A DevOps engineer is designing a CI/CD pipeline for a containerized application using AWS CodePipeline and Amazon ECS. The pipeline should build a Docker image, push it to Amazon ECR, and deploy it to an ECS service. Which deployment action should they use in the pipeline?
Amazon ECS (Blue/Green) with CodeDeploy is the correct native deployment provider for ECS in CodePipeline. CodeDeploy's ECS compute platform orchestrates the creation of a green task set, shifts traffic from the blue target group to the green target group in either linear or canary increments, and performs post-traffic-shift validation hooks defined in an AppSpec file. It also supports automatic rollback if the deployment fails health checks, making it the ideal, fully integrated choice for ECS blue/green deployments in a pipeline.
Why this answer
Amazon ECS (Blue/Green) deployment provider with CodeDeploy is the native, fully managed deployment action in AWS CodePipeline for ECS services. It orchestrates traffic shifting, task set management, and rollback automatically using CodeDeploy's ECS blue/green deployment type, which is the recommended approach for containerized applications on ECS.
Exam trap
The trap here is that candidates often confuse the ECS (Blue/Green) deployment provider with a simple 'update-service' command, not realizing that CodePipeline requires a native deployment provider to support automated traffic shifting, rollback, and integration with CodeDeploy's lifecycle hooks.
How to eliminate wrong answers
Option A is wrong because AWS Elastic Beanstalk deployment action is designed for Elastic Beanstalk environments, not for ECS services; it cannot directly deploy to an ECS cluster or service. Option B is wrong because while CodeBuild can run aws ecs update-service, this approach bypasses CodePipeline's deployment tracking, rollback capabilities, and traffic shifting; it is a custom script, not a native deployment action. Option D is wrong because AWS CloudFormation deployment action updates CloudFormation stacks, not ECS services directly; it would require wrapping the ECS service update in a CloudFormation template, adding unnecessary complexity and losing the built-in deployment features of CodeDeploy.