Create the pipeline
Source, Build and Deploy stages created with the CodePipeline wizard, triggered only by pushes that touch the API.
About 25 min · Verified 8 October 2026
The CodePipeline wizard creates the pipeline, a CodeBuild project and the service roles in one pass. You will answer six screens.
Run the wizard#
Choose how to create it#
Open CodePipelinePipelinesCreate pipeline. Choose Build custom pipeline and then Next.
Pipeline settings#
| Field | Value |
|---|---|
| Pipeline name | shortlink-api-prod |
| Pipeline type | V2 |
| Execution mode | Queued |
| Service role | New service role (accept the generated name) |
| Allow AWS CodePipeline to create a service role | ticked |
Under Advanced settings leave Artifact store on Default location and the encryption key on Default AWS managed key. The artifact store is a private bucket named codepipeline-<region>-…, not your website bucket.
Choose Next.
Source#
| Field | Value |
|---|---|
| Source provider | GitHub (via GitHub App) |
| Connection | shortlink-github |
| Repository name | <GITHUB_USER>/shortlink (your fork) |
| Default branch | main |
| Output artifact format | CodePipeline default (a ZIP) |
Under Trigger, keep Start the pipeline on source code change and add a filter so only backend changes start a release:
| Field | Value |
|---|---|
| Event type | Push |
| Branches → Include | main |
| File paths → Include | shortlink-api/**, appspec.yml, deploy/** |
Choose Next. The output artifact for this stage is called SourceArtifact.
Build: create the CodeBuild project#
| Field | Value |
|---|---|
| Build provider | Other build providers → AWS CodeBuild |
| Region | ap-south-1 |
| Project name | choose Create project |
A new window or panel opens for the CodeBuild project:
| Field | Value |
|---|---|
| Project name | shortlink-api-build |
| Project type | Default project (not Runner project) |
| Environment image | Managed image |
| Compute | EC2 |
| Operating system | Amazon Linux |
| Runtime(s) | Standard |
| Image | aws/codebuild/amazonlinux-x86_64-standard:5.0 (or the newest standard image offered) |
| Service role | New service role (accept the name) |
| Buildspec | Use a buildspec file → deploy/buildspec-api.yml |
| Logs | CloudWatch logs ticked |
| VPC | none |
Choose Continue to CodePipeline. Back in the wizard, confirm Input artifacts is SourceArtifact, Build type is Single build, and leave the output artifact as the default, BuildArtifact. Choose Next.
Test: skip#
Choose Skip test stage (and confirm). Tests already run inside the build.
Deploy#
| Field | Value |
|---|---|
| Deploy provider | AWS CodeDeploy |
| Region | ap-south-1 |
| Application name | shortlink-api |
| Deployment group | shortlink-api-prod |
| Input artifacts | BuildArtifact |
Choose Next.
Review and create#
Check the summary: Source (SourceArtifact) → Build (BuildArtifact) → Deploy. Choose Create pipeline.
The pipeline starts running. Let it. If Deploy fails with an access denied or cannot download message, that is the expected first failure.
Verify the structure#
aws codepipeline get-pipeline --region ap-south-1 --name shortlink-api-prod \
--query 'pipeline.{type:pipelineType,mode:executionMode,stages:stages[].{stage:name,actions:actions[].{action:name,provider:actionTypeId.provider,in:inputArtifacts[].name,out:outputArtifacts[].name}}}' \
--output jsonCodeStarSourceConnection, output SourceArtifact), Build (CodeBuild, input SourceArtifact, output BuildArtifact) and Deploy (CodeDeploy, input BuildArtifact). type is V2 and mode is QUEUED.The Build action has no output artifact
Open CodePipelineshortlink-api-prodEditBuildEdit stagethe actionEdit and set Output artifacts to BuildArtifact. Then check that the Deploy action's input is BuildArtifact. Save the pipeline.
CodeBuild says its source type is GitHub instead of CodePipeline
Projects created from the wizard use the CODEPIPELINE source and artifact types automatically. That mismatch only happens when a project was created separately in the CodeBuild console first. Fix it from the command line, then confirm:
aws codebuild update-project --region ap-south-1 --name shortlink-api-build \
--source 'type=CODEPIPELINE,buildspec=deploy/buildspec-api.yml' --artifacts 'type=CODEPIPELINE'
aws codebuild batch-get-projects --region ap-south-1 --names shortlink-api-build \
--query 'projects[].{name:name,source:source.type,artifacts:artifacts.type,buildspec:source.buildspec}'Both source and artifacts must say CODEPIPELINE. CodeBuild validates them together, so setting only the source (or NO_ARTIFACTS) is rejected.
Next: fix the permissions.
Found a mistake? Edit this page on GitHub.