the execution fails at that stage
the source is re-cloned

41. How do you implement blue/green deployment with CodePipeline?

Blue/green in CodePipeline is done by CodeDeploy, which the pipeline triggers in the Deploy stage.

  • ECS - the ECS (Blue/Green) action shifts an ALB listener from the old task set to a new one.
  • EC2 - CodeDeploy provisions a replacement Auto Scaling group and reroutes the load balancer.
  • Lambda - CodeDeploy moves alias traffic gradually.

You can add pre- and post-traffic hooks and a CloudWatch alarm so a failure rolls traffic back to the original version. The old environment is kept briefly before termination.

Take quiz
What does CodeDeploy shift in an ECS blue/green deployment?
the pipeline name
the KMS key alias
the load balancer listener between task sets
the S3 bucket policy
What can trigger an automatic rollback?
a longer commit message
a new IAM user
a renamed stage
a CloudWatch alarm or failed hook

42. How do you troubleshoot a CodePipeline permissions error?

Start by finding which role is failing. The console error usually says whether it is the pipeline service role, the CodeBuild role or the deployment role.

  1. Read the failed action's details and CloudTrail event for the denied API call.
  2. Check the role's policy for that action and resource ARN.
  3. For artifacts, verify S3 and KMS permissions on both sides.
  4. Check the trust policy if it is a cross-account role assumption.

The IAM policy simulator helps confirm a fix before rerunning the failed action.

Take quiz
What is the first thing to identify in a permission error?
the pipeline's region name
the commit hash length
which role is being denied
the number of stages
Where can you see the exact denied API call?
in Route 53
in the S3 lifecycle rules
in CodeCommit branches
in CloudTrail or the action details

43. Why is my pipeline not triggering on new commits?

Check these causes in order:

  • The connection is still PENDING or was revoked in the provider.
  • The EventBridge rule for a CodeCommit source is missing or disabled.
  • A V2 trigger filter excludes the branch or file path you changed.
  • For S3, versioning or CloudTrail data events are off.
  • The commit went to a different branch than the one configured.

Manually run start-pipeline-execution to confirm the pipeline itself works, which separates a trigger problem from a stage problem.

Take quiz
A GitHub-based pipeline never starts. A likely cause is:
the SNS topic is empty
the connection is in PENDING status
the artifact bucket is too large
CodeBuild has no buildspec
A manual start works but commits do not trigger. This points to:
the deploy provider
the trigger or event configuration
the build image
the KMS key

44. How do stage conditions and rollbacks work in V2 pipelines?

V2 pipelines let you attach conditions to a stage at three points: beforeEntry, onSuccess and onFailure.

Each condition holds rules such as a CloudWatch alarm check, a Lambda invoke, a variable check or a deployment window. If a beforeEntry rule fails, the pipeline can fail, skip or wait, and an onFailure condition can automatically retry the stage or roll back to the last successful execution.

This lets you gate deployments on alarms or time windows without adding a separate approval step.

Take quiz
Which condition point can trigger an automatic rollback?
onCommit
beforeEntry only
onSource
onFailure
Which rule type checks CloudWatch alarm state?
a Route 53 health rule
a CodeCommit rule
an S3 lifecycle rule
an alarm-based rule in a stage condition

45. How can you optimize CodePipeline execution time?

Focus on the slowest stages first, usually Build and Test.

  • Run independent tests and scans in parallel using the same runOrder.
  • Enable CodeBuild caching for dependencies and Docker layers.
  • Use a larger CodeBuild compute type if builds are CPU bound.
  • Trim artifacts so less data is uploaded and downloaded.
  • Use trigger filters to skip runs for unrelated changes.

Measure first: the execution history shows per-action durations, so you optimize the real bottleneck.

Take quiz
Which change speeds up independent tests?
adding a manual approval
disabling transitions
giving them the same runOrder to run in parallel
renaming the stage
What helps repeated dependency downloads in CodeBuild?
using a smaller artifact name
adding more SNS topics
enabling build caching
creating more IAM roles

46. How do you implement a custom action with a job worker?

Use a custom action when no built-in provider fits, for example an in-house test tool.

  1. Create the action type with create-custom-action-type, defining category, provider and version.
  2. Add the action to a pipeline stage.
  3. Run a job worker that calls PollForJobs to find work.
  4. Acknowledge with AcknowledgeJob, do the work, then call PutJobSuccessResult or PutJobFailureResult.

The worker can run anywhere with network access to CodePipeline, such as an EC2 instance.

Take quiz
Which API does a job worker use to find work?
StartPipelineExecution
PollForJobs
GetPipelineState
PutApprovalResult
Where can a custom job worker run?
only in Lambda layers
only in the S3 console
anywhere with network access to CodePipeline
only inside CodeCommit

47. What happens when two commits arrive while a pipeline is running?

It depends on the execution mode. In the default SUPERSEDED mode, the first run continues, but when the second run reaches a stage that is locked, it waits there. If a third arrives, it supersedes the waiting second one, so the middle commit is never deployed.

In QUEUED mode both are processed in order. In PARALLEL mode both run at once as independent executions.

Choose based on whether every commit must ship or only the newest.

Take quiz
In SUPERSEDED mode, what happens to a waiting older run when a newer one arrives?
it is paused forever
it is replaced by the newer run
it is promoted to prod
it is duplicated
Which mode guarantees every commit is deployed in order?
DISABLED
PARALLEL
SUPERSEDED
QUEUED

48. How do CDK Pipelines self-mutate?

CDK Pipelines is a construct that builds a CodePipeline for deploying CDK apps. It adds a UpdatePipeline (self-mutation) stage right after the build.

That stage runs cdk deploy on the pipeline's own stack. If you changed the pipeline definition in code, such as adding a stage, it updates itself and then restarts the run with the new structure.

You only need to deploy the pipeline manually once. After that, pushing code changes both the app and the pipeline.

Take quiz
What does the self-mutation stage do?
rotates secrets
updates the pipeline's own stack from the code
creates SNS topics
deletes old artifacts
How often must you deploy a CDK pipeline manually?
on every commit
never, it is impossible
every hour
once, for the initial deployment

49. How do you audit and restrict who can approve or change a pipeline?

Use IAM to separate duties. Give developers codepipeline:StartPipelineExecution and read access, but only release managers codepipeline:PutApprovalResult.

Restrict changes with permissions on UpdatePipeline, and scope policies by pipeline ARN or tags. For cross-account controls, use SCPs at the organization level.

CloudTrail logs every approval and update with the caller identity, giving you an audit trail. You can also send events to EventBridge for alerts.

Take quiz
Which permission should be limited to release managers for approvals?
codepipeline:ListPipelines
logs:GetLogEvents
codepipeline:PutApprovalResult
s3:ListBucket
Which service gives the audit trail of approvals?
Amazon Lightsail
AWS Glue
Amazon Polly
AWS CloudTrail

50. How would you design a multi-environment pipeline for dev, test and prod?

Build the artifact once, then promote the same artifact through environments so what you test is exactly what you ship.

flowchart LR
  S[Source] --> B["Build once"]
  B --> D["Deploy Dev"]
  D --> T["Deploy Test + integration tests"]
  T --> A{Manual approval}
  A --> P["Deploy Prod"]

Use separate accounts per environment with cross-account roles, environment-specific config via variables or Parameter Store, and an approval before prod. Add alarm-based rollback on the prod deploy.

Take quiz
Why build the artifact only once?
to reduce the number of stages
the same tested artifact is promoted to every environment
to avoid using IAM
to skip approvals
Where should the manual approval sit?
before the source stage
after prod is live
inside CodeCommit
right before the production deploy
«
»

Comments & Discussions