Skip to main content

ECS rolling and blue/green deployments

Exam alignment: DOP-C02 Domain 1 task statements for pipelines, testing, artifacts, or deployment.

Learning objective

Compare task replacement, capacity, pre-traffic tests, roles, and rollback.

Difficulty / SchwierigkeitsgradIntermediate
Study time / Lernzeit120 minutes
Prerequisites / VoraussetzungenPrevious lessons in this volume

Professional scenario

Routine container releases are low risk; checkout releases need pre-traffic validation.

Core concepts

  • Rolling replaces tasks gradually and uses spare capacity.
  • Blue/green keeps separate task sets for validation and traffic shift.
  • Task execution role pulls images and writes logs; task role is for application code.
  • Container, service, and load-balancer health are distinct.

Architecture flow

  1. Identify the release input and immutable identity.
  2. Select the managed AWS control plane and least-privilege role.
  3. Execute build, test, artifact, or deployment work.
  4. Collect service events, logs, reports, and runtime metrics.
  5. Stop, retry, or roll back according to explicit rules.

Decision matrix

RequirementPreferred choiceReason
Routine releaseRollingSimple and efficient
Pre-traffic testingBlue/greenValidate green first
Immediate traffic rollbackRetain blue task setOld revision available

Failure modes and troubleshooting

  • No capacity for replacement tasks.
  • Task execution role cannot pull.
  • Port/path mismatch fails ALB health.

Security and operations

  • Use short-lived service roles and least privilege.
  • Encrypt artifacts and protect logs from secret exposure.
  • Record changes and approvals for audit.

Hands-on lab

Goal / Ziel: Deploy a rolling revision and design blue/green alternative.

Tasks

  1. Create the smallest safe test architecture.
  2. Implement or simulate the main workflow.
  3. Introduce one controlled failure.
  4. Diagnose it from service evidence.
  5. Document cleanup and one improvement.

Validation

  • The workflow uses an immutable version.
  • A required failure blocks promotion.
  • The diagnosis identifies the first failed transition.

Cost control / Kostenkontrolle: Keep resources short lived; read cleanup before starting.

Cleanup

  1. Delete pipeline/build/deployment resources.
  2. Delete temporary artifacts, images, logs, and roles.

Exam traps

  • Giving app permissions to task execution role.
  • Choosing blue/green without duplicate capacity.

Key takeaways

  • Rolling replaces tasks gradually and uses spare capacity.
  • Container, service, and load-balancer health are distinct.
  • Decisions must be justified by requirements and failure behavior.

Review questions

  1. What is the immutable release identity?
  2. Which evidence proves failure or success?
  3. What is the safest recovery action?
Answers
  1. A version, digest, or uniquely versioned artifact.
  2. Service events, logs, reports, health checks, and runtime metrics.
  3. Restore the known-good version using the configured rollback path.