Skip to main content

EC2 blue/green immutable replacement

Exam alignment: DOP-C02 Domain 1 task statements for pipelines, testing, artifacts, or deployment.

Learning objective

Validate a replacement environment, shift traffic, and retain the old fleet for rollback.

Difficulty / SchwierigkeitsgradIntermediate
Study time / Lernzeit120 minutes
Prerequisites / VoraussetzungenPrevious lessons in this volume

Professional scenario

A customer-facing service cannot tolerate mixed versions or long rollback.

Core concepts

  • Blue/green runs original and replacement environments.
  • Green is validated before production traffic.
  • Load balancers support controlled traffic routing.
  • Database changes must be backward compatible during overlap.

Architecture flow

  1. Identify the release input and immutable identity.
  2. Select the managed AWS control plane and least-privilege role.
  3. Execute build, test, artifact, or deployment work.
  4. Collect service events, logs, reports, and runtime metrics.
  5. Stop, retry, or roll back according to explicit rules.

Decision matrix

RequirementPreferred choiceReason
Fast rollbackRetain blue temporarilyTraffic can return
No mixed host stateImmutable replacementConsistent instances
Breaking schema changeExpand-and-contractSupports both versions

Failure modes and troubleshooting

  • Green fails target health.
  • Business transaction fails despite technical health.
  • Blue is terminated too early.

Security and operations

  • Use short-lived service roles and least privilege.
  • Encrypt artifacts and protect logs from secret exposure.
  • Record changes and approvals for audit.

Hands-on lab

Goal / Ziel: Design blue/green with health, business checks, and rollback window.

Tasks

  1. Create the smallest safe test architecture.
  2. Implement or simulate the main workflow.
  3. Introduce one controlled failure.
  4. Diagnose it from service evidence.
  5. Document cleanup and one improvement.

Validation

  • The workflow uses an immutable version.
  • A required failure blocks promotion.
  • The diagnosis identifies the first failed transition.

Cost control / Kostenkontrolle: Keep resources short lived; read cleanup before starting.

Cleanup

  1. Delete pipeline/build/deployment resources.
  2. Delete temporary artifacts, images, logs, and roles.

Exam traps

  • Ignoring database compatibility.
  • Assuming ALB health proves business success.

Key takeaways

  • Blue/green runs original and replacement environments.
  • Database changes must be backward compatible during overlap.
  • Decisions must be justified by requirements and failure behavior.

Review questions

  1. What is the immutable release identity?
  2. Which evidence proves failure or success?
  3. What is the safest recovery action?
Answers
  1. A version, digest, or uniquely versioned artifact.
  2. Service events, logs, reports, health checks, and runtime metrics.
  3. Restore the known-good version using the configured rollback path.