Skip to content

Overview and prerequisites

How a push to your fork becomes a running release on EC2, and what must already exist.

About 10 min · Verified 8 October 2026

In guide 1 you deployed the API by hand. Here you make AWS do it: every push to main on your fork is tested, packaged and installed on the EC2 server automatically, and rolled back if the new version does not start.

GitHubyour fork · mainpushSourceCodeConnectionsBuildCodeBuild · test + packageartifactDeployCodeDeployEC2 APIagent + hooksPrivate artifact bucketcodepipeline-<region>-…
A push to main on your fork starts CodePipeline. CodeBuild tests and packages the API, CodeDeploy hands it to the agent on EC2, and the lifecycle hooks restart the service.

What happens on every push#

  1. You push a commit to main on your GitHub fork.
  2. CodePipeline notices (through the GitHub connection) and starts an execution.
  3. Source stage: it downloads the commit as a ZIP into a private S3 artifact bucket.
  4. Build stage: CodeBuild unpacks it, runs npm ci and the 36 API tests. If any test fails the pipeline stops here, and nothing reaches the server. If they pass, it packages appspec.yml, the hook scripts and shortlink-api/ into a new ZIP.
  5. Deploy stage: CodeDeploy tells the agent on your EC2 server to download that ZIP, then runs the lifecycle scripts: stop the service, copy files, install dependencies, start the service, check /health.
  6. If the health check fails, CodeDeploy rolls back to the previous version.

The pieces#

PieceWhat it isWhat you create in this guide
GitHub connectionAn AWS-owned GitHub App you authorize on your forkshortlink-github
CodePipelineOrchestrator: runs stages in ordershortlink-api-prod
CodeBuildRuns a build container and the buildspecshortlink-api-build
CodeDeploy application and groupDefines what to deploy and which serversshortlink-api / shortlink-api-prod
CodeDeploy agentA small program on the EC2 server that does the workInstalled on shortlink-api
IAM rolesEach service acts as a role. Permissions are per roleSee the permissions chapter
Artifact bucketPrivate S3 bucket for ZIPs between stagesCreated by CodePipeline

Before you begin#

You need the working deployment from guide 1, at least chapters 1 to 10. Check each item, because the pipeline depends on all of them.

Your computerQuick check of the first four
curl -fsS http://<ALB_DNS>/health && echo
aws ec2 describe-instances --region ap-south-1 \
  --filters Name=tag:Name,Values=shortlink-api Name=instance-state-name,Values=running \
  --query 'Reservations[].Instances[].InstanceId' --output text
aws ssm describe-instance-information --region ap-south-1 \
  --query 'InstanceInformationList[].{id:InstanceId,ping:PingStatus}' --output table

Replace <ALB_DNS> with your own value (or fill in the known ones once under My values at the top of the page).

Names used in this guide#

Use them exactly. IAM policies later refer to them.

ResourceName
GitHub connectionshortlink-github
Pipelineshortlink-api-prod
CodeBuild projectshortlink-api-build
CodeDeploy applicationshortlink-api
CodeDeploy deployment groupshortlink-api-prod
CodeDeploy service roleshortlink-codedeploy-service-role
Pipeline artifactsSourceArtifact, BuildArtifact

An honest note about downtime#

This is an in-place deployment on one server. While CodeDeploy stops the old version and starts the new one, the load balancer has no healthy target and visitors get a 503 for roughly 30 to 90 seconds. That is normal here and it is why chapter 10 mentions a second server and rolling deployments as the next step.

Next: understand the repository files.

Found a mistake? Edit this page on GitHub.