ECS Blue/Green Deployment Rollback Causes and Configuration
A team is using AWS CodePipeline to deploy a critical application to Amazon ECS. The pipeline has a deployment stage that uses Amazon ECS (Blue/Green) action with CodeDeploy. Recently, the deployment failed because the new task set did not become healthy within the specified timeout. The team wants to ensure that future deployments automatically roll back if the health check fails. What should the team do?
⚠ Common exam trap
Candidates often think they need to set up complex CloudWatch alarms (Option A) or use ECS deployment circuit breakers (Option D) to roll back ECS blue/green deployments. However, because the deployment is managed by CodeDeploy, the native and simplest way to handle this is to enable automatic rollback on deployment failure directly within the CodeDeploy deployment group configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the CodeDeploy deployment group to enable automatic rollback when a deployment fails. The deployment will automatically revert to the last successful deployment.
AWS CodeDeploy allows you to configure automatic rollbacks in the event of a deployment failure. If a new task set fails to become healthy within the specified timeout during an Amazon ECS blue/green deployment, CodeDeploy marks the deployment as failed. By enabling the 'Roll back when a deployment fails' option in the CodeDeploy deployment group, CodeDeploy will automatically roll back the deployment to the last known successful revision without requiring manual intervention or custom CloudWatch alarms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a CloudWatch alarm that triggers when the healthy task count of the ECS service falls below a threshold. Configure the CodeDeploy deployment group to automatically roll back when this alarm is in ALARM state.
Why it's wrong here
This is the correct approach for integrating external health checks with CodeDeploy rollbacks. CodeDeploy deployment groups can be configured with rollback triggers that monitor CloudWatch alarms. If the healthy task count metric for the ECS service drops below a predefined threshold, indicating a health issue with the new deployment, the CloudWatch alarm will transition to ALARM state, prompting CodeDeploy to initiate an automatic rollback to the last known good state. This ensures rapid recovery from post-deployment health degradation.
- ✓
Modify the CodeDeploy deployment group to enable automatic rollback when a deployment fails. The deployment will automatically revert to the last successful deployment.
Why this is correct
While CodeDeploy deployment groups do offer an option to automatically roll back on deployment failures (e.g., hooks failing, timeout, or insufficient instances), this addresses a different problem than what the team is facing. The question implies the deployment itself might succeed initially, but the application's health degrades after the deployment completes or during the traffic shifting phase. Rolling back only on deployment failure wouldn't catch post-deployment health issues detected by the healthy task count.
- ✗
Increase the deployment timeout in the CodeDeploy deployment configuration to allow more time for the new task set to become healthy.
Why it's wrong here
Increasing the deployment timeout merely extends the duration CodeDeploy waits before declaring a deployment failed if certain conditions (like minimum healthy hosts) aren't met. It does not introduce an automatic rollback mechanism based on post-deployment application health metrics like the healthy task count. This action would only delay the inevitable failure notification and potential manual intervention, rather than providing an automated recovery solution.
- ✗
Configure the ECS service to automatically roll back to the previous task definition if the deployment fails. Use the ECS service's deployment circuit breaker.
Why it's wrong here
The ECS deployment circuit breaker is a valuable feature for rolling update deployments directly managed by ECS, allowing automatic rollback on deployment failures or health check failures. However, when using CodeDeploy for blue/green deployments with ECS, CodeDeploy takes over the orchestration of the deployment and rollback logic. In this scenario, CodeDeploy's rollback capabilities, including integration with CloudWatch alarms, are the primary mechanism for managing automatic rollbacks, not the ECS service's native circuit breaker.
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.