An organization uses AWS Elastic Beanstalk for application deployments. They want to implement immutable updates to minimize downtime and ensure that if the new environment fails health checks, the old environment remains intact. Which deployment policy should they choose?
Immutable update deploys the new application version to a completely new set of instances (or a fully separate environment) that runs alongside the old fleet. It waits for all new instances to pass health checks before shifting traffic to them, and if any fail, the old environment remains untouched, enabling an immediate, zero-impact rollback. This provides the strongest availability and isolation, making it the safest deployment policy.
Why this answer
Immutable updates in AWS Elastic Beanstalk launch a completely new environment with the new application version. If the new environment fails health checks, Elastic Beanstalk automatically terminates it, leaving the original environment untouched. This ensures zero downtime and a safe rollback, which matches the requirement to keep the old environment intact if health checks fail.
Exam trap
The trap here is that candidates confuse 'immutable update' with 'traffic splitting' because both involve a new environment, but traffic splitting does not automatically terminate the new environment on health check failure—it requires manual intervention or additional automation to roll back.
How to eliminate wrong answers
Option A is wrong because traffic splitting gradually shifts a percentage of traffic to a new environment, but if health checks fail, the old environment is not guaranteed to remain intact—the new environment may still be partially serving traffic and the rollback is not fully automated. Option C is wrong because all-at-once deploys replace all instances simultaneously, causing downtime and leaving no fallback environment if health checks fail. Option D is wrong because rolling update based on health replaces instances in batches and can terminate unhealthy instances in the old environment, potentially disrupting the original environment before the new one is fully verified.